<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Mon, 15 Jun 2026 02:05:36 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Marc Espie”</title>
    <link>https://www.bsdnow.tv/tags/marc%20espie</link>
    <pubDate>Wed, 25 Jun 2014 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>43: Package Design</title>
  <link>https://www.bsdnow.tv/43</link>
  <guid isPermaLink="false">d4b10034-d20a-44a6-a918-a57335debcae</guid>
  <pubDate>Wed, 25 Jun 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d4b10034-d20a-44a6-a918-a57335debcae.mp3" length="62389876" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:26:39</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener"&gt;EuroBSDCon 2014 talks and schedule&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The talks and schedules for EuroBSDCon 2014 are finally revealed&lt;/li&gt;
&lt;li&gt;The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh&lt;/li&gt;
&lt;li&gt;Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great&lt;/li&gt;
&lt;li&gt;It looks like Theo even has a talk, but the title isn't on the page... how mysterious&lt;/li&gt;
&lt;li&gt;There are also days dedicated to some really interesting tutorials&lt;/li&gt;
&lt;li&gt;Register now, the conference is on September 25-28th in Bulgaria&lt;/li&gt;
&lt;li&gt;If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen&lt;/li&gt;
&lt;li&gt;Why aren't the videos up from last year yet? Will this year also not have any?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener"&gt;FreeNAS vs NAS4Free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;More mainstream news covering BSD, this time with an article about different NAS solutions&lt;/li&gt;
&lt;li&gt;In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free&lt;/li&gt;
&lt;li&gt;Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect&lt;/li&gt;
&lt;li&gt;Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project&lt;/li&gt;
&lt;li&gt;"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener"&gt;Quality software costs money, heartbleed was free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener"&gt;PHK&lt;/a&gt; writes an article for ACM Queue about open source software projects' funding efforts&lt;/li&gt;
&lt;li&gt;A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc&lt;/li&gt;
&lt;li&gt;The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding&lt;/li&gt;
&lt;li&gt;The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them&lt;/li&gt;
&lt;li&gt;On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"&lt;/li&gt;
&lt;li&gt;Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener"&gt;Geoblock evasion with pf and OpenBSD rdomains&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Geoblocking is a way for websites to block visitors based on the location of their IP&lt;/li&gt;
&lt;li&gt;This is a blog post about how to get around it, using pf and rdomains&lt;/li&gt;
&lt;li&gt;It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;a tutorial about that&lt;/a&gt;...)&lt;/li&gt;
&lt;li&gt;In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia&lt;/li&gt;
&lt;li&gt;It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Marc Espie - &lt;a href="mailto:espie@openbsd.org" rel="nofollow noopener"&gt;espie@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/espie_openbsd" rel="nofollow noopener"&gt;@espie_openbsd&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's package system, building cluster, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener"&gt;Keeping your BSD up to date&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener"&gt;BoringSSL and LibReSSL&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Yet another OpenSSL fork pops up, this time from Google, called BoringSSL&lt;/li&gt;
&lt;li&gt;Adam Langley has a blog post about it, why they did it and how they're going to maintain it&lt;/li&gt;
&lt;li&gt;You can easily browse &lt;a href="https://boringssl.googlesource.com/" rel="nofollow noopener"&gt;the source code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Theo de Raadt also &lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140332790726752&amp;amp;w=2" rel="nofollow noopener"&gt;weighs in&lt;/a&gt; with how this effort relates to LibReSSL&lt;/li&gt;
&lt;li&gt;More eyes on the code is good, and patches will be shared between the two projects
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener"&gt;More BSD Tor nodes wanted&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener"&gt;Originally discussed&lt;/a&gt; on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network&lt;/li&gt;
&lt;li&gt;If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.&lt;/li&gt;
&lt;li&gt;The EFF is also holding a &lt;a href="https://www.eff.org/torchallenge/" rel="nofollow noopener"&gt;Tor challenge&lt;/a&gt; for people to start up new relays and keep them online for over a year&lt;/li&gt;
&lt;li&gt;Check out our &lt;a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener"&gt;Tor tutorial&lt;/a&gt; and help out the network, and promote BSD at the same time!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener"&gt;FreeBSD 10 OpenStack images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."&lt;/li&gt;
&lt;li&gt;The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"&lt;/li&gt;
&lt;li&gt;The author of the article is a regular listener and emailer of the show, hey!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener"&gt;BSDday 2014 call for papers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSD Day, a conference not so well-known, is going to be held August 9th in Argentina&lt;/li&gt;
&lt;li&gt;It was created in 2008 and is the only BSD conference around that area&lt;/li&gt;
&lt;li&gt;The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk&lt;/li&gt;
&lt;li&gt;Sysadmins, developers and regular users are, of course, all welcome to come to the event
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener"&gt;Maruf writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener"&gt;Solomon writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener"&gt;Silas writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener"&gt;Bert writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ports, packages, cluster, building, pkg_add, freenas, ixsystems, tarsnap, eurobsdcon, bulgaria, 2014, talks, presentation, slides, Poul-Henning Kamp, phk, schedule, freenas, nas4free, nas, geoblock, evasion, bypassing, ip ban, pf, firewall, rdomains, glusterfs, marc espie, boringssl, openssl, libressl, upgrades, how to upgrade, update, rebuild, tor, tor nodes, relays, exit node, eff, tor challenge, aslr, pie, security, bsdday, openstack, bsd-cloudinit, cloud computing</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's a big show this week! We'll be interviewing Marc Espie about OpenBSD's package system and build cluster. Also, we've been asked many times "how do I keep my BSD box up to date?" Well, today's tutorial should finally answer that. Answers to all your emails and this week's headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and schedule</a></h3>

