<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web01.fireside.fm</fireside:hostname>
    <fireside:genDate>Sat, 30 May 2026 03:11:34 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Diversity”</title>
    <link>https://www.bsdnow.tv/tags/diversity</link>
    <pubDate>Thu, 30 Sep 2021 03:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>422: The Brian Callahan Interview</title>
  <link>https://www.bsdnow.tv/422</link>
  <guid isPermaLink="false">4ca5efbc-d83b-41a2-981c-42c4dacefb05</guid>
  <pubDate>Thu, 30 Sep 2021 03:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/4ca5efbc-d83b-41a2-981c-42c4dacefb05.mp3" length="30162984" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We interview Dr. Brian Callahan about his language porting work for OpenBSD, teaching with BSDs and recruiting students into projects, research, and his work at NYC*BUG in this week’s episode of BSDnow.</itunes:subtitle>
  <itunes:duration>49:59</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We interview Dr. Brian Callahan about his language porting work for OpenBSD, teaching with BSDs and recruiting students into projects, research, and his work at NYC*BUG in this week’s episode of BSDnow.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;&lt;em&gt;NOTES&lt;/em&gt;&lt;/strong&gt;&lt;br&gt;
This episode of BSDNow is brought to you by &lt;a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;Interview - Dr. Brian Robert Callahan - &lt;a href="https://briancallahan.net/" target="_blank" rel="nofollow noopener"&gt;https://briancallahan.net/&lt;/a&gt; / &lt;a href="https://mastodon.com/bcallah@bsdnetwork" target="_blank" rel="nofollow noopener"&gt;bcallah@bsdnetwork&lt;/a&gt;&lt;/h2&gt;

&lt;hr&gt;

&lt;h3&gt;Tarsnap&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.&lt;/li&gt;
&lt;/ul&gt;

&lt;hr&gt;

&lt;ul&gt;
&lt;li&gt;Send questions, comments, show ideas/topics, or stories you want mentioned on the show to &lt;a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener"&gt;feedback@bsdnow.tv&lt;/a&gt;
*** Special Guest: Brian Callahan.&lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, trueos, trident, hardenedbsd, tutorial, howto, guide, bsd, operating system, open source, shell, unix, os, berkeley, software, distribution, release, zfs, zpool, dataset, interview, ports, packages, interview, callahan, language porting, teaching, research, recruiting, diversity, nycbug, new york, bsd user group,</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We interview Dr. Brian Callahan about his language porting work for OpenBSD, teaching with BSDs and recruiting students into projects, research, and his work at NYC*BUG in this week’s episode of BSDnow.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Interview - Dr. Brian Robert Callahan - <a href="https://briancallahan.net/" target="_blank" rel="nofollow noopener">https://briancallahan.net/</a> / <a href="https://mastodon.com/bcallah@bsdnetwork" target="_blank" rel="nofollow noopener">bcallah@bsdnetwork</a></h2>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul><p>Special Guest: Brian Callahan.</p>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We interview Dr. Brian Callahan about his language porting work for OpenBSD, teaching with BSDs and recruiting students into projects, research, and his work at NYC*BUG in this week’s episode of BSDnow.</p>

<p><strong><em>NOTES</em></strong><br>
This episode of BSDNow is brought to you by <a href="https://www.tarsnap.com/bsdnow" target="_blank" rel="nofollow noopener">Tarsnap</a></p>

<h2>Interview - Dr. Brian Robert Callahan - <a href="https://briancallahan.net/" target="_blank" rel="nofollow noopener">https://briancallahan.net/</a> / <a href="https://mastodon.com/bcallah@bsdnetwork" target="_blank" rel="nofollow noopener">bcallah@bsdnetwork</a></h2>

<hr>

<h3>Tarsnap</h3>

<ul>
<li>This weeks episode of BSDNow was sponsored by our friends at Tarsnap, the only secure online backup you can trust your data to. Even paranoids need backups.</li>
</ul>

