<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app03</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 09:03:38 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Meetbsd”</title>
    <link>https://www.bsdnow.tv/tags/meetbsd</link>
    <pubDate>Wed, 02 Sep 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>105: Virginia BSD Assembly</title>
  <link>https://www.bsdnow.tv/105</link>
  <guid isPermaLink="false">09c955b0-1ecf-440f-9aa9-80dc2fb05a49</guid>
  <pubDate>Wed, 02 Sep 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/09c955b0-1ecf-440f-9aa9-80dc2fb05a49.mp3" length="47635924" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</itunes:subtitle>
  <itunes:duration>1:06:09</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=144104398132541&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD hypervisor coming soon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy Mike Larkin never rests, and he posted some very tight-lipped &lt;a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener"&gt;console output&lt;/a&gt; on Twitter recently&lt;/li&gt;
&lt;li&gt;From what little he revealed &lt;a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener"&gt;at the time&lt;/a&gt;, it appeared to be a new &lt;a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener"&gt;hypervisor&lt;/a&gt; (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"&lt;/li&gt;
&lt;li&gt;Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is&lt;/li&gt;
&lt;li&gt;Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation&lt;/li&gt;
&lt;li&gt;One thing to note: this &lt;strong&gt;isn't&lt;/strong&gt; just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route&lt;/li&gt;
&lt;li&gt;He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener"&gt;Why FreeBSD should not adopt launchd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener"&gt;Last week&lt;/a&gt; we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD&lt;/li&gt;
&lt;li&gt;One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)&lt;/li&gt;
&lt;li&gt;In this article, the author talks about why he thinks this is a bad idea&lt;/li&gt;
&lt;li&gt;He doesn't oppose the integration into FreeBSD-&lt;em&gt;derived&lt;/em&gt; projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail&lt;/li&gt;
&lt;li&gt;The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities&lt;/li&gt;
&lt;li&gt;Reddit had &lt;a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener"&gt;quite a bit&lt;/a&gt; &lt;a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener"&gt;to say&lt;/a&gt; about this one, some in agreement and some not
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener"&gt;DragonFly graphics improvements&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack&lt;/li&gt;
&lt;li&gt;This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs&lt;/li&gt;
&lt;li&gt;You should also see some power management improvements, longer battery life and various other bug fixes&lt;/li&gt;
&lt;li&gt;If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=144070638327053&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD tames the userland&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are&lt;/li&gt;
&lt;li&gt;Theo posted a &lt;em&gt;mega diff&lt;/em&gt; of nearly 100 smaller diffs, adding tame support to many areas of the userland tools&lt;/li&gt;
&lt;li&gt;It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)&lt;/li&gt;
&lt;li&gt;Some classic utilities are even being reworked to make taming them easier - &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144103945031253&amp;amp;w=2" rel="nofollow noopener"&gt;the "w" command&lt;/a&gt;, for example&lt;/li&gt;
&lt;li&gt;The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener"&gt;on HN&lt;/a&gt;, as one might expect&lt;/li&gt;
&lt;li&gt;If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Scott Courtney - &lt;a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener"&gt;vbsdcon@verisign.com&lt;/a&gt; / &lt;a href="https://twitter.com/verisign" rel="nofollow noopener"&gt;@verisign&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://vbsdcon.com/" rel="nofollow noopener"&gt;vBSDCon&lt;/a&gt; 2015&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener"&gt;OPNsense, beyond the fork&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We first &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;heard about&lt;/a&gt; OPNsense back in January, and they've since released nearly &lt;strong&gt;40&lt;/strong&gt; versions, spanning over &lt;strong&gt;5,000&lt;/strong&gt; commits&lt;/li&gt;
&lt;li&gt;This is their first big status update, covering some of the things that've happened since the project was born&lt;/li&gt;
&lt;li&gt;There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150827112006" rel="nofollow noopener"&gt;LibreSSL nukes SSLv3&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With their latest release, LibreSSL began to turn off &lt;a href="http://disablessl3.com" rel="nofollow noopener"&gt;SSLv3&lt;/a&gt; support, starting with the "openssl" command&lt;/li&gt;
&lt;li&gt;At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)&lt;/li&gt;
&lt;li&gt;They've now flipped the switch, and the process of complete removal has started&lt;/li&gt;
&lt;li&gt;From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"&lt;/li&gt;
&lt;li&gt;With this change and a few more to follow shortly, Libre*SSL* won't actually &lt;em&gt;support SSL&lt;/em&gt; anymore - time to rename it "LibreTLS"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener"&gt;FreeBSD MPTCP updated&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For anyone unaware, &lt;a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener"&gt;Multipath TCP&lt;/a&gt; is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."&lt;/li&gt;
&lt;li&gt;There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated&lt;/li&gt;
&lt;li&gt;Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements&lt;/li&gt;
&lt;li&gt;Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144092912907778&amp;amp;w=2" rel="nofollow noopener"&gt;UEFI and GPT in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently&lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener"&gt;support&lt;/a&gt; for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review&lt;/li&gt;
&lt;li&gt;This comes along with a &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=143732984925140&amp;amp;w=2" rel="nofollow noopener"&gt;number&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144088136200753&amp;amp;w=2" rel="nofollow noopener"&gt;of&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144046793225230&amp;amp;w=2" rel="nofollow noopener"&gt;other&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144045760723039&amp;amp;w=2" rel="nofollow noopener"&gt;commits&lt;/a&gt; related to GPT, much of which is being refactored and slowly reintroduced&lt;/li&gt;
&lt;li&gt;Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)&lt;/li&gt;
&lt;li&gt;The UEFI bootloader support &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144115942223734&amp;amp;w=2" rel="nofollow noopener"&gt;has been committed&lt;/a&gt;, so stay tuned for &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150902074526&amp;amp;mode=flat" rel="nofollow noopener"&gt;more updates&lt;/a&gt; as &lt;a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener"&gt;further&lt;/a&gt; &lt;a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener"&gt;progress&lt;/a&gt; is made
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener"&gt;Mason writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener"&gt;Earl writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, verisign, vbsdcon, conference, eurobsdcon, bsdcan, meetbsd, asiabsdcon, nextbsd, launchd, darwin, tame, mach, libressl, vmm, hypervisor, bhyve, multipath, tcp</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144104398132541&amp;w=2" rel="nofollow noopener">OpenBSD hypervisor coming soon</a></h3>

<ul>
<li>Our buddy Mike Larkin never rests, and he posted some very tight-lipped <a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener">console output</a> on Twitter recently</li>
<li>From what little he revealed <a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener">at the time</a>, it appeared to be a new <a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener">hypervisor</a> (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"</li>
<li>Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is</li>
<li>Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation</li>
<li>One thing to note: this <strong>isn't</strong> just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route</li>
<li>He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***</li>
</ul>

<h3><a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener">Why FreeBSD should not adopt launchd</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener">Last week</a> we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD</li>
<li>One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)</li>
<li>In this article, the author talks about why he thinks this is a bad idea</li>
<li>He doesn't oppose the integration into FreeBSD-<em>derived</em> projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail</li>
<li>The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities</li>
<li>Reddit had <a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener">quite a bit</a> <a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener">to say</a> about this one, some in agreement and some not
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener">DragonFly graphics improvements</a></h3>

<ul>
<li>The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack</li>
<li>This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs</li>
<li>You should also see some power management improvements, longer battery life and various other bug fixes</li>
<li>If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144070638327053&amp;w=2" rel="nofollow noopener">OpenBSD tames the userland</a></h3>

<ul>
<li>Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are</li>
<li>Theo posted a <em>mega diff</em> of nearly 100 smaller diffs, adding tame support to many areas of the userland tools</li>
<li>It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)</li>
<li>Some classic utilities are even being reworked to make taming them easier - <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144103945031253&amp;w=2" rel="nofollow noopener">the "w" command</a>, for example</li>
<li>The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener">on HN</a>, as one might expect</li>
<li>If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***</li>
</ul>

<h2>Interview - Scott Courtney - <a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener">vbsdcon@verisign.com</a> / <a href="https://twitter.com/verisign" rel="nofollow noopener">@verisign</a></h2>

<p><a href="http://vbsdcon.com/" rel="nofollow noopener">vBSDCon</a> 2015</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener">OPNsense, beyond the fork</a></h3>

<ul>
<li>We first <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">heard about</a> OPNsense back in January, and they've since released nearly <strong>40</strong> versions, spanning over <strong>5,000</strong> commits</li>
<li>This is their first big status update, covering some of the things that've happened since the project was born</li>
<li>There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150827112006" rel="nofollow noopener">LibreSSL nukes SSLv3</a></h3>

<ul>
<li>With their latest release, LibreSSL began to turn off <a href="http://disablessl3.com" rel="nofollow noopener">SSLv3</a> support, starting with the "openssl" command</li>
<li>At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)</li>
<li>They've now flipped the switch, and the process of complete removal has started</li>
<li>From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"</li>
<li>With this change and a few more to follow shortly, Libre*SSL* won't actually <em>support SSL</em> anymore - time to rename it "LibreTLS"
***</li>
</ul>

<h3><a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener">FreeBSD MPTCP updated</a></h3>

<ul>
<li>For anyone unaware, <a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener">Multipath TCP</a> is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."</li>
<li>There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated</li>
<li>Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements</li>
<li>Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144092912907778&amp;w=2" rel="nofollow noopener">UEFI and GPT in OpenBSD</a></h3>

<ul>
<li>There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently</li>
<li>Some <a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener">support</a> for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review</li>
<li>This comes along with a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143732984925140&amp;w=2" rel="nofollow noopener">number</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144088136200753&amp;w=2" rel="nofollow noopener">of</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144046793225230&amp;w=2" rel="nofollow noopener">other</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144045760723039&amp;w=2" rel="nofollow noopener">commits</a> related to GPT, much of which is being refactored and slowly reintroduced</li>
<li>Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)</li>
<li>The UEFI bootloader support <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144115942223734&amp;w=2" rel="nofollow noopener">has been committed</a>, so stay tuned for <a href="http://undeadly.org/cgi?action=article&amp;sid=20150902074526&amp;mode=flat" rel="nofollow noopener">more updates</a> as <a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener">further</a> <a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener">progress</a> is made
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener">Earl writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144104398132541&amp;w=2" rel="nofollow noopener">OpenBSD hypervisor coming soon</a></h3>