<ul>
<li>The talks and schedules for EuroBSDCon 2014 are finally revealed</li>
<li>The opening keynote is called "FreeBSD, looking forward to another 10 years" by jkh</li>
<li>Lots of talks spanning FreeBSD, OpenBSD and PCBSD, and we finally have a few about NetBSD and DragonflyBSD too! Variety is great</li>
<li>It looks like Theo even has a talk, but the title isn't on the page... how mysterious</li>
<li>There are also days dedicated to some really interesting tutorials</li>
<li>Register now, the conference is on September 25-28th in Bulgaria</li>
<li>If you see Allan and Kris walking towards you and you haven't given us an interview yet... well you know what's going to happen</li>
<li>Why aren't the videos up from last year yet? Will this year also not have any?
***</li>
</ul>

<h3><a href="http://arstechnica.com/information-technology/2014/06/the-ars-nas-distribution-shootout-freenas-vs-nas4free/" rel="nofollow noopener">FreeNAS vs NAS4Free</a></h3>

<ul>
<li>More mainstream news covering BSD, this time with an article about different NAS solutions</li>
<li>In a possibly excessive eight-page article, Ars Technica discusses the pros and cons of both FreeNAS and NAS4Free</li>
<li>Both are based on FreeBSD and ZFS of course, but there are more differences than you might expect</li>
<li>Discusses the different development models, release cycles, features, interfaces and ease-of-use factor of each project</li>
<li>"One is pleasantly functional; the other continues devolving during a journey of pain" - uh oh, who's the loser?
***</li>
</ul>

<h3><a href="https://queue.acm.org/detail.cfm?id=2636165" rel="nofollow noopener">Quality software costs money, heartbleed was free</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">PHK</a> writes an article for ACM Queue about open source software projects' funding efforts</li>
<li>A lot of people don't realize just how widespread open source software is - TVs, printers, gaming consoles, etc</li>
<li>The article discusses ways to convince your workplace to fund open source efforts, then goes into a little bit about FreeBSD and Varnish's funding</li>
<li>The latest heartbleed vulnerability should teach everyone that open source projects are critical to the internet, and need people actively maintaining them</li>
<li>On that subject, "Earlier this year the OpenSSL Heartbleed bug laid waste to Internet security, and there are still hundreds of thousands of embedded devices of all kinds—probably your television among them—that have not been and will not ever be software-upgraded to fix it. The best way to prevent that from happening again is to avoid having bugs of that kind go undiscovered for several years, and the only way to avoid that is to have competent people paying attention to the software"</li>
<li>Consider donating to your favorite BSD foundation (or buying cool shirts and CDs!) and keeping the ecosystem alive
***</li>
</ul>

<h3><a href="https://matt.bionicmessage.net/blog/2014/06/21/Advanced%20Geoblock%20evasion%20with%20OpenBSD%20pf%20and%20rdomain%27s" rel="nofollow noopener">Geoblock evasion with pf and OpenBSD rdomains</a></h3>

<ul>
<li>Geoblocking is a way for websites to block visitors based on the location of their IP</li>
<li>This is a blog post about how to get around it, using pf and rdomains</li>
<li>It has the advantage of not requiring any browser plugins or DNS settings on the users' computers, you just need to be running OpenBSD on your router (hmm, if only a website had <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">a tutorial about that</a>...)</li>
<li>In this post, the author wanted to get an American IP address, since the service he was using (Netflix) is blocked in Australia</li>
<li>It's got all the details you need to set up a VPN-like system and bypass those pesky geographic filters
***</li>
</ul>