<hr>

<ul>
<li>Send questions, comments, show ideas/topics, or stories you want mentioned on the show to <a href="mailto:feedback@bsdnow.tv" target="_blank" rel="nofollow noopener">feedback@bsdnow.tv</a>
***</li>
</ul><p>Special Guest: Brian Callahan.</p>]]>
  </itunes:summary>
</item>
<item>
  <title>88: Below the Clouds</title>
  <link>https://www.bsdnow.tv/88</link>
  <guid isPermaLink="false">26ef6d0e-ea2a-4032-88ee-121e1b2be033</guid>
  <pubDate>Wed, 06 May 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/26ef6d0e-ea2a-4032-88ee-121e1b2be033.mp3" length="67680724" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:34:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has posted a report of the activities that went on between January and March of this year&lt;/li&gt;
&lt;li&gt;As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)&lt;/li&gt;
&lt;li&gt;The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter&lt;/li&gt;
&lt;li&gt;The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward&lt;/li&gt;
&lt;li&gt;FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team&lt;/li&gt;
&lt;li&gt;Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code&lt;/li&gt;
&lt;li&gt;Lots of activity is happening in bhyve, some of which we've covered &lt;a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" target="_blank" rel="nofollow noopener"&gt;recently&lt;/a&gt;, and a number of improvements were made this quarter&lt;/li&gt;
&lt;li&gt;Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT&lt;/li&gt;
&lt;li&gt;Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being&lt;/li&gt;
&lt;li&gt;The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" target="_blank" rel="nofollow noopener"&gt;ASLR work&lt;/a&gt; is still being done by the HardenedBSD guys, and their next aim is position-independent executable&lt;/li&gt;
&lt;li&gt;The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more&lt;/li&gt;
&lt;li&gt;Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/57.html" target="_blank" rel="nofollow noopener"&gt;OpenBSD 5.7 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD has formally released another new version, complete with the giant changelog we've come to expect&lt;/li&gt;
&lt;li&gt;In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs&lt;/li&gt;
&lt;li&gt;If you're using one of the Soekris boards, there's even &lt;a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" target="_blank" rel="nofollow noopener"&gt;a new driver&lt;/a&gt; to manipulate the GPIO and LEDs on them - this has some fun possibilities&lt;/li&gt;
&lt;li&gt;Some new security improvements include: &lt;a href="https://en.wikipedia.org/wiki/SipHash" target="_blank" rel="nofollow noopener"&gt;SipHash&lt;/a&gt; being sprinkled in some areas to protect hashing functions, big &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;W&lt;sup&gt;X&lt;/sup&gt; improvements&lt;/a&gt; in the kernel space, &lt;a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" target="_blank" rel="nofollow noopener"&gt;static PIE&lt;/a&gt; on all architectures, deterministic "random" functions &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141807224826859&amp;amp;w=2" target="_blank" rel="nofollow noopener"&gt;being replaced&lt;/a&gt; with strong randomness, and support for remote logging over TLS&lt;/li&gt;
&lt;li&gt;The entire source tree has also been audited to use &lt;a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" target="_blank" rel="nofollow noopener"&gt;reallocarray&lt;/a&gt;, which unintentionally &lt;a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" target="_blank" rel="nofollow noopener"&gt;saved&lt;/a&gt; OpenBSD's libc from being vulnerable to &lt;a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" target="_blank" rel="nofollow noopener"&gt;earlier attacks&lt;/a&gt; affecting other BSDs' implementations&lt;/li&gt;
&lt;li&gt;Being that it's OpenBSD, a number of things have also been &lt;em&gt;removed&lt;/em&gt; from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)&lt;/li&gt;
&lt;li&gt;Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily&lt;/li&gt;
&lt;li&gt;BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon&lt;/li&gt;
&lt;li&gt;Speaking of httpd, it's gotten a number of &lt;a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" target="_blank" rel="nofollow noopener"&gt;new&lt;/a&gt; &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" target="_blank" rel="nofollow noopener"&gt;features&lt;/a&gt;, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so&lt;/li&gt;
&lt;li&gt;This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and &lt;a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" target="_blank" rel="nofollow noopener"&gt;mandoc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="http://www.openbsd.org/errata57.html" target="_blank" rel="nofollow noopener"&gt;errata page&lt;/a&gt; for any post-release fixes, and the &lt;a href="http://www.openbsd.org/faq/upgrade57.html" target="_blank" rel="nofollow noopener"&gt;upgrade guide&lt;/a&gt; for specific instructions on updating from 5.6&lt;/li&gt;