<ul>
<li>Our buddy Mike Larkin never rests, and he posted some very tight-lipped <a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener">console output</a> on Twitter recently</li>
<li>From what little he revealed <a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener">at the time</a>, it appeared to be a new <a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener">hypervisor</a> (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"</li>
<li>Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is</li>
<li>Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation</li>
<li>One thing to note: this <strong>isn't</strong> just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route</li>
<li>He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***</li>
</ul>

<h3><a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener">Why FreeBSD should not adopt launchd</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener">Last week</a> we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD</li>
<li>One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)</li>
<li>In this article, the author talks about why he thinks this is a bad idea</li>
<li>He doesn't oppose the integration into FreeBSD-<em>derived</em> projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail</li>
<li>The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities</li>
<li>Reddit had <a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener">quite a bit</a> <a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener">to say</a> about this one, some in agreement and some not
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener">DragonFly graphics improvements</a></h3>

<ul>
<li>The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack</li>
<li>This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs</li>
<li>You should also see some power management improvements, longer battery life and various other bug fixes</li>
<li>If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144070638327053&amp;w=2" rel="nofollow noopener">OpenBSD tames the userland</a></h3>

<ul>
<li>Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are</li>
<li>Theo posted a <em>mega diff</em> of nearly 100 smaller diffs, adding tame support to many areas of the userland tools</li>
<li>It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)</li>
<li>Some classic utilities are even being reworked to make taming them easier - <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144103945031253&amp;w=2" rel="nofollow noopener">the "w" command</a>, for example</li>
<li>The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener">on HN</a>, as one might expect</li>
<li>If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***</li>
</ul>

<h2>Interview - Scott Courtney - <a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener">vbsdcon@verisign.com</a> / <a href="https://twitter.com/verisign" rel="nofollow noopener">@verisign</a></h2>

<p><a href="http://vbsdcon.com/" rel="nofollow noopener">vBSDCon</a> 2015</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener">OPNsense, beyond the fork</a></h3>

<ul>
<li>We first <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">heard about</a> OPNsense back in January, and they've since released nearly <strong>40</strong> versions, spanning over <strong>5,000</strong> commits</li>
<li>This is their first big status update, covering some of the things that've happened since the project was born</li>
<li>There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150827112006" rel="nofollow noopener">LibreSSL nukes SSLv3</a></h3>

<ul>
<li>With their latest release, LibreSSL began to turn off <a href="http://disablessl3.com" rel="nofollow noopener">SSLv3</a> support, starting with the "openssl" command</li>
<li>At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)</li>
<li>They've now flipped the switch, and the process of complete removal has started</li>
<li>From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"</li>
<li>With this change and a few more to follow shortly, Libre*SSL* won't actually <em>support SSL</em> anymore - time to rename it "LibreTLS"
***</li>
</ul>

<h3><a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener">FreeBSD MPTCP updated</a></h3>

<ul>
<li>For anyone unaware, <a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener">Multipath TCP</a> is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."</li>
<li>There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated</li>
<li>Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements</li>
<li>Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144092912907778&amp;w=2" rel="nofollow noopener">UEFI and GPT in OpenBSD</a></h3>

<ul>
<li>There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently</li>
<li>Some <a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener">support</a> for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review</li>
<li>This comes along with a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143732984925140&amp;w=2" rel="nofollow noopener">number</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144088136200753&amp;w=2" rel="nofollow noopener">of</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144046793225230&amp;w=2" rel="nofollow noopener">other</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144045760723039&amp;w=2" rel="nofollow noopener">commits</a> related to GPT, much of which is being refactored and slowly reintroduced</li>
<li>Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)</li>
<li>The UEFI bootloader support <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144115942223734&amp;w=2" rel="nofollow noopener">has been committed</a>, so stay tuned for <a href="http://undeadly.org/cgi?action=article&amp;sid=20150902074526&amp;mode=flat" rel="nofollow noopener">more updates</a> as <a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener">further</a> <a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener">progress</a> is made
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener">Earl writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>66: Conference Connoisseur</title>
  <link>https://www.bsdnow.tv/66</link>
  <guid isPermaLink="false">e76cf015-25d3-4a75-89c3-629d1f6d9a87</guid>
  <pubDate>Wed, 03 Dec 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e76cf015-25d3-4a75-89c3-629d1f6d9a87.mp3" length="59426068" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:22:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.meetbsd.com/" rel="nofollow noopener"&gt;More BSD presentation videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch&lt;/li&gt;
&lt;li&gt;Corey Vixie, &lt;a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener"&gt;Web Apps in Embedded BSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Allan Jude, &lt;a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener"&gt;UCL config&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kip Macy, &lt;a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener"&gt;iflib&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;While we're on the topic of conferences, AsiaBSDCon's CFP was &lt;a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener"&gt;extended&lt;/a&gt; by one week&lt;/li&gt;
&lt;li&gt;This year's &lt;a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener"&gt;ruBSD&lt;/a&gt; will be on December 13th in Moscow&lt;/li&gt;
&lt;li&gt;Also, the &lt;a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener"&gt;BSDCan call for papers&lt;/a&gt; is out, and the event will be in June next year&lt;/li&gt;
&lt;li&gt;Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener"&gt;BSD-powered digital library in Africa&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access&lt;/li&gt;
&lt;li&gt;With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school&lt;/li&gt;
&lt;li&gt;They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)&lt;/li&gt;
&lt;li&gt;The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener"&gt;pfSense 2.2 status update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update&lt;/li&gt;
&lt;li&gt;2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc&lt;/li&gt;
&lt;li&gt;All these things have taken more time than previously expected&lt;/li&gt;
&lt;li&gt;The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener"&gt;Recommended hardware threads&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A few threads on caught our attention this week, all about hardware recommendations for BSD setups&lt;/li&gt;
&lt;li&gt;In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS&lt;/li&gt;
&lt;li&gt;Everyone gave some good recommendations for low power, Atom-based systems&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.marc.info/?t=141694918800006&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;second thread&lt;/a&gt; started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread&lt;/li&gt;
&lt;li&gt;For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the &lt;a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener"&gt;third&lt;/a&gt; and &lt;a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener"&gt;fourth&lt;/a&gt; threads confirming this&lt;/li&gt;
&lt;li&gt;If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Paul Schenkeveld - &lt;a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener"&gt;freebsd@psconsult.nl&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Running a BSD conference&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener"&gt;From Linux to FreeBSD - for reals&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)&lt;/li&gt;
&lt;li&gt;After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition&lt;/li&gt;
&lt;li&gt;In the comments, a lot of new switchers offer some advice and reading material&lt;/li&gt;
&lt;li&gt;If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener"&gt;Running FreeBSD as a Xen Dom0&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor&lt;/li&gt;
&lt;li&gt;This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it&lt;/li&gt;
&lt;li&gt;Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)&lt;/li&gt;
&lt;li&gt;The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener"&gt;HardenedBSD updates and changes&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;a.out is the old executable format for Unix&lt;/li&gt;
&lt;li&gt;The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968&lt;/li&gt;
&lt;li&gt;FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0&lt;/li&gt;
&lt;li&gt;A restriction against NULL mapping was introduced in &lt;a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener"&gt;FreeBSD 7&lt;/a&gt; and enabled by default in FreeBSD 8&lt;/li&gt;
&lt;li&gt;However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited&lt;/li&gt;
&lt;li&gt;HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’&lt;/li&gt;
&lt;li&gt;Package building update: &lt;a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener"&gt;more consistent repo, no more i386 packages &lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener"&gt;Boris writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt; (&lt;b&gt;edit:&lt;/b&gt; adding "tinker panic 0" to the ntp.conf will disable the sanity check)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener"&gt;Robert writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener"&gt;Jake writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141711266800001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;Real world authpf use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;amp;r2=373563&amp;amp;pathrev=373564" rel="nofollow noopener"&gt;The&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener"&gt;great&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener"&gt;perl&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener"&gt;event&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener"&gt;of&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener"&gt;2014&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, eurobsdcon, meetbsd, bsdcan, asiabsdcon, conference, community, organization, foundation, pfsense, soekris, router, alix, apu, netgate, pcengines</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">More BSD presentation videos</a></h3>

<ul>
<li>The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch</li>
<li>Corey Vixie, <a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener">Web Apps in Embedded BSD</a></li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener">UCL config</a></li>
<li>Kip Macy, <a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener">iflib</a></li>
<li>While we're on the topic of conferences, AsiaBSDCon's CFP was <a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener">extended</a> by one week</li>
<li>This year's <a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener">ruBSD</a> will be on December 13th in Moscow</li>
<li>Also, the <a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener">BSDCan call for papers</a> is out, and the event will be in June next year</li>
<li>Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***</li>
</ul>

<h3><a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener">BSD-powered digital library in Africa</a></h3>

<ul>
<li>You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access</li>
<li>With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school</li>
<li>They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)</li>
<li>The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener">pfSense 2.2 status update</a></h3>

<ul>
<li>With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update</li>
<li>2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc</li>
<li>All these things have taken more time than previously expected</li>
<li>The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener">Recommended hardware threads</a></h3>

<ul>
<li>A few threads on caught our attention this week, all about hardware recommendations for BSD setups</li>
<li>In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS</li>
<li>Everyone gave some good recommendations for low power, Atom-based systems</li>
<li>The <a href="https://www.marc.info/?t=141694918800006&amp;r=1&amp;w=2" rel="nofollow noopener">second thread</a> started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread</li>
<li>For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the <a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener">third</a> and <a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener">fourth</a> threads confirming this</li>
<li>If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***</li>
</ul>

<h2>Interview - Paul Schenkeveld - <a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener">freebsd@psconsult.nl</a></h2>

<p>Running a BSD conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener">From Linux to FreeBSD - for reals</a></h3>

<ul>
<li>Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)</li>
<li>After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition</li>
<li>In the comments, a lot of new switchers offer some advice and reading material</li>
<li>If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***</li>
</ul>

<h3><a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener">Running FreeBSD as a Xen Dom0</a></h3>

<ul>
<li>Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor</li>
<li>This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it</li>
<li>Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)</li>
<li>The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener">HardenedBSD updates and changes</a></h3>

<ul>
<li>a.out is the old executable format for Unix</li>
<li>The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968</li>
<li>FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0</li>
<li>A restriction against NULL mapping was introduced in <a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener">FreeBSD 7</a> and enabled by default in FreeBSD 8</li>
<li>However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited</li>
<li>HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’</li>
<li>Package building update: <a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener">more consistent repo, no more i386 packages </a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener">Boris writes in</a></li>
<li><a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener">Alex writes in</a> (<b>edit:</b> adding "tinker panic 0" to the ntp.conf will disable the sanity check)</li>
<li><a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener">Jake writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141711266800001&amp;r=1&amp;w=2" rel="nofollow noopener">Real world authpf use</a></li>
<li><a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;r2=373563&amp;pathrev=373564" rel="nofollow noopener">The</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener">great</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener">perl</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener">event</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener">of</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener">2014</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">More BSD presentation videos</a></h3>