<h2>Interview - Marc Espie - <a href="mailto:espie@openbsd.org" rel="nofollow noopener">espie@openbsd.org</a> / <a href="https://twitter.com/espie_openbsd" rel="nofollow noopener">@espie_openbsd</a></h2>

<p>OpenBSD's package system, building cluster, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/upgrade" rel="nofollow noopener">Keeping your BSD up to date</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.imperialviolet.org/2014/06/20/boringssl.html" rel="nofollow noopener">BoringSSL and LibReSSL</a></h3>

<ul>
<li>Yet another OpenSSL fork pops up, this time from Google, called BoringSSL</li>
<li>Adam Langley has a blog post about it, why they did it and how they're going to maintain it</li>
<li>You can easily browse <a href="https://boringssl.googlesource.com/" rel="nofollow noopener">the source code</a></li>
<li>Theo de Raadt also <a href="http://marc.info/?l=openbsd-tech&amp;m=140332790726752&amp;w=2" rel="nofollow noopener">weighs in</a> with how this effort relates to LibReSSL</li>
<li>More eyes on the code is good, and patches will be shared between the two projects
***</li>
</ul>

<h3><a href="http://lists.nycbug.org/pipermail/tor-bsd/2014-June/000129.html" rel="nofollow noopener">More BSD Tor nodes wanted</a></h3>

<ul>
<li>Friend of the show bcallah posts some news to the Tor-BSD mailing list about monoculture in the Tor network being both bad and dangerous</li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2014-June/004699.html" rel="nofollow noopener">Originally discussed</a> on the Tor-Relays list, it was made apparent that having such a large amount of Linux nodes weakens the security of the whole network</li>
<li>If one vulnerability is found, a huge portion of the network would be useless - we need more variety in the network stacks, crypto, etc.</li>
<li>The EFF is also holding a <a href="https://www.eff.org/torchallenge/" rel="nofollow noopener">Tor challenge</a> for people to start up new relays and keep them online for over a year</li>
<li>Check out our <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">Tor tutorial</a> and help out the network, and promote BSD at the same time!
***</li>
</ul>

<h3><a href="https://raymii.org/s/tutorials/FreeBSD_10.0-release_Openstack_Image.html" rel="nofollow noopener">FreeBSD 10 OpenStack images</a></h3>

<ul>
<li>OpenStack, to quote Wikipedia, is "a free and open-source software cloud computing platform. It is primarily deployed as an infrastructure as a service (IaaS) solution."</li>
<li>The article goes into detail about creating a FreeBSD instant, installing and converting it for use with "bsd-cloudinit"</li>
<li>The author of the article is a regular listener and emailer of the show, hey!
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2014-June/004465.html" rel="nofollow noopener">BSDday 2014 call for papers</a></h3>