&lt;li&gt;Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases&lt;/li&gt;
&lt;li&gt;There's a &lt;a href="http://www.openbsd.org/lyrics.html#57" target="_blank" rel="nofollow noopener"&gt;song and artwork&lt;/a&gt; to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week&lt;/li&gt;
&lt;li&gt;Consider &lt;a href="https://www.openbsdstore.com" target="_blank" rel="nofollow noopener"&gt;picking one up&lt;/a&gt; to support the project (and it's the only way to get puffy stickers)&lt;/li&gt;
&lt;li&gt;For those of you paying close attention, the &lt;a href="http://www.openbsd.org/images/puffy57.gif" target="_blank" rel="nofollow noopener"&gt;banner image&lt;/a&gt; for this release just might remind you of a &lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener"&gt;certain special episode&lt;/a&gt; of BSD Now...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://torbsd.github.io/" target="_blank" rel="nofollow noopener"&gt;Tor-BSD diversity project&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)&lt;/li&gt;
&lt;li&gt;A new initiative has started to do just that, called the Tor-BSD diversity project&lt;/li&gt;
&lt;li&gt;"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."&lt;/li&gt;
&lt;li&gt;In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy&lt;/li&gt;
&lt;li&gt;There's an additional &lt;a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" target="_blank" rel="nofollow noopener"&gt;progress report&lt;/a&gt; for that part specifically, and it looks like most of the work is done now&lt;/li&gt;
&lt;li&gt;Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list &lt;/li&gt;
&lt;li&gt;If you've been considering running a node to help out, there's always &lt;a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener"&gt;our handy tutorial&lt;/a&gt; on getting set up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" target="_blank" rel="nofollow noopener"&gt;PC-BSD 10.1.2-RC1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab&lt;/li&gt;
&lt;li&gt;This quarterly update includes a number of new features, improvements and even some additional utilities&lt;/li&gt;
&lt;li&gt;PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems&lt;/li&gt;
&lt;li&gt;A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use&lt;/li&gt;
&lt;li&gt;Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network&lt;/li&gt;
&lt;li&gt;IPFW is now the default firewall, offering improved VIMAGE capabilities&lt;/li&gt;
&lt;li&gt;The life preserver backup tool now allows for bare-metal restores via the install CD&lt;/li&gt;
&lt;li&gt;ISC's NTP daemon has been replaced with &lt;a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" target="_blank" rel="nofollow noopener"&gt;OpenNTPD&lt;/a&gt;, and OpenSSL has been replaced with &lt;a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" target="_blank" rel="nofollow noopener"&gt;LibreSSL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It also includes the latest &lt;a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" target="_blank" rel="nofollow noopener"&gt;Lumina&lt;/a&gt; desktop, and there's another &lt;a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" target="_blank" rel="nofollow noopener"&gt;post dedicated to that&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Binary packages have also been updated to fresh versions from the ports tree&lt;/li&gt;
&lt;li&gt;More details, including upgrade instructions, can be found in the linked blog post
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ed Schouten - &lt;a href="mailto:ed@freebsd.org" target="_blank" rel="nofollow noopener"&gt;ed@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/edschouten" target="_blank" rel="nofollow noopener"&gt;@edschouten&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" target="_blank" rel="nofollow noopener"&gt;CloudABI&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" target="_blank" rel="nofollow noopener"&gt;Open Household Router Contraption&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This article introduces OpenHRC, the "Open Household Router Contraption"&lt;/li&gt;
&lt;li&gt;In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device&lt;/li&gt;
&lt;li&gt;It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup&lt;/li&gt;
&lt;li&gt;Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation&lt;/li&gt;