<ul>
<li>The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch</li>
<li>Corey Vixie, <a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener">Web Apps in Embedded BSD</a></li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener">UCL config</a></li>
<li>Kip Macy, <a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener">iflib</a></li>
<li>While we're on the topic of conferences, AsiaBSDCon's CFP was <a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener">extended</a> by one week</li>
<li>This year's <a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener">ruBSD</a> will be on December 13th in Moscow</li>
<li>Also, the <a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener">BSDCan call for papers</a> is out, and the event will be in June next year</li>
<li>Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***</li>
</ul>

<h3><a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener">BSD-powered digital library in Africa</a></h3>

<ul>
<li>You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access</li>
<li>With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school</li>
<li>They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)</li>
<li>The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener">pfSense 2.2 status update</a></h3>

<ul>
<li>With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update</li>
<li>2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc</li>
<li>All these things have taken more time than previously expected</li>
<li>The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener">Recommended hardware threads</a></h3>

<ul>
<li>A few threads on caught our attention this week, all about hardware recommendations for BSD setups</li>
<li>In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS</li>
<li>Everyone gave some good recommendations for low power, Atom-based systems</li>
<li>The <a href="https://www.marc.info/?t=141694918800006&amp;r=1&amp;w=2" rel="nofollow noopener">second thread</a> started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread</li>
<li>For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the <a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener">third</a> and <a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener">fourth</a> threads confirming this</li>
<li>If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***</li>
</ul>

<h2>Interview - Paul Schenkeveld - <a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener">freebsd@psconsult.nl</a></h2>

<p>Running a BSD conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener">From Linux to FreeBSD - for reals</a></h3>

<ul>
<li>Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)</li>
<li>After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition</li>
<li>In the comments, a lot of new switchers offer some advice and reading material</li>
<li>If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***</li>
</ul>

<h3><a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener">Running FreeBSD as a Xen Dom0</a></h3>

<ul>
<li>Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor</li>
<li>This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it</li>
<li>Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)</li>
<li>The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener">HardenedBSD updates and changes</a></h3>