<ul>
<li>BSD Day, a conference not so well-known, is going to be held August 9th in Argentina</li>
<li>It was created in 2008 and is the only BSD conference around that area</li>
<li>The "call for papers" was issued, so if you're around Argentina and use BSD, consider submitting a talk</li>
<li>Sysadmins, developers and regular users are, of course, all welcome to come to the event
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20nTYO2w1" rel="nofollow noopener">Maruf writes in</a></li>
<li><a href="http://slexy.org/view/s21cvV6mRP" rel="nofollow noopener">Solomon writes in</a></li>
<li><a href="http://slexy.org/view/s2MK8sbea0" rel="nofollow noopener">Silas writes in</a></li>
<li><a href="http://slexy.org/view/s2Yz97YlzI" rel="nofollow noopener">Bert writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>33: Certified Package Delivery</title>
  <link>https://www.bsdnow.tv/33</link>
  <guid isPermaLink="false">f0c15113-8ade-464b-a89f-3398734256dc</guid>
  <pubDate>Wed, 16 Apr 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/f0c15113-8ade-464b-a89f-3398734256dc.mp3" length="57837748" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:19</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener"&gt;BSDCan schedule, speakers and talks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's BSDCan will kick off on May 14th in Ottawa&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener"&gt;list of speakers&lt;/a&gt; is also out&lt;/li&gt;
&lt;li&gt;And finally &lt;a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener"&gt;the talks&lt;/a&gt; everyone's looking forward to&lt;/li&gt;
&lt;li&gt;Lots of great tutorials and talks, spanning a wide range of topics of interest&lt;/li&gt;
&lt;li&gt;Be sure to come by so you can and meet Allan and Kris in person &lt;a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener"&gt;and get BSDCan shirts&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener"&gt;NYCBSDCon talks uploaded&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon&lt;/li&gt;
&lt;li&gt;Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener"&gt;Dru Lavigne's talk&lt;/a&gt;, "ZFS Management Tools in FreeNAS and PC-BSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener"&gt;Scott Long's talk&lt;/a&gt;, "Serving one third of the Internet via FreeBSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener"&gt;Michael W. Lucas' talk&lt;/a&gt;, "BSD Breaking Barriers"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener"&gt;FreeBSD Journal, issue 2&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The bi-monthly FreeBSD journal's second issue is out&lt;/li&gt;
&lt;li&gt;Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates&lt;/li&gt;
&lt;li&gt;In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc&lt;/li&gt;
&lt;li&gt;"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"&lt;/li&gt;
&lt;li&gt;Check &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;our interview with GNN&lt;/a&gt; for more information about the journal
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener"&gt;OpenSSL, more like OpenSS-Hell&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy&lt;/li&gt;
&lt;li&gt;There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so&lt;/li&gt;
&lt;li&gt;We finally have &lt;a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener"&gt;a timeline of events&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reactions from &lt;a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener"&gt;ISC&lt;/a&gt;, &lt;a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener"&gt;PCBSD&lt;/a&gt;, &lt;a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;, the &lt;a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener"&gt;Tor&lt;/a&gt; &lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener"&gt;project&lt;/a&gt;, &lt;a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener"&gt;NetBSD&lt;/a&gt;, &lt;a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener"&gt;oss-sec&lt;/a&gt;, &lt;a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener"&gt;PHK&lt;/a&gt;, &lt;a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener"&gt;Varnish&lt;/a&gt; and &lt;a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener"&gt;Akamai&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;pfSense&lt;/a&gt; released &lt;a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener"&gt;a new version to fix it&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenBSD &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139715336230455&amp;amp;w=2" rel="nofollow noopener"&gt;disabled heartbeat entirely&lt;/a&gt; and is very &lt;a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener"&gt;unforgiving of the IETF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has two &lt;a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener"&gt;good&lt;/a&gt; &lt;a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener"&gt;write-ups&lt;/a&gt; about the issue and how horrible the OpenSSL codebase is&lt;/li&gt;
&lt;li&gt;A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"&lt;/li&gt;
&lt;li&gt;Sounds like &lt;a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener"&gt;someone else&lt;/a&gt; was having fun with the bug for a while too&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;There's also another OpenSSL bug&lt;/strong&gt; that &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139732441810737&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD patched&lt;/a&gt; - it allows an attacker to &lt;strong&gt;inject data from one connection into another&lt;/strong&gt; &lt;/li&gt;
&lt;li&gt;OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140415093252" rel="nofollow noopener"&gt;seeing a fork&lt;/a&gt; in real time
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jim Brown - &lt;a href="mailto:info@bsdcertification.org" rel="nofollow noopener"&gt;info@bsdcertification.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href="http://bsdcertification.org/" rel="nofollow noopener"&gt;BSD Certification&lt;/a&gt; exams&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener"&gt;Building OpenBSD binary packages in bulk&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/aperezdc/signify" rel="nofollow noopener"&gt;Portable signify&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back in &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;episode 23&lt;/a&gt; we talked with Ted Unangst about the new "signify" tool in OpenBSD&lt;/li&gt;
&lt;li&gt;Now there's a (completely unofficial) portable version of it on github&lt;/li&gt;
&lt;li&gt;If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it&lt;/li&gt;
&lt;li&gt;Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener"&gt;Foundation goals and updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenBSD foundation has reached their 2014 goal of $150,000&lt;/li&gt;
&lt;li&gt;You can check &lt;a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener"&gt;their activities and goals&lt;/a&gt; to see where the money is going&lt;/li&gt;
&lt;li&gt;Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data&lt;/li&gt;
&lt;li&gt;The FreeBSD foundation has kicked off their &lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener"&gt;spring fundraising&lt;/a&gt; campaign&lt;/li&gt;
&lt;li&gt;There's also a list of their activities and goals available to read through&lt;/li&gt;
&lt;li&gt;Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New PBI runtime that fixes stability issues and decreases load times&lt;/li&gt;
&lt;li&gt;"Update Center" is getting a lot of development and improvements&lt;/li&gt;
&lt;li&gt;Lots of misc. bug fixes and updates
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener"&gt;There's a reddit thread&lt;/a&gt; we wanted to highlight - a user wants to show his friend BSD and why it's great&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener"&gt;iGibbs writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener"&gt;Matt writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, dpb, distributed ports builder, marc espie, poudriere, package builds, jim brown, bsdcertification, bsd certification, exam, test, openssl, heartbleed, exploit, ssl, tls, heartbeat, openssh, theo de raadt, hole, 0day, zero day, bsdcan, nycbsdcon, presentations, talks, conference, recording, netflix, tarsnap, mitigation, ixsystems, foundation, journal, cve</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