&lt;li&gt;All the code is open source &lt;a href="https://github.com/ioc32/openhrc" target="_blank" rel="nofollow noopener"&gt;and on Github&lt;/a&gt;, so you can read through what's actually being changed and put in place&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="https://www.youtube.com/watch?v=LZeKDM5jc90" target="_blank" rel="nofollow noopener"&gt;video guide&lt;/a&gt; to the entire process, if you're more of a visual person
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=365.0" target="_blank" rel="nofollow noopener"&gt;OPNsense 15.1.10 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version&lt;/li&gt;
&lt;li&gt;15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code&lt;/li&gt;
&lt;li&gt;Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree&lt;/li&gt;
&lt;li&gt;Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed&lt;/li&gt;
&lt;li&gt;NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well&lt;/li&gt;
&lt;li&gt;Version &lt;a href="https://twitter.com/opnsense/status/596009164746432512" target="_blank" rel="nofollow noopener"&gt;15.1.10.1&lt;/a&gt; was released shortly thereafter, including a hotfix for VLANs
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" target="_blank" rel="nofollow noopener"&gt;IBM Workpad Z50 and NetBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same&lt;/li&gt;
&lt;li&gt;Back in 1999, they released &lt;a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" target="_blank" rel="nofollow noopener"&gt;the Workpad Z50&lt;/a&gt; with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display&lt;/li&gt;
&lt;li&gt;You can probably tell where this is going... the article is about installing NetBSD it&lt;/li&gt;
&lt;li&gt;"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"&lt;/li&gt;
&lt;li&gt;The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern&lt;/li&gt;
&lt;li&gt;He's also got a &lt;a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" target="_blank" rel="nofollow noopener"&gt;couple&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" target="_blank" rel="nofollow noopener"&gt;videos&lt;/a&gt; of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" target="_blank" rel="nofollow noopener"&gt;FreeBSD from the trenches&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases&lt;/li&gt;
&lt;li&gt;In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI&lt;/li&gt;
&lt;li&gt;While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually&lt;/li&gt;
&lt;li&gt;Each command is explained, and he walks you through the process of doing &lt;a href="http://www.bsdnow.tv/tutorials/fde" target="_blank" rel="nofollow noopener"&gt;an encrypted installation&lt;/a&gt; on your root zpool
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" target="_blank" rel="nofollow noopener"&gt;Broadwell in DragonFly&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver&lt;/li&gt;
&lt;li&gt;Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too&lt;/li&gt;
&lt;li&gt;It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216QQcHyX" target="_blank" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21hGSk3c0" target="_blank" rel="nofollow noopener"&gt;Hunter writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20JwPw9Je" target="_blank" rel="nofollow noopener"&gt;Hrishi writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2x1GYr7y6" target="_blank" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2swXxr2PX" target="_blank" rel="nofollow noopener"&gt;Sergei writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" target="_blank" rel="nofollow noopener"&gt;How did you guess&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, 5.7, libressl, opensmtpd, openntpd, openssh, cloudabi, capsicum, 5.7, tor-bsd, tor, diversity, browser bundle, ipfw, openhrc, opnsense, router, workpad z50, gateway</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted a report of the activities that went on between January and March of this year</li>
<li>As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)</li>
<li>The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter</li>
<li>The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward</li>
<li>FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team</li>
<li>Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code</li>
<li>Lots of activity is happening in bhyve, some of which we've covered <a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" target="_blank" rel="nofollow noopener">recently</a>, and a number of improvements were made this quarter</li>
<li>Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT</li>
<li>Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being</li>
<li>The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" target="_blank" rel="nofollow noopener">ASLR work</a> is still being done by the HardenedBSD guys, and their next aim is position-independent executable</li>
<li>The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more</li>
<li>Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***</li>
</ul>