<ul>
<li>a.out is the old executable format for Unix</li>
<li>The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968</li>
<li>FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0</li>
<li>A restriction against NULL mapping was introduced in <a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener">FreeBSD 7</a> and enabled by default in FreeBSD 8</li>
<li>However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited</li>
<li>HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’</li>
<li>Package building update: <a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener">more consistent repo, no more i386 packages </a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener">Boris writes in</a></li>
<li><a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener">Alex writes in</a> (<b>edit:</b> adding "tinker panic 0" to the ntp.conf will disable the sanity check)</li>
<li><a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener">Jake writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141711266800001&amp;r=1&amp;w=2" rel="nofollow noopener">Real world authpf use</a></li>
<li><a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;r2=373563&amp;pathrev=373564" rel="nofollow noopener">The</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener">great</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener">perl</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener">event</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener">of</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener">2014</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>64: Rump Kernels Revisited</title>
  <link>https://www.bsdnow.tv/64</link>
  <guid isPermaLink="false">b5100d19-f472-4a18-93f7-72e1494ce394</guid>
  <pubDate>Wed, 19 Nov 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b5100d19-f472-4a18-93f7-72e1494ce394.mp3" length="81755572" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Justin Cormack about NetBSD rump kernels. We'll learn how to run them on other operating systems, what's planned for the future and a lot more. As always, answers to viewer-submitted questions and all the news for the week, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:53:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Justin Cormack about NetBSD rump kernels. We'll learn how to run them on other operating systems, what's planned for the future and a lot more. As always, answers to viewer-submitted questions and all the news for the week, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener"&gt;EuroBSDCon 2014 talks and tutorials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The 2014 EuroBSDCon videos have been online for over a month, but unannounced - keep in mind these links may be temporary (but we'll mention their new location in a future show and fix the show notes if that's the case)
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Arun Thomas, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/01.BSD-ARM%20Kernel%20Internals%20-%20Arun%20Thomas.mp4" rel="nofollow noopener"&gt;BSD ARM Kernel Internals&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Ted Unangst, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/02.Developing%20Software%20in%20a%20Hostile%20Environment%20-%20Ted%20Unangst.mp4" rel="nofollow noopener"&gt;Developing Software in a Hostile Environment&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Martin Pieuchot, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener"&gt;Taming OpenBSD Network Stack Dragons&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Henning Brauer, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/04.OpenBGPD%20turns%2010%20years%20-%20%20Henning%20Brauer.mp4" rel="nofollow noopener"&gt;OpenBGPD turns 10 years&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Claudio Jeker, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/05.vscsi(4)%20and%20iscsid%20-%20iSCSI%20initiator%20the%20OpenBSD%20way%20-%20Claudio%20Jeker.mp4" rel="nofollow noopener"&gt;vscsi and iscsid iSCSI initiator the OpenBSD way&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Paul Irofti, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/06.Making%20OpenBSD%20Useful%20on%20the%20Octeon%20Network%20Gear%20-%20Paul%20Irofti.mp4" rel="nofollow noopener"&gt;Making OpenBSD Useful on the Octeon Network Gear&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Baptiste Daroussin, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/01.Cross%20Building%20the%20FreeBSD%20ports%20tree%20-%20Baptiste%20Daroussin.mp4" rel="nofollow noopener"&gt;Cross Building the FreeBSD ports tree&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Boris Astardzhiev, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/02.Smartcom%e2%80%99s%20control%20plane%20software,%20a%20customized%20version%20of%20FreeBSD%20-%20Boris%20Astardzhiev.mp4" rel="nofollow noopener"&gt;Smartcom’s control plane software, a customized version of FreeBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Michał Dubiel, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/03.OpenStack%20and%20OpenContrail%20for%20FreeBSD%20platform%20-%20Micha%c5%82%20Dubiel.mp4" rel="nofollow noopener"&gt;OpenStack and OpenContrail for FreeBSD platform&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Martin Husemann &amp;amp; Joerg Sonnenberger, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/04.(Tool-)chaining%20the%20Hydra%20The%20ongoing%20quest%20for%20modern%20toolchains%20in%20NetBSD%20-%20Martin%20Huseman%20&amp;amp;%20Joerg%20Sonnenberger.mp4" rel="nofollow noopener"&gt;Tool-chaining the Hydra, the ongoing quest for modern toolchains in NetBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Taylor R Campbell, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/05.The%20entropic%20principle:%20dev-u%3frandom%20and%20NetBSD%20-%20Taylor%20R%20Campbell.mp4" rel="nofollow noopener"&gt;The entropic principle: /dev/u?random and NetBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Dag-Erling Smørgrav, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/06.Securing%20sensitive%20&amp;amp;%20restricted%20data%20-%20Dag-Erling%20Sm%c3%b8rgrav.mp4" rel="nofollow noopener"&gt;Securing sensitive &amp;amp; restricted data&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Peter Hansteen, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/01.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener"&gt;Building The Network You Need&lt;/a&gt; &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/02.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener"&gt;With PF&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Stefan Sperling, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/03.Subversion%20for%20FreeBSD%20developers%20-%20Stefan%20Sperling.mp4" rel="nofollow noopener"&gt;Subversion for FreeBSD developers&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Peter Hansteen, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/01.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener"&gt;Transition to&lt;/a&gt; &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/02.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener"&gt;OpenBSD 5.6&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Ingo Schwarze, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/03.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener"&gt;Let’s make manuals&lt;/a&gt; &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/04.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener"&gt;more useful&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Francois Tigeot, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/01.Improving%20DragonFly%e2%80%99s%20performance%20with%20PostgreSQL%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener"&gt;Improving DragonFly’s performance with PostgreSQL&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Justin Cormack, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/02.Running%20Applications%20on%20the%20NetBSD%20Rump%20Kernel%20-%20Justin%20Cormack.mp4" rel="nofollow noopener"&gt;Running Applications on the NetBSD Rump Kernel&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Pierre Pronchery, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/04.EdgeBSD,%20a%20year%20later%20-%20%20Pierre%20Pronchery.mp4" rel="nofollow noopener"&gt;EdgeBSD, a year later&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Peter Hessler, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/05.Using%20routing%20domains%20or%20tables%20in%20a%20production%20network%20-%20%20Peter%20Hessler.mp4" rel="nofollow noopener"&gt;Using routing domains or tables in a production network&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Sean Bruno, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/06.QEMU%20user%20mode%20on%20FreeBSD%20-%20%20Sean%20Bruno.mp4" rel="nofollow noopener"&gt;QEMU user mode on FreeBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Kristaps Dzonsons, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/01.Bugs%20Ex%20Ante%20-%20Kristaps%20Dzonsons.mp4" rel="nofollow noopener"&gt;Bugs Ex Ante&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Yann Sionneau, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/02.Porting%20NetBSD%20to%20the%20LatticeMico32%20open%20source%20CPU%20-%20Yann%20Sionneau.mp4" rel="nofollow noopener"&gt;Porting NetBSD to the LatticeMico32 open source CPU&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Alexander Nasonov, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/03.JIT%20Code%20Generator%20for%20NetBSD%20-%20Alexander%20Nasonov.mp4" rel="nofollow noopener"&gt;JIT Code Generator for NetBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Masao Uebayashi, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/04.Porting%20Valgrind%20to%20NetBSD%20and%20OpenBSD%20-%20Masao%20Uebayashi.mp4" rel="nofollow noopener"&gt;Porting Valgrind to NetBSD and OpenBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Marc Espie, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/05.parallel%20make:%20working%20with%20legacy%20code%20-%20Marc%20Espie.mp4" rel="nofollow noopener"&gt;parallel make, working with legacy code&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Francois Tigeot, &lt;a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/06.Porting%20the%20drm-kms%20graphic%20drivers%20to%20DragonFly%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener"&gt;Porting the drm-kms graphic drivers to DragonFly&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The following talks (from the Vitosha track room) are all currently missing:&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Jordan Hubbard, FreeBSD, Looking forward to another 10 years (but we have another recording)&lt;/li&gt;
&lt;li&gt;Theo de Raadt, Randomness, how arc4random has grown since 1998 (but we have another recording)&lt;/li&gt;
&lt;li&gt;Kris Moore, Snapshots, Replication, and Boot-Environments&lt;/li&gt;
&lt;li&gt;Kirk McKusick, An Introduction to the Implementation of ZFS&lt;/li&gt;
&lt;li&gt;John-Mark Gurney, Optimizing GELI Performance&lt;/li&gt;
&lt;li&gt;Emmanuel Dreyfus, FUSE and beyond, bridging filesystems&lt;/li&gt;
&lt;li&gt;Lourival Vieira Neto, NPF scripting with Lua&lt;/li&gt;
&lt;li&gt;Andy Tanenbaum, A Reimplementation of NetBSD Based on a Microkernel&lt;/li&gt;
&lt;li&gt;Stefano Garzarella, Software segmentation offloading for FreeBSD&lt;/li&gt;
&lt;li&gt;Ted Unangst, LibreSSL&lt;/li&gt;
&lt;li&gt;Shawn Webb, Introducing ASLR In FreeBSD&lt;/li&gt;
&lt;li&gt;Ed Maste, The LLDB Debugger in FreeBSD&lt;/li&gt;
&lt;li&gt;Philip Guenther, Secure lazy binding
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141614801713457&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD adopts SipHash&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Even more DJB crypto somehow finds its way into OpenBSD's base system&lt;/li&gt;
&lt;li&gt;This time it's &lt;a href="https://131002.net/siphash/" rel="nofollow noopener"&gt;SipHash&lt;/a&gt;, a family of pseudorandom functions that's resistant to hash bucket flooding attacks while still providing good performance&lt;/li&gt;
&lt;li&gt;After an &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/crypto/siphash.c?rev=1.1&amp;amp;content-type=text/x-cvsweb-markup" rel="nofollow noopener"&gt;initial import&lt;/a&gt; and some &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141604896822253&amp;amp;w=2" rel="nofollow noopener"&gt;clever early usage&lt;/a&gt;, a few developers agreed that it would be better to use it in a lot more places&lt;/li&gt;
&lt;li&gt;It will now be used in the filesystem, and the plan is to utilize it to protect &lt;strong&gt;all kernel hash functions&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Some &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;other places&lt;/a&gt; that Bernstein's work can be found in OpenBSD include the ChaCha20-Poly1305 authenticated stream cipher and Curve25519 KEX used in SSH, ChaCha20 used in the RNG, and Ed25519 keys used in &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;signify&lt;/a&gt; and SSH
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.1R/announce.html" rel="nofollow noopener"&gt;FreeBSD 10.1-RELEASE&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD's &lt;a href="http://www.bsdnow.tv/episodes/2013-09-11_engineering_powder_kegs" rel="nofollow noopener"&gt;release engineering team&lt;/a&gt; likes to troll us by uploading new versions just a few hours after we finish recording an episode&lt;/li&gt;
&lt;li&gt;The first maintenance update for the 10.x branch is out, improving upon a lot of things found in 10.0-RELEASE&lt;/li&gt;
&lt;li&gt;The vt driver was merged from -CURRENT and can now be enabled with a loader.conf switch (and can even be used on a PlayStation 3)&lt;/li&gt;
&lt;li&gt;Bhyve has gotten quite a lot of fixes and improvements from its initial debut in 10.0, including boot support for ZFS&lt;/li&gt;
&lt;li&gt;Lots of new ARM hardware is supported now, including SMP support for most of them&lt;/li&gt;
&lt;li&gt;A new kernel selection menu was added to the loader, so you can switch between newer and older kernels at boot time&lt;/li&gt;
&lt;li&gt;10.1 is the first to support UEFI booting on amd64, which also has serial console support now&lt;/li&gt;
&lt;li&gt;Lots of third party software (OpenSSH, OpenSSL, Unbound..) and drivers have gotten updates to newer versions&lt;/li&gt;
&lt;li&gt;It's a worthy update from 10.0, or a good time to try the 10.x branch if you were avoiding the first .0 release, so &lt;a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.1/" rel="nofollow noopener"&gt;grab an ISO&lt;/a&gt; or &lt;a href="https://www.freebsd.org/cgi/man.cgi?query=freebsd-update" rel="nofollow noopener"&gt;upgrade&lt;/a&gt; today&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="https://www.freebsd.org/releases/10.1R/relnotes.html" rel="nofollow noopener"&gt;detailed release notes&lt;/a&gt; for more information on all the changes&lt;/li&gt;
&lt;li&gt;Also take a look at some of the &lt;a href="https://www.freebsd.org/releases/10.1R/errata.html#open-issues" rel="nofollow noopener"&gt;known problems&lt;/a&gt; to see &lt;a href="https://forums.freebsd.org/threads/segmentation-fault-while-upgrading-from-10-0-release-to-10-1-release.48977/" rel="nofollow noopener"&gt;if&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-October/080599.html" rel="nofollow noopener"&gt;you'll&lt;/a&gt; &lt;a href="https://forums.freebsd.org/threads/10-0-10-1-diocaddrule-operation-not-supported-by-device.49016/" rel="nofollow noopener"&gt;be&lt;/a&gt; &lt;a href="https://www.reddit.com/r/freebsd/comments/2mmzzy/101release_restart_problems_anyone/" rel="nofollow noopener"&gt;affected&lt;/a&gt; by any of them&lt;/li&gt;
&lt;li&gt;PC-BSD was also &lt;a href="http://wiki.pcbsd.org/index.php/What%27s_New/10.1" rel="nofollow noopener"&gt;updated accordingly&lt;/a&gt; with some of their own unique features and changes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=aWmLWx8ut20" rel="nofollow noopener"&gt;arc4random - Randomization for All Occasions&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Theo de Raadt gave an updated version of his EuroBSDCon presentation at Hackfest 2014 in Quebec&lt;/li&gt;
&lt;li&gt;The presentation is mainly about OpenBSD's arc4random function, and outlines the overall poor state of randomization in the 90s and how it has evolved in OpenBSD over time&lt;/li&gt;
&lt;li&gt;It begins with some interesting history on OpenBSD and how it became a security-focused OS - in 1996, their syslogd got broken into and "suddenly we became interested in security"&lt;/li&gt;
&lt;li&gt;The talk also touches on how low-level changes can shake up the software ecosystem and third party packages that everyone uses&lt;/li&gt;
&lt;li&gt;There's some funny history on the name of the function (being called arc4random despite not using RC4 anymore) and an overall status update on various platforms' usage of it&lt;/li&gt;
&lt;li&gt;Very detailed and informative presentation, and the slides can be found &lt;a href="http://www.openbsd.org/papers/hackfest2014-arc4random/index.html" rel="nofollow noopener"&gt;here&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;A great quote from the beginning: "We consider ourselves a community of (probably rather strange) people who work on software specifically for the purpose of trying to make it better. We take a 'whole-systems' approach: trying to change everything in the ecosystem that's under our control, trying to see if we can make it better. We gain a lot of strength by being able to throw backwards compatibility out the window. So that means that we're able to do research and the minute that we decide that something isn't right, we'll design an alternative for it and push it in. And if it ends up breaking everybody's machines from the previous stage to the next stage, that's fine because we'll end up in a happier place."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Justin Cormack - &lt;a href="mailto:justin@netbsd.org" rel="nofollow noopener"&gt;justin@netbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/justincormack" rel="nofollow noopener"&gt;@justincormack&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;NetBSD on Xen, rump kernels, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/11/freebsd-foundation-announces-generous.html" rel="nofollow noopener"&gt;The FreeBSD foundation's biggest donation&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation has a new blog post about the largest donation they've ever gotten&lt;/li&gt;
&lt;li&gt;From the CEO of WhatsApp comes a whopping one million dollars in a single donation&lt;/li&gt;
&lt;li&gt;It also has some comments from the donor about why they use BSD and why it's important to give back&lt;/li&gt;
&lt;li&gt;Be sure to donate to the foundation of whatever BSD you use when you can - every little bit helps, especially for &lt;a href="http://www.openbsd.org/donations.html" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt;, &lt;a href="https://www.netbsd.org/donations/" rel="nofollow noopener"&gt;NetBSD&lt;/a&gt; and &lt;a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener"&gt;DragonFly&lt;/a&gt; who don't have huge companies supporting them regularly like FreeBSD does
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://open-zfs.org/wiki/OpenZFS_Developer_Summit" rel="nofollow noopener"&gt;OpenZFS Dev Summit 2014 videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Videos from the recent OpenZFS developer summit are being uploaded, with speakers from different represented platforms and companies
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" rel="nofollow noopener"&gt;Matt Ahrens&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=XnTzbisLYzg" rel="nofollow noopener"&gt;opening keynote&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Raphael Carvalho, &lt;a href="https://www.youtube.com/watch?v=TJLOBLSRoHE" rel="nofollow noopener"&gt;Platform Overview: ZFS on OSv&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Brian Behlendorf, &lt;a href="https://www.youtube.com/watch?v=_MVOpMNV7LY" rel="nofollow noopener"&gt;Platform Overview: ZFS on Linux&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Prakash Surya, &lt;a href="https://www.youtube.com/watch?v=UtlGt3ag0o0" rel="nofollow noopener"&gt;Platform Overview: illumos&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Xin Li, &lt;a href="https://www.youtube.com/watch?v=xO0x5_3A1X4" rel="nofollow noopener"&gt;Platform Overview: FreeBSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;All platforms, &lt;a href="https://www.youtube.com/watch?v=t4UlT0RmSCc" rel="nofollow noopener"&gt;Group Q&amp;amp;A Session&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Dave Pacheco, &lt;a href="https://www.youtube.com/watch?v=BEoCMpdB8WU" rel="nofollow noopener"&gt;Manta&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Saso Kiselkov, &lt;a href="https://www.youtube.com/watch?v=TZF92taa_us" rel="nofollow noopener"&gt;Compression&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener"&gt;George Wilson&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=deJc0EMKrM4" rel="nofollow noopener"&gt;Performance&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Tim Feldman, &lt;a href="https://www.youtube.com/watch?v=b1yqjV8qemU" rel="nofollow noopener"&gt;Host-Aware SMR&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Pavel Zakharov, &lt;a href="https://www.youtube.com/watch?v=-4c4gsLi1LI" rel="nofollow noopener"&gt;Fast File Cloning&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;The audio is &lt;a href="https://twitter.com/OpenZFS/status/534005125853888512" rel="nofollow noopener"&gt;pretty poor&lt;/a&gt; on all of them unfortunately
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2014/11/bsdtalk248-dragonflybsd-with-matthew.html" rel="nofollow noopener"&gt;BSDTalk 248&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our friend Will Backman is still busy getting BSD interviews as well&lt;/li&gt;
&lt;li&gt;This time he sits down with Matthew Dillon, the lead developer of DragonFly BSD&lt;/li&gt;
&lt;li&gt;We've never had Dillon on the show, so you'll definitely want to give this one a listen&lt;/li&gt;
&lt;li&gt;They mainly discuss all the big changes coming in DragonFly's upcoming 4.0 release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.meetbsd.com/" rel="nofollow noopener"&gt;MeetBSD 2014 videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The presentations from this year's MeetBSD conference are starting to appear online as well
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener"&gt;Kirk McKusick&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=DEEr6dT-4uQ" rel="nofollow noopener"&gt;A Narrative History of BSD&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_27-bridging_the_gap" rel="nofollow noopener"&gt;Jordan Hubbard&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=Mri66Uz6-8Y" rel="nofollow noopener"&gt;FreeBSD: The Next 10 Years&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;Brendan Gregg, &lt;a href="https://www.youtube.com/watch?v=uvKMptfXtdo" rel="nofollow noopener"&gt;Performance Analysis&lt;/a&gt;
&amp;lt;!-- i wonder if freebsdnews will rip our html again and repost it &lt;sup&gt;_^&lt;/sup&gt; --&amp;gt;&lt;/li&gt;
&lt;li&gt;The slides can be found &lt;a href="https://www.meetbsd.com/agenda/" rel="nofollow noopener"&gt;here&lt;/a&gt; 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20PXjp55N" rel="nofollow noopener"&gt;Dominik writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2LwEYT3bA" rel="nofollow noopener"&gt;Steven writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ubK8vQVt" rel="nofollow noopener"&gt;Florian writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216Eq8nFG" rel="nofollow noopener"&gt;Richard writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21D2ugDUy" rel="nofollow noopener"&gt;Kevin writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141600819500004&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;Contributing without code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033176.html" rel="nofollow noopener"&gt;Compression isn't a CRIME&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141616714600001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;Securing web browsers&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, rump kernels, xen, userspace, networking, siphash, 10.1, review, 10.1 review, openzfs, zfs, devsummit, hackfest, arc4random, meetbsd, presentation</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Justin Cormack about NetBSD rump kernels. We'll learn how to run them on other operating systems, what's planned for the future and a lot more. As always, answers to viewer-submitted questions and all the news for the week, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and tutorials</a></h3>