<h3><a href="http://www.openbsd.org/57.html" target="_blank" rel="nofollow noopener">OpenBSD 5.7 released</a></h3>

<ul>
<li>OpenBSD has formally released another new version, complete with the giant changelog we've come to expect</li>
<li>In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs</li>
<li>If you're using one of the Soekris boards, there's even <a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" target="_blank" rel="nofollow noopener">a new driver</a> to manipulate the GPIO and LEDs on them - this has some fun possibilities</li>
<li>Some new security improvements include: <a href="https://en.wikipedia.org/wiki/SipHash" target="_blank" rel="nofollow noopener">SipHash</a> being sprinkled in some areas to protect hashing functions, big <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" target="_blank" rel="nofollow noopener">W<sup>X</sup> improvements</a> in the kernel space, <a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" target="_blank" rel="nofollow noopener">static PIE</a> on all architectures, deterministic "random" functions <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141807224826859&amp;w=2" target="_blank" rel="nofollow noopener">being replaced</a> with strong randomness, and support for remote logging over TLS</li>
<li>The entire source tree has also been audited to use <a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" target="_blank" rel="nofollow noopener">reallocarray</a>, which unintentionally <a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" target="_blank" rel="nofollow noopener">saved</a> OpenBSD's libc from being vulnerable to <a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" target="_blank" rel="nofollow noopener">earlier attacks</a> affecting other BSDs' implementations</li>
<li>Being that it's OpenBSD, a number of things have also been <em>removed</em> from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)</li>
<li>Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily</li>
<li>BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon</li>
<li>Speaking of httpd, it's gotten a number of <a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" target="_blank" rel="nofollow noopener">new</a> <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" target="_blank" rel="nofollow noopener">features</a>, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so</li>
<li>This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and <a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" target="_blank" rel="nofollow noopener">mandoc</a></li>
<li>Check the <a href="http://www.openbsd.org/errata57.html" target="_blank" rel="nofollow noopener">errata page</a> for any post-release fixes, and the <a href="http://www.openbsd.org/faq/upgrade57.html" target="_blank" rel="nofollow noopener">upgrade guide</a> for specific instructions on updating from 5.6</li>
<li>Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases</li>
<li>There's a <a href="http://www.openbsd.org/lyrics.html#57" target="_blank" rel="nofollow noopener">song and artwork</a> to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week</li>
<li>Consider <a href="https://www.openbsdstore.com" target="_blank" rel="nofollow noopener">picking one up</a> to support the project (and it's the only way to get puffy stickers)</li>
<li>For those of you paying close attention, the <a href="http://www.openbsd.org/images/puffy57.gif" target="_blank" rel="nofollow noopener">banner image</a> for this release just might remind you of a <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener">certain special episode</a> of BSD Now...
***</li>
</ul>

<h3><a href="https://torbsd.github.io/" target="_blank" rel="nofollow noopener">Tor-BSD diversity project</a></h3>

<ul>
<li>We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)</li>
<li>A new initiative has started to do just that, called the Tor-BSD diversity project</li>
<li>"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."</li>
<li>In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy</li>
<li>There's an additional <a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" target="_blank" rel="nofollow noopener">progress report</a> for that part specifically, and it looks like most of the work is done now</li>
<li>Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list </li>
<li>If you've been considering running a node to help out, there's always <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">our handy tutorial</a> on getting set up
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" target="_blank" rel="nofollow noopener">PC-BSD 10.1.2-RC1 released</a></h3>

<ul>
<li>If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab</li>
<li>This quarterly update includes a number of new features, improvements and even some additional utilities</li>
<li>PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems</li>
<li>A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use</li>
<li>Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network</li>
<li>IPFW is now the default firewall, offering improved VIMAGE capabilities</li>
<li>The life preserver backup tool now allows for bare-metal restores via the install CD</li>
<li>ISC's NTP daemon has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" target="_blank" rel="nofollow noopener">OpenNTPD</a>, and OpenSSL has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" target="_blank" rel="nofollow noopener">LibreSSL</a></li>
<li>It also includes the latest <a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" target="_blank" rel="nofollow noopener">Lumina</a> desktop, and there's another <a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" target="_blank" rel="nofollow noopener">post dedicated to that</a></li>
<li>Binary packages have also been updated to fresh versions from the ports tree</li>
<li>More details, including upgrade instructions, can be found in the linked blog post
***</li>
</ul>

<h2>Interview - Ed Schouten - <a href="mailto:ed@freebsd.org" target="_blank" rel="nofollow noopener">ed@freebsd.org</a> / <a href="https://twitter.com/edschouten" target="_blank" rel="nofollow noopener">@edschouten</a></h2>

<p><a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" target="_blank" rel="nofollow noopener">CloudABI</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" target="_blank" rel="nofollow noopener">Open Household Router Contraption</a></h3>

<ul>
<li>This article introduces OpenHRC, the "Open Household Router Contraption"</li>
<li>In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device</li>
<li>It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup</li>
<li>Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation</li>
<li>All the code is open source <a href="https://github.com/ioc32/openhrc" target="_blank" rel="nofollow noopener">and on Github</a>, so you can read through what's actually being changed and put in place</li>
<li>There's also a <a href="https://www.youtube.com/watch?v=LZeKDM5jc90" target="_blank" rel="nofollow noopener">video guide</a> to the entire process, if you're more of a visual person
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=365.0" target="_blank" rel="nofollow noopener">OPNsense 15.1.10 released</a></h3>

<ul>
<li>Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version</li>
<li>15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code</li>
<li>Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree</li>
<li>Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed</li>
<li>NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well</li>
<li>Version <a href="https://twitter.com/opnsense/status/596009164746432512" target="_blank" rel="nofollow noopener">15.1.10.1</a> was released shortly thereafter, including a hotfix for VLANs
***</li>
</ul>

<h3><a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" target="_blank" rel="nofollow noopener">IBM Workpad Z50 and NetBSD</a></h3>

<ul>
<li>Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same</li>
<li>Back in 1999, they released <a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" target="_blank" rel="nofollow noopener">the Workpad Z50</a> with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display</li>
<li>You can probably tell where this is going... the article is about installing NetBSD it</li>
<li>"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"</li>
<li>The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern</li>
<li>He's also got a <a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" target="_blank" rel="nofollow noopener">couple</a> <a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" target="_blank" rel="nofollow noopener">videos</a> of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" target="_blank" rel="nofollow noopener">FreeBSD from the trenches</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases</li>
<li>In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI</li>
<li>While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually</li>
<li>Each command is explained, and he walks you through the process of doing <a href="http://www.bsdnow.tv/tutorials/fde" target="_blank" rel="nofollow noopener">an encrypted installation</a> on your root zpool
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" target="_blank" rel="nofollow noopener">Broadwell in DragonFly</a></h3>

<ul>
<li>DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver</li>
<li>Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too</li>
<li>It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216QQcHyX" target="_blank" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21hGSk3c0" target="_blank" rel="nofollow noopener">Hunter writes in</a></li>
<li><a href="http://slexy.org/view/s20JwPw9Je" target="_blank" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2x1GYr7y6" target="_blank" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s2swXxr2PX" target="_blank" rel="nofollow noopener">Sergei writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" target="_blank" rel="nofollow noopener">How did you guess</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" target="_blank" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" target="_blank" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" target="_blank" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" target="_blank" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted a report of the activities that went on between January and March of this year</li>
<li>As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)</li>
<li>The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter</li>
<li>The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward</li>
<li>FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team</li>
<li>Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code</li>
<li>Lots of activity is happening in bhyve, some of which we've covered <a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" target="_blank" rel="nofollow noopener">recently</a>, and a number of improvements were made this quarter</li>
<li>Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT</li>
<li>Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being</li>
<li>The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" target="_blank" rel="nofollow noopener">ASLR work</a> is still being done by the HardenedBSD guys, and their next aim is position-independent executable</li>
<li>The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more</li>
<li>Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***</li>
</ul>