<ul>
<li>The 2014 EuroBSDCon videos have been online for over a month, but unannounced - keep in mind these links may be temporary (but we'll mention their new location in a future show and fix the show notes if that's the case)
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Arun Thomas, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/01.BSD-ARM%20Kernel%20Internals%20-%20Arun%20Thomas.mp4" rel="nofollow noopener">BSD ARM Kernel Internals</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Ted Unangst, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/02.Developing%20Software%20in%20a%20Hostile%20Environment%20-%20Ted%20Unangst.mp4" rel="nofollow noopener">Developing Software in a Hostile Environment</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Martin Pieuchot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener">Taming OpenBSD Network Stack Dragons</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Henning Brauer, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/04.OpenBGPD%20turns%2010%20years%20-%20%20Henning%20Brauer.mp4" rel="nofollow noopener">OpenBGPD turns 10 years</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Claudio Jeker, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/05.vscsi(4)%20and%20iscsid%20-%20iSCSI%20initiator%20the%20OpenBSD%20way%20-%20Claudio%20Jeker.mp4" rel="nofollow noopener">vscsi and iscsid iSCSI initiator the OpenBSD way</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Paul Irofti, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/06.Making%20OpenBSD%20Useful%20on%20the%20Octeon%20Network%20Gear%20-%20Paul%20Irofti.mp4" rel="nofollow noopener">Making OpenBSD Useful on the Octeon Network Gear</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Baptiste Daroussin, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/01.Cross%20Building%20the%20FreeBSD%20ports%20tree%20-%20Baptiste%20Daroussin.mp4" rel="nofollow noopener">Cross Building the FreeBSD ports tree</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Boris Astardzhiev, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/02.Smartcom%e2%80%99s%20control%20plane%20software,%20a%20customized%20version%20of%20FreeBSD%20-%20Boris%20Astardzhiev.mp4" rel="nofollow noopener">Smartcom’s control plane software, a customized version of FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Michał Dubiel, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/03.OpenStack%20and%20OpenContrail%20for%20FreeBSD%20platform%20-%20Micha%c5%82%20Dubiel.mp4" rel="nofollow noopener">OpenStack and OpenContrail for FreeBSD platform</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Martin Husemann &amp; Joerg Sonnenberger, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/04.(Tool-)chaining%20the%20Hydra%20The%20ongoing%20quest%20for%20modern%20toolchains%20in%20NetBSD%20-%20Martin%20Huseman%20&amp;%20Joerg%20Sonnenberger.mp4" rel="nofollow noopener">Tool-chaining the Hydra, the ongoing quest for modern toolchains in NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Taylor R Campbell, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/05.The%20entropic%20principle:%20dev-u%3frandom%20and%20NetBSD%20-%20Taylor%20R%20Campbell.mp4" rel="nofollow noopener">The entropic principle: /dev/u?random and NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Dag-Erling Smørgrav, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/06.Securing%20sensitive%20&amp;%20restricted%20data%20-%20Dag-Erling%20Sm%c3%b8rgrav.mp4" rel="nofollow noopener">Securing sensitive &amp; restricted data</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hansteen, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/01.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">Building The Network You Need</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/02.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">With PF</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Stefan Sperling, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/03.Subversion%20for%20FreeBSD%20developers%20-%20Stefan%20Sperling.mp4" rel="nofollow noopener">Subversion for FreeBSD developers</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hansteen, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/01.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">Transition to</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/02.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">OpenBSD 5.6</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Ingo Schwarze, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/03.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener">Let’s make manuals</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/04.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener">more useful</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Francois Tigeot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/01.Improving%20DragonFly%e2%80%99s%20performance%20with%20PostgreSQL%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener">Improving DragonFly’s performance with PostgreSQL</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Justin Cormack, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/02.Running%20Applications%20on%20the%20NetBSD%20Rump%20Kernel%20-%20Justin%20Cormack.mp4" rel="nofollow noopener">Running Applications on the NetBSD Rump Kernel</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Pierre Pronchery, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/04.EdgeBSD,%20a%20year%20later%20-%20%20Pierre%20Pronchery.mp4" rel="nofollow noopener">EdgeBSD, a year later</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hessler, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/05.Using%20routing%20domains%20or%20tables%20in%20a%20production%20network%20-%20%20Peter%20Hessler.mp4" rel="nofollow noopener">Using routing domains or tables in a production network</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Sean Bruno, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/06.QEMU%20user%20mode%20on%20FreeBSD%20-%20%20Sean%20Bruno.mp4" rel="nofollow noopener">QEMU user mode on FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Kristaps Dzonsons, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/01.Bugs%20Ex%20Ante%20-%20Kristaps%20Dzonsons.mp4" rel="nofollow noopener">Bugs Ex Ante</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Yann Sionneau, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/02.Porting%20NetBSD%20to%20the%20LatticeMico32%20open%20source%20CPU%20-%20Yann%20Sionneau.mp4" rel="nofollow noopener">Porting NetBSD to the LatticeMico32 open source CPU</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Alexander Nasonov, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/03.JIT%20Code%20Generator%20for%20NetBSD%20-%20Alexander%20Nasonov.mp4" rel="nofollow noopener">JIT Code Generator for NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Masao Uebayashi, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/04.Porting%20Valgrind%20to%20NetBSD%20and%20OpenBSD%20-%20Masao%20Uebayashi.mp4" rel="nofollow noopener">Porting Valgrind to NetBSD and OpenBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Marc Espie, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/05.parallel%20make:%20working%20with%20legacy%20code%20-%20Marc%20Espie.mp4" rel="nofollow noopener">parallel make, working with legacy code</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Francois Tigeot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/06.Porting%20the%20drm-kms%20graphic%20drivers%20to%20DragonFly%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener">Porting the drm-kms graphic drivers to DragonFly</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><strong>The following talks (from the Vitosha track room) are all currently missing:</strong></li>
<li>Jordan Hubbard, FreeBSD, Looking forward to another 10 years (but we have another recording)</li>
<li>Theo de Raadt, Randomness, how arc4random has grown since 1998 (but we have another recording)</li>
<li>Kris Moore, Snapshots, Replication, and Boot-Environments</li>
<li>Kirk McKusick, An Introduction to the Implementation of ZFS</li>
<li>John-Mark Gurney, Optimizing GELI Performance</li>
<li>Emmanuel Dreyfus, FUSE and beyond, bridging filesystems</li>
<li>Lourival Vieira Neto, NPF scripting with Lua</li>
<li>Andy Tanenbaum, A Reimplementation of NetBSD Based on a Microkernel</li>
<li>Stefano Garzarella, Software segmentation offloading for FreeBSD</li>
<li>Ted Unangst, LibreSSL</li>
<li>Shawn Webb, Introducing ASLR In FreeBSD</li>
<li>Ed Maste, The LLDB Debugger in FreeBSD</li>
<li>Philip Guenther, Secure lazy binding
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141614801713457&amp;w=2" rel="nofollow noopener">OpenBSD adopts SipHash</a></h3>

<ul>
<li>Even more DJB crypto somehow finds its way into OpenBSD's base system</li>
<li>This time it's <a href="https://131002.net/siphash/" rel="nofollow noopener">SipHash</a>, a family of pseudorandom functions that's resistant to hash bucket flooding attacks while still providing good performance</li>
<li>After an <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/crypto/siphash.c?rev=1.1&amp;content-type=text/x-cvsweb-markup" rel="nofollow noopener">initial import</a> and some <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141604896822253&amp;w=2" rel="nofollow noopener">clever early usage</a>, a few developers agreed that it would be better to use it in a lot more places</li>
<li>It will now be used in the filesystem, and the plan is to utilize it to protect <strong>all kernel hash functions</strong></li>
<li>Some <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">other places</a> that Bernstein's work can be found in OpenBSD include the ChaCha20-Poly1305 authenticated stream cipher and Curve25519 KEX used in SSH, ChaCha20 used in the RNG, and Ed25519 keys used in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">signify</a> and SSH
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.1R/announce.html" rel="nofollow noopener">FreeBSD 10.1-RELEASE</a></h3>