<h3><a href="http://www.openbsd.org/57.html" target="_blank" rel="nofollow noopener">OpenBSD 5.7 released</a></h3>

<ul>
<li>OpenBSD has formally released another new version, complete with the giant changelog we've come to expect</li>
<li>In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs</li>
<li>If you're using one of the Soekris boards, there's even <a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" target="_blank" rel="nofollow noopener">a new driver</a> to manipulate the GPIO and LEDs on them - this has some fun possibilities</li>
<li>Some new security improvements include: <a href="https://en.wikipedia.org/wiki/SipHash" target="_blank" rel="nofollow noopener">SipHash</a> being sprinkled in some areas to protect hashing functions, big <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" target="_blank" rel="nofollow noopener">W<sup>X</sup> improvements</a> in the kernel space, <a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" target="_blank" rel="nofollow noopener">static PIE</a> on all architectures, deterministic "random" functions <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141807224826859&amp;w=2" target="_blank" rel="nofollow noopener">being replaced</a> with strong randomness, and support for remote logging over TLS</li>
<li>The entire source tree has also been audited to use <a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" target="_blank" rel="nofollow noopener">reallocarray</a>, which unintentionally <a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" target="_blank" rel="nofollow noopener">saved</a> OpenBSD's libc from being vulnerable to <a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" target="_blank" rel="nofollow noopener">earlier attacks</a> affecting other BSDs' implementations</li>
<li>Being that it's OpenBSD, a number of things have also been <em>removed</em> from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)</li>
<li>Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily</li>
<li>BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon</li>
<li>Speaking of httpd, it's gotten a number of <a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" target="_blank" rel="nofollow noopener">new</a> <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" target="_blank" rel="nofollow noopener">features</a>, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so</li>
<li>This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and <a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" target="_blank" rel="nofollow noopener">mandoc</a></li>
<li>Check the <a href="http://www.openbsd.org/errata57.html" target="_blank" rel="nofollow noopener">errata page</a> for any post-release fixes, and the <a href="http://www.openbsd.org/faq/upgrade57.html" target="_blank" rel="nofollow noopener">upgrade guide</a> for specific instructions on updating from 5.6</li>
<li>Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases</li>
<li>There's a <a href="http://www.openbsd.org/lyrics.html#57" target="_blank" rel="nofollow noopener">song and artwork</a> to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week</li>
<li>Consider <a href="https://www.openbsdstore.com" target="_blank" rel="nofollow noopener">picking one up</a> to support the project (and it's the only way to get puffy stickers)</li>
<li>For those of you paying close attention, the <a href="http://www.openbsd.org/images/puffy57.gif" target="_blank" rel="nofollow noopener">banner image</a> for this release just might remind you of a <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" target="_blank" rel="nofollow noopener">certain special episode</a> of BSD Now...
***</li>
</ul>

<h3><a href="https://torbsd.github.io/" target="_blank" rel="nofollow noopener">Tor-BSD diversity project</a></h3>

<ul>
<li>We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)</li>
<li>A new initiative has started to do just that, called the Tor-BSD diversity project</li>
<li>"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."</li>
<li>In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy</li>
<li>There's an additional <a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" target="_blank" rel="nofollow noopener">progress report</a> for that part specifically, and it looks like most of the work is done now</li>
<li>Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list </li>
<li>If you've been considering running a node to help out, there's always <a href="http://www.bsdnow.tv/tutorials/tor" target="_blank" rel="nofollow noopener">our handy tutorial</a> on getting set up
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" target="_blank" rel="nofollow noopener">PC-BSD 10.1.2-RC1 released</a></h3>