<ul>
<li>FreeBSD's <a href="http://www.bsdnow.tv/episodes/2013-09-11_engineering_powder_kegs" rel="nofollow noopener">release engineering team</a> likes to troll us by uploading new versions just a few hours after we finish recording an episode</li>
<li>The first maintenance update for the 10.x branch is out, improving upon a lot of things found in 10.0-RELEASE</li>
<li>The vt driver was merged from -CURRENT and can now be enabled with a loader.conf switch (and can even be used on a PlayStation 3)</li>
<li>Bhyve has gotten quite a lot of fixes and improvements from its initial debut in 10.0, including boot support for ZFS</li>
<li>Lots of new ARM hardware is supported now, including SMP support for most of them</li>
<li>A new kernel selection menu was added to the loader, so you can switch between newer and older kernels at boot time</li>
<li>10.1 is the first to support UEFI booting on amd64, which also has serial console support now</li>
<li>Lots of third party software (OpenSSH, OpenSSL, Unbound..) and drivers have gotten updates to newer versions</li>
<li>It's a worthy update from 10.0, or a good time to try the 10.x branch if you were avoiding the first .0 release, so <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.1/" rel="nofollow noopener">grab an ISO</a> or <a href="https://www.freebsd.org/cgi/man.cgi?query=freebsd-update" rel="nofollow noopener">upgrade</a> today</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.1R/relnotes.html" rel="nofollow noopener">detailed release notes</a> for more information on all the changes</li>
<li>Also take a look at some of the <a href="https://www.freebsd.org/releases/10.1R/errata.html#open-issues" rel="nofollow noopener">known problems</a> to see <a href="https://forums.freebsd.org/threads/segmentation-fault-while-upgrading-from-10-0-release-to-10-1-release.48977/" rel="nofollow noopener">if</a> <a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-October/080599.html" rel="nofollow noopener">you'll</a> <a href="https://forums.freebsd.org/threads/10-0-10-1-diocaddrule-operation-not-supported-by-device.49016/" rel="nofollow noopener">be</a> <a href="https://www.reddit.com/r/freebsd/comments/2mmzzy/101release_restart_problems_anyone/" rel="nofollow noopener">affected</a> by any of them</li>
<li>PC-BSD was also <a href="http://wiki.pcbsd.org/index.php/What%27s_New/10.1" rel="nofollow noopener">updated accordingly</a> with some of their own unique features and changes
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=aWmLWx8ut20" rel="nofollow noopener">arc4random - Randomization for All Occasions</a></h3>

<ul>
<li>Theo de Raadt gave an updated version of his EuroBSDCon presentation at Hackfest 2014 in Quebec</li>
<li>The presentation is mainly about OpenBSD's arc4random function, and outlines the overall poor state of randomization in the 90s and how it has evolved in OpenBSD over time</li>
<li>It begins with some interesting history on OpenBSD and how it became a security-focused OS - in 1996, their syslogd got broken into and "suddenly we became interested in security"</li>
<li>The talk also touches on how low-level changes can shake up the software ecosystem and third party packages that everyone uses</li>
<li>There's some funny history on the name of the function (being called arc4random despite not using RC4 anymore) and an overall status update on various platforms' usage of it</li>
<li>Very detailed and informative presentation, and the slides can be found <a href="http://www.openbsd.org/papers/hackfest2014-arc4random/index.html" rel="nofollow noopener">here</a></li>
<li>A great quote from the beginning: "We consider ourselves a community of (probably rather strange) people who work on software specifically for the purpose of trying to make it better. We take a 'whole-systems' approach: trying to change everything in the ecosystem that's under our control, trying to see if we can make it better. We gain a lot of strength by being able to throw backwards compatibility out the window. So that means that we're able to do research and the minute that we decide that something isn't right, we'll design an alternative for it and push it in. And if it ends up breaking everybody's machines from the previous stage to the next stage, that's fine because we'll end up in a happier place."
***</li>
</ul>

<h2>Interview - Justin Cormack - <a href="mailto:justin@netbsd.org" rel="nofollow noopener">justin@netbsd.org</a> / <a href="https://twitter.com/justincormack" rel="nofollow noopener">@justincormack</a></h2>

<p>NetBSD on Xen, rump kernels, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/11/freebsd-foundation-announces-generous.html" rel="nofollow noopener">The FreeBSD foundation's biggest donation</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post about the largest donation they've ever gotten</li>
<li>From the CEO of WhatsApp comes a whopping one million dollars in a single donation</li>
<li>It also has some comments from the donor about why they use BSD and why it's important to give back</li>
<li>Be sure to donate to the foundation of whatever BSD you use when you can - every little bit helps, especially for <a href="http://www.openbsd.org/donations.html" rel="nofollow noopener">OpenBSD</a>, <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">NetBSD</a> and <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">DragonFly</a> who don't have huge companies supporting them regularly like FreeBSD does
***</li>
</ul>

<h3><a href="http://open-zfs.org/wiki/OpenZFS_Developer_Summit" rel="nofollow noopener">OpenZFS Dev Summit 2014 videos</a></h3>

<ul>
<li>Videos from the recent OpenZFS developer summit are being uploaded, with speakers from different represented platforms and companies
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" rel="nofollow noopener">Matt Ahrens</a>, <a href="https://www.youtube.com/watch?v=XnTzbisLYzg" rel="nofollow noopener">opening keynote</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Raphael Carvalho, <a href="https://www.youtube.com/watch?v=TJLOBLSRoHE" rel="nofollow noopener">Platform Overview: ZFS on OSv</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Brian Behlendorf, <a href="https://www.youtube.com/watch?v=_MVOpMNV7LY" rel="nofollow noopener">Platform Overview: ZFS on Linux</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Prakash Surya, <a href="https://www.youtube.com/watch?v=UtlGt3ag0o0" rel="nofollow noopener">Platform Overview: illumos</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Xin Li, <a href="https://www.youtube.com/watch?v=xO0x5_3A1X4" rel="nofollow noopener">Platform Overview: FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>All platforms, <a href="https://www.youtube.com/watch?v=t4UlT0RmSCc" rel="nofollow noopener">Group Q&amp;A Session</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Dave Pacheco, <a href="https://www.youtube.com/watch?v=BEoCMpdB8WU" rel="nofollow noopener">Manta</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Saso Kiselkov, <a href="https://www.youtube.com/watch?v=TZF92taa_us" rel="nofollow noopener">Compression</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener">George Wilson</a>, <a href="https://www.youtube.com/watch?v=deJc0EMKrM4" rel="nofollow noopener">Performance</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Tim Feldman, <a href="https://www.youtube.com/watch?v=b1yqjV8qemU" rel="nofollow noopener">Host-Aware SMR</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Pavel Zakharov, <a href="https://www.youtube.com/watch?v=-4c4gsLi1LI" rel="nofollow noopener">Fast File Cloning</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>The audio is <a href="https://twitter.com/OpenZFS/status/534005125853888512" rel="nofollow noopener">pretty poor</a> on all of them unfortunately
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/11/bsdtalk248-dragonflybsd-with-matthew.html" rel="nofollow noopener">BSDTalk 248</a></h3>

<ul>
<li>Our friend Will Backman is still busy getting BSD interviews as well</li>
<li>This time he sits down with Matthew Dillon, the lead developer of DragonFly BSD</li>
<li>We've never had Dillon on the show, so you'll definitely want to give this one a listen</li>
<li>They mainly discuss all the big changes coming in DragonFly's upcoming 4.0 release
***</li>
</ul>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">MeetBSD 2014 videos</a></h3>

<ul>
<li>The presentations from this year's MeetBSD conference are starting to appear online as well
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener">Kirk McKusick</a>, <a href="https://www.youtube.com/watch?v=DEEr6dT-4uQ" rel="nofollow noopener">A Narrative History of BSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_27-bridging_the_gap" rel="nofollow noopener">Jordan Hubbard</a>, <a href="https://www.youtube.com/watch?v=Mri66Uz6-8Y" rel="nofollow noopener">FreeBSD: The Next 10 Years</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Brendan Gregg, <a href="https://www.youtube.com/watch?v=uvKMptfXtdo" rel="nofollow noopener">Performance Analysis</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>The slides can be found <a href="https://www.meetbsd.com/agenda/" rel="nofollow noopener">here</a> 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20PXjp55N" rel="nofollow noopener">Dominik writes in</a></li>
<li><a href="http://slexy.org/view/s2LwEYT3bA" rel="nofollow noopener">Steven writes in</a></li>
<li><a href="http://slexy.org/view/s2ubK8vQVt" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s216Eq8nFG" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s21D2ugDUy" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141600819500004&amp;r=1&amp;w=2" rel="nofollow noopener">Contributing without code</a></li>
<li><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033176.html" rel="nofollow noopener">Compression isn't a CRIME</a></li>
<li><a href="https://www.marc.info/?t=141616714600001&amp;r=1&amp;w=2" rel="nofollow noopener">Securing web browsers</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Justin Cormack about NetBSD rump kernels. We'll learn how to run them on other operating systems, what's planned for the future and a lot more. As always, answers to viewer-submitted questions and all the news for the week, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.eurobsdcon.org/talks-and-schedule/" rel="nofollow noopener">EuroBSDCon 2014 talks and tutorials</a></h3>

<ul>
<li>The 2014 EuroBSDCon videos have been online for over a month, but unannounced - keep in mind these links may be temporary (but we'll mention their new location in a future show and fix the show notes if that's the case)
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Arun Thomas, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/01.BSD-ARM%20Kernel%20Internals%20-%20Arun%20Thomas.mp4" rel="nofollow noopener">BSD ARM Kernel Internals</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Ted Unangst, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/02.Developing%20Software%20in%20a%20Hostile%20Environment%20-%20Ted%20Unangst.mp4" rel="nofollow noopener">Developing Software in a Hostile Environment</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Martin Pieuchot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/03.Taming%20OpenBSD%20Network%20Stack%20Dragons%20-%20Martin%20Pieuchot.mp4" rel="nofollow noopener">Taming OpenBSD Network Stack Dragons</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Henning Brauer, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/04.OpenBGPD%20turns%2010%20years%20-%20%20Henning%20Brauer.mp4" rel="nofollow noopener">OpenBGPD turns 10 years</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Claudio Jeker, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/05.vscsi(4)%20and%20iscsid%20-%20iSCSI%20initiator%20the%20OpenBSD%20way%20-%20Claudio%20Jeker.mp4" rel="nofollow noopener">vscsi and iscsid iSCSI initiator the OpenBSD way</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Paul Irofti, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/03.Saturday/06.Making%20OpenBSD%20Useful%20on%20the%20Octeon%20Network%20Gear%20-%20Paul%20Irofti.mp4" rel="nofollow noopener">Making OpenBSD Useful on the Octeon Network Gear</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Baptiste Daroussin, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/01.Cross%20Building%20the%20FreeBSD%20ports%20tree%20-%20Baptiste%20Daroussin.mp4" rel="nofollow noopener">Cross Building the FreeBSD ports tree</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Boris Astardzhiev, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/02.Smartcom%e2%80%99s%20control%20plane%20software,%20a%20customized%20version%20of%20FreeBSD%20-%20Boris%20Astardzhiev.mp4" rel="nofollow noopener">Smartcom’s control plane software, a customized version of FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Michał Dubiel, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/03.OpenStack%20and%20OpenContrail%20for%20FreeBSD%20platform%20-%20Micha%c5%82%20Dubiel.mp4" rel="nofollow noopener">OpenStack and OpenContrail for FreeBSD platform</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Martin Husemann &amp; Joerg Sonnenberger, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/04.(Tool-)chaining%20the%20Hydra%20The%20ongoing%20quest%20for%20modern%20toolchains%20in%20NetBSD%20-%20Martin%20Huseman%20&amp;%20Joerg%20Sonnenberger.mp4" rel="nofollow noopener">Tool-chaining the Hydra, the ongoing quest for modern toolchains in NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Taylor R Campbell, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/05.The%20entropic%20principle:%20dev-u%3frandom%20and%20NetBSD%20-%20Taylor%20R%20Campbell.mp4" rel="nofollow noopener">The entropic principle: /dev/u?random and NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Dag-Erling Smørgrav, <a href="https://va.ludost.net/files/eurobsdcon/2014/Rodopi/04.Sunday/06.Securing%20sensitive%20&amp;%20restricted%20data%20-%20Dag-Erling%20Sm%c3%b8rgrav.mp4" rel="nofollow noopener">Securing sensitive &amp; restricted data</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hansteen, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/01.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">Building The Network You Need</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/02.Building%20The%20Network%20You%20Need%20With%20PF%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">With PF</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Stefan Sperling, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/01.Thursday/03.Subversion%20for%20FreeBSD%20developers%20-%20Stefan%20Sperling.mp4" rel="nofollow noopener">Subversion for FreeBSD developers</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hansteen, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/01.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">Transition to</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/02.Transition%20to%20OpenBSD%205.6%20-%20Peter%20Hansteen.mp4" rel="nofollow noopener">OpenBSD 5.6</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Ingo Schwarze, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/03.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener">Let’s make manuals</a> <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/02.Friday/04.Let%e2%80%99s%20make%20manuals%20more%20useful%20-%20Ingo%20Schwarze.mp4" rel="nofollow noopener">more useful</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Francois Tigeot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/01.Improving%20DragonFly%e2%80%99s%20performance%20with%20PostgreSQL%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener">Improving DragonFly’s performance with PostgreSQL</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Justin Cormack, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/02.Running%20Applications%20on%20the%20NetBSD%20Rump%20Kernel%20-%20Justin%20Cormack.mp4" rel="nofollow noopener">Running Applications on the NetBSD Rump Kernel</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Pierre Pronchery, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/04.EdgeBSD,%20a%20year%20later%20-%20%20Pierre%20Pronchery.mp4" rel="nofollow noopener">EdgeBSD, a year later</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Peter Hessler, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/05.Using%20routing%20domains%20or%20tables%20in%20a%20production%20network%20-%20%20Peter%20Hessler.mp4" rel="nofollow noopener">Using routing domains or tables in a production network</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Sean Bruno, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/03.Saturday/06.QEMU%20user%20mode%20on%20FreeBSD%20-%20%20Sean%20Bruno.mp4" rel="nofollow noopener">QEMU user mode on FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Kristaps Dzonsons, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/01.Bugs%20Ex%20Ante%20-%20Kristaps%20Dzonsons.mp4" rel="nofollow noopener">Bugs Ex Ante</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Yann Sionneau, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/02.Porting%20NetBSD%20to%20the%20LatticeMico32%20open%20source%20CPU%20-%20Yann%20Sionneau.mp4" rel="nofollow noopener">Porting NetBSD to the LatticeMico32 open source CPU</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Alexander Nasonov, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/03.JIT%20Code%20Generator%20for%20NetBSD%20-%20Alexander%20Nasonov.mp4" rel="nofollow noopener">JIT Code Generator for NetBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Masao Uebayashi, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/04.Porting%20Valgrind%20to%20NetBSD%20and%20OpenBSD%20-%20Masao%20Uebayashi.mp4" rel="nofollow noopener">Porting Valgrind to NetBSD and OpenBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Marc Espie, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/05.parallel%20make:%20working%20with%20legacy%20code%20-%20Marc%20Espie.mp4" rel="nofollow noopener">parallel make, working with legacy code</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Francois Tigeot, <a href="https://va.ludost.net/files/eurobsdcon/2014/Pirin/04.Sunday/06.Porting%20the%20drm-kms%20graphic%20drivers%20to%20DragonFly%20-%20Francois%20Tigeot.mp4" rel="nofollow noopener">Porting the drm-kms graphic drivers to DragonFly</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><strong>The following talks (from the Vitosha track room) are all currently missing:</strong></li>
<li>Jordan Hubbard, FreeBSD, Looking forward to another 10 years (but we have another recording)</li>
<li>Theo de Raadt, Randomness, how arc4random has grown since 1998 (but we have another recording)</li>
<li>Kris Moore, Snapshots, Replication, and Boot-Environments</li>
<li>Kirk McKusick, An Introduction to the Implementation of ZFS</li>
<li>John-Mark Gurney, Optimizing GELI Performance</li>
<li>Emmanuel Dreyfus, FUSE and beyond, bridging filesystems</li>
<li>Lourival Vieira Neto, NPF scripting with Lua</li>
<li>Andy Tanenbaum, A Reimplementation of NetBSD Based on a Microkernel</li>
<li>Stefano Garzarella, Software segmentation offloading for FreeBSD</li>
<li>Ted Unangst, LibreSSL</li>
<li>Shawn Webb, Introducing ASLR In FreeBSD</li>
<li>Ed Maste, The LLDB Debugger in FreeBSD</li>
<li>Philip Guenther, Secure lazy binding
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141614801713457&amp;w=2" rel="nofollow noopener">OpenBSD adopts SipHash</a></h3>

<ul>
<li>Even more DJB crypto somehow finds its way into OpenBSD's base system</li>
<li>This time it's <a href="https://131002.net/siphash/" rel="nofollow noopener">SipHash</a>, a family of pseudorandom functions that's resistant to hash bucket flooding attacks while still providing good performance</li>
<li>After an <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/sys/crypto/siphash.c?rev=1.1&amp;content-type=text/x-cvsweb-markup" rel="nofollow noopener">initial import</a> and some <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141604896822253&amp;w=2" rel="nofollow noopener">clever early usage</a>, a few developers agreed that it would be better to use it in a lot more places</li>
<li>It will now be used in the filesystem, and the plan is to utilize it to protect <strong>all kernel hash functions</strong></li>
<li>Some <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">other places</a> that Bernstein's work can be found in OpenBSD include the ChaCha20-Poly1305 authenticated stream cipher and Curve25519 KEX used in SSH, ChaCha20 used in the RNG, and Ed25519 keys used in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">signify</a> and SSH
***</li>
</ul>

<h3><a href="https://www.freebsd.org/releases/10.1R/announce.html" rel="nofollow noopener">FreeBSD 10.1-RELEASE</a></h3>

<ul>
<li>FreeBSD's <a href="http://www.bsdnow.tv/episodes/2013-09-11_engineering_powder_kegs" rel="nofollow noopener">release engineering team</a> likes to troll us by uploading new versions just a few hours after we finish recording an episode</li>
<li>The first maintenance update for the 10.x branch is out, improving upon a lot of things found in 10.0-RELEASE</li>
<li>The vt driver was merged from -CURRENT and can now be enabled with a loader.conf switch (and can even be used on a PlayStation 3)</li>
<li>Bhyve has gotten quite a lot of fixes and improvements from its initial debut in 10.0, including boot support for ZFS</li>
<li>Lots of new ARM hardware is supported now, including SMP support for most of them</li>
<li>A new kernel selection menu was added to the loader, so you can switch between newer and older kernels at boot time</li>
<li>10.1 is the first to support UEFI booting on amd64, which also has serial console support now</li>
<li>Lots of third party software (OpenSSH, OpenSSL, Unbound..) and drivers have gotten updates to newer versions</li>
<li>It's a worthy update from 10.0, or a good time to try the 10.x branch if you were avoiding the first .0 release, so <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.1/" rel="nofollow noopener">grab an ISO</a> or <a href="https://www.freebsd.org/cgi/man.cgi?query=freebsd-update" rel="nofollow noopener">upgrade</a> today</li>
<li>Check the <a href="https://www.freebsd.org/releases/10.1R/relnotes.html" rel="nofollow noopener">detailed release notes</a> for more information on all the changes</li>
<li>Also take a look at some of the <a href="https://www.freebsd.org/releases/10.1R/errata.html#open-issues" rel="nofollow noopener">known problems</a> to see <a href="https://forums.freebsd.org/threads/segmentation-fault-while-upgrading-from-10-0-release-to-10-1-release.48977/" rel="nofollow noopener">if</a> <a href="https://lists.freebsd.org/pipermail/freebsd-stable/2014-October/080599.html" rel="nofollow noopener">you'll</a> <a href="https://forums.freebsd.org/threads/10-0-10-1-diocaddrule-operation-not-supported-by-device.49016/" rel="nofollow noopener">be</a> <a href="https://www.reddit.com/r/freebsd/comments/2mmzzy/101release_restart_problems_anyone/" rel="nofollow noopener">affected</a> by any of them</li>
<li>PC-BSD was also <a href="http://wiki.pcbsd.org/index.php/What%27s_New/10.1" rel="nofollow noopener">updated accordingly</a> with some of their own unique features and changes
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=aWmLWx8ut20" rel="nofollow noopener">arc4random - Randomization for All Occasions</a></h3>

<ul>
<li>Theo de Raadt gave an updated version of his EuroBSDCon presentation at Hackfest 2014 in Quebec</li>
<li>The presentation is mainly about OpenBSD's arc4random function, and outlines the overall poor state of randomization in the 90s and how it has evolved in OpenBSD over time</li>
<li>It begins with some interesting history on OpenBSD and how it became a security-focused OS - in 1996, their syslogd got broken into and "suddenly we became interested in security"</li>
<li>The talk also touches on how low-level changes can shake up the software ecosystem and third party packages that everyone uses</li>
<li>There's some funny history on the name of the function (being called arc4random despite not using RC4 anymore) and an overall status update on various platforms' usage of it</li>
<li>Very detailed and informative presentation, and the slides can be found <a href="http://www.openbsd.org/papers/hackfest2014-arc4random/index.html" rel="nofollow noopener">here</a></li>
<li>A great quote from the beginning: "We consider ourselves a community of (probably rather strange) people who work on software specifically for the purpose of trying to make it better. We take a 'whole-systems' approach: trying to change everything in the ecosystem that's under our control, trying to see if we can make it better. We gain a lot of strength by being able to throw backwards compatibility out the window. So that means that we're able to do research and the minute that we decide that something isn't right, we'll design an alternative for it and push it in. And if it ends up breaking everybody's machines from the previous stage to the next stage, that's fine because we'll end up in a happier place."
***</li>
</ul>