<ul>
<li>If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab</li>
<li>This quarterly update includes a number of new features, improvements and even some additional utilities</li>
<li>PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems</li>
<li>A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use</li>
<li>Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network</li>
<li>IPFW is now the default firewall, offering improved VIMAGE capabilities</li>
<li>The life preserver backup tool now allows for bare-metal restores via the install CD</li>
<li>ISC's NTP daemon has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" target="_blank" rel="nofollow noopener">OpenNTPD</a>, and OpenSSL has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" target="_blank" rel="nofollow noopener">LibreSSL</a></li>
<li>It also includes the latest <a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" target="_blank" rel="nofollow noopener">Lumina</a> desktop, and there's another <a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" target="_blank" rel="nofollow noopener">post dedicated to that</a></li>
<li>Binary packages have also been updated to fresh versions from the ports tree</li>
<li>More details, including upgrade instructions, can be found in the linked blog post
***</li>
</ul>

<h2>Interview - Ed Schouten - <a href="mailto:ed@freebsd.org" target="_blank" rel="nofollow noopener">ed@freebsd.org</a> / <a href="https://twitter.com/edschouten" target="_blank" rel="nofollow noopener">@edschouten</a></h2>

<p><a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" target="_blank" rel="nofollow noopener">CloudABI</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" target="_blank" rel="nofollow noopener">Open Household Router Contraption</a></h3>

<ul>
<li>This article introduces OpenHRC, the "Open Household Router Contraption"</li>
<li>In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device</li>
<li>It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup</li>
<li>Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation</li>
<li>All the code is open source <a href="https://github.com/ioc32/openhrc" target="_blank" rel="nofollow noopener">and on Github</a>, so you can read through what's actually being changed and put in place</li>
<li>There's also a <a href="https://www.youtube.com/watch?v=LZeKDM5jc90" target="_blank" rel="nofollow noopener">video guide</a> to the entire process, if you're more of a visual person
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=365.0" target="_blank" rel="nofollow noopener">OPNsense 15.1.10 released</a></h3>

<ul>
<li>Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version</li>
<li>15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code</li>
<li>Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree</li>
<li>Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed</li>
<li>NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well</li>
<li>Version <a href="https://twitter.com/opnsense/status/596009164746432512" target="_blank" rel="nofollow noopener">15.1.10.1</a> was released shortly thereafter, including a hotfix for VLANs
***</li>
</ul>

<h3><a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" target="_blank" rel="nofollow noopener">IBM Workpad Z50 and NetBSD</a></h3>

<ul>
<li>Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same</li>
<li>Back in 1999, they released <a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" target="_blank" rel="nofollow noopener">the Workpad Z50</a> with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display</li>
<li>You can probably tell where this is going... the article is about installing NetBSD it</li>
<li>"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"</li>
<li>The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern</li>
<li>He's also got a <a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" target="_blank" rel="nofollow noopener">couple</a> <a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" target="_blank" rel="nofollow noopener">videos</a> of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" target="_blank" rel="nofollow noopener">FreeBSD from the trenches</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases</li>
<li>In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI</li>
<li>While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually</li>
<li>Each command is explained, and he walks you through the process of doing <a href="http://www.bsdnow.tv/tutorials/fde" target="_blank" rel="nofollow noopener">an encrypted installation</a> on your root zpool
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" target="_blank" rel="nofollow noopener">Broadwell in DragonFly</a></h3>

<ul>
<li>DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver</li>
<li>Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too</li>
<li>It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216QQcHyX" target="_blank" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21hGSk3c0" target="_blank" rel="nofollow noopener">Hunter writes in</a></li>
<li><a href="http://slexy.org/view/s20JwPw9Je" target="_blank" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2x1GYr7y6" target="_blank" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s2swXxr2PX" target="_blank" rel="nofollow noopener">Sergei writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" target="_blank" rel="nofollow noopener">How did you guess</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