<h2>Interview - Justin Cormack - <a href="mailto:justin@netbsd.org" rel="nofollow noopener">justin@netbsd.org</a> / <a href="https://twitter.com/justincormack" rel="nofollow noopener">@justincormack</a></h2>

<p>NetBSD on Xen, rump kernels, various topics</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/11/freebsd-foundation-announces-generous.html" rel="nofollow noopener">The FreeBSD foundation's biggest donation</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post about the largest donation they've ever gotten</li>
<li>From the CEO of WhatsApp comes a whopping one million dollars in a single donation</li>
<li>It also has some comments from the donor about why they use BSD and why it's important to give back</li>
<li>Be sure to donate to the foundation of whatever BSD you use when you can - every little bit helps, especially for <a href="http://www.openbsd.org/donations.html" rel="nofollow noopener">OpenBSD</a>, <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">NetBSD</a> and <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">DragonFly</a> who don't have huge companies supporting them regularly like FreeBSD does
***</li>
</ul>

<h3><a href="http://open-zfs.org/wiki/OpenZFS_Developer_Summit" rel="nofollow noopener">OpenZFS Dev Summit 2014 videos</a></h3>

<ul>
<li>Videos from the recent OpenZFS developer summit are being uploaded, with speakers from different represented platforms and companies
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_05_14-bsdcanned_goods" rel="nofollow noopener">Matt Ahrens</a>, <a href="https://www.youtube.com/watch?v=XnTzbisLYzg" rel="nofollow noopener">opening keynote</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Raphael Carvalho, <a href="https://www.youtube.com/watch?v=TJLOBLSRoHE" rel="nofollow noopener">Platform Overview: ZFS on OSv</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Brian Behlendorf, <a href="https://www.youtube.com/watch?v=_MVOpMNV7LY" rel="nofollow noopener">Platform Overview: ZFS on Linux</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Prakash Surya, <a href="https://www.youtube.com/watch?v=UtlGt3ag0o0" rel="nofollow noopener">Platform Overview: illumos</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Xin Li, <a href="https://www.youtube.com/watch?v=xO0x5_3A1X4" rel="nofollow noopener">Platform Overview: FreeBSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>All platforms, <a href="https://www.youtube.com/watch?v=t4UlT0RmSCc" rel="nofollow noopener">Group Q&amp;A Session</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Dave Pacheco, <a href="https://www.youtube.com/watch?v=BEoCMpdB8WU" rel="nofollow noopener">Manta</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Saso Kiselkov, <a href="https://www.youtube.com/watch?v=TZF92taa_us" rel="nofollow noopener">Compression</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_12_04-zettabytes_for_days" rel="nofollow noopener">George Wilson</a>, <a href="https://www.youtube.com/watch?v=deJc0EMKrM4" rel="nofollow noopener">Performance</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Tim Feldman, <a href="https://www.youtube.com/watch?v=b1yqjV8qemU" rel="nofollow noopener">Host-Aware SMR</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Pavel Zakharov, <a href="https://www.youtube.com/watch?v=-4c4gsLi1LI" rel="nofollow noopener">Fast File Cloning</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>The audio is <a href="https://twitter.com/OpenZFS/status/534005125853888512" rel="nofollow noopener">pretty poor</a> on all of them unfortunately
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2014/11/bsdtalk248-dragonflybsd-with-matthew.html" rel="nofollow noopener">BSDTalk 248</a></h3>

<ul>
<li>Our friend Will Backman is still busy getting BSD interviews as well</li>
<li>This time he sits down with Matthew Dillon, the lead developer of DragonFly BSD</li>
<li>We've never had Dillon on the show, so you'll definitely want to give this one a listen</li>
<li>They mainly discuss all the big changes coming in DragonFly's upcoming 4.0 release
***</li>
</ul>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">MeetBSD 2014 videos</a></h3>

<ul>
<li>The presentations from this year's MeetBSD conference are starting to appear online as well
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013-10-02_stacks_of_cache" rel="nofollow noopener">Kirk McKusick</a>, <a href="https://www.youtube.com/watch?v=DEEr6dT-4uQ" rel="nofollow noopener">A Narrative History of BSD</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_27-bridging_the_gap" rel="nofollow noopener">Jordan Hubbard</a>, <a href="https://www.youtube.com/watch?v=Mri66Uz6-8Y" rel="nofollow noopener">FreeBSD: The Next 10 Years</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>Brendan Gregg, <a href="https://www.youtube.com/watch?v=uvKMptfXtdo" rel="nofollow noopener">Performance Analysis</a>
&lt;!-- i wonder if freebsdnews will rip our html again and repost it <sup>_^</sup> --&gt;</li>
<li>The slides can be found <a href="https://www.meetbsd.com/agenda/" rel="nofollow noopener">here</a> 
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20PXjp55N" rel="nofollow noopener">Dominik writes in</a></li>
<li><a href="http://slexy.org/view/s2LwEYT3bA" rel="nofollow noopener">Steven writes in</a></li>
<li><a href="http://slexy.org/view/s2ubK8vQVt" rel="nofollow noopener">Florian writes in</a></li>
<li><a href="http://slexy.org/view/s216Eq8nFG" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s21D2ugDUy" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141600819500004&amp;r=1&amp;w=2" rel="nofollow noopener">Contributing without code</a></li>
<li><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033176.html" rel="nofollow noopener">Compression isn't a CRIME</a></li>
<li><a href="https://www.marc.info/?t=141616714600001&amp;r=1&amp;w=2" rel="nofollow noopener">Securing web browsers</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>63: A Man's man(1)</title>
  <link>https://www.bsdnow.tv/63</link>
  <guid isPermaLink="false">0dbe70cc-bfdd-4af8-b67f-a5d1e85b7115</guid>
  <pubDate>Wed, 12 Nov 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/0dbe70cc-bfdd-4af8-b67f-a5d1e85b7115.mp3" length="70356244" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:37:43</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=273872" rel="nofollow noopener"&gt;Updates to FreeBSD's random(4)&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD's random device, which presents itself as "/dev/random" to &lt;a href="https://news.ycombinator.com/item?id=8550457" rel="nofollow noopener"&gt;users&lt;/a&gt;, has gotten a fairly major overhaul in -CURRENT&lt;/li&gt;
&lt;li&gt;The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna&lt;/li&gt;
&lt;li&gt;Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)&lt;/li&gt;
&lt;li&gt;Pluggable modules can now be written to add more sources of entropy&lt;/li&gt;
&lt;li&gt;These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" rel="nofollow noopener"&gt;OpenBSD Tor relays and network diversity&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about getting &lt;a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" rel="nofollow noopener"&gt;more BSD-based Tor nodes&lt;/a&gt; a few times in previous episodes&lt;/li&gt;
&lt;li&gt;The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes&lt;/li&gt;
&lt;li&gt;With the security features and attention to detail, it makes for an excellent dedicated Tor box&lt;/li&gt;
&lt;li&gt;More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large&lt;/li&gt;
&lt;li&gt;A few users are even saying they'll &lt;em&gt;convert their Linux nodes&lt;/em&gt; to OpenBSD to help out&lt;/li&gt;
&lt;li&gt;Check the archive for the full conversation, and maybe &lt;a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener"&gt;run a node yourself&lt;/a&gt; on any of the BSDs&lt;/li&gt;
&lt;li&gt;The Tor wiki page on OpenBSD is pretty &lt;a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" rel="nofollow noopener"&gt;out of date&lt;/a&gt; (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" rel="nofollow noopener"&gt;SSP now default for FreeBSD ports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SSP, or &lt;a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener"&gt;Stack Smashing Protection&lt;/a&gt;, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces&lt;/li&gt;
&lt;li&gt;It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)&lt;/li&gt;
&lt;li&gt;This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates&lt;/li&gt;
&lt;li&gt;If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over&lt;/li&gt;
&lt;li&gt;NetBSD made this the default on i386 and amd64 &lt;a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" rel="nofollow noopener"&gt;two years ago&lt;/a&gt; and OpenBSD made this the default on all architectures &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=103881967909595&amp;amp;w=2" rel="nofollow noopener"&gt;twelve years ago&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" rel="nofollow noopener"&gt;Building an OpenBSD firewall and router&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side&lt;/li&gt;
&lt;li&gt;The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris&lt;/li&gt;
&lt;li&gt;Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community&lt;/li&gt;
&lt;li&gt;They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.&lt;/li&gt;
&lt;li&gt;Through the comments, we also find out that &lt;strong&gt;QuakeCon runs OpenBSD&lt;/strong&gt; on their network&lt;/li&gt;
&lt;li&gt;Hopefully most of our listeners are running some kind of BSD as their gateway - &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;try it out&lt;/a&gt; if you haven't already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Kristaps Džonsons - &lt;a href="mailto:kristaps@bsd.lv" rel="nofollow noopener"&gt;kristaps@bsd.lv&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Mandoc, historical man pages, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" rel="nofollow noopener"&gt;Throttling bandwidth with PF&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" rel="nofollow noopener"&gt;NetBSD at Kansai Open Forum 2014&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Japanese NetBSD users invade yet another conference, demonstrating that they &lt;strong&gt;can and will&lt;/strong&gt; install NetBSD &lt;em&gt;on everything&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all&lt;/li&gt;
&lt;li&gt;As always, you can find lots of pictures in the trip report
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" rel="nofollow noopener"&gt;Getting to know your portmgr lurkers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The lovable "getting to know your portmgr" series makes its triumphant return&lt;/li&gt;
&lt;li&gt;This time around, they interview Alex, one of the portmgr lurkers that joined just this month&lt;/li&gt;
&lt;li&gt;"How would you describe yourself?" "Too lazy."&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" rel="nofollow noopener"&gt;Another post&lt;/a&gt; includes a short interview with Emanuel, another new lurker&lt;/li&gt;
&lt;li&gt;We discussed the portmgr lurkers initiative with Steve Wills &lt;a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" rel="nofollow noopener"&gt;a while back&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" rel="nofollow noopener"&gt;NetBSD's ARM port gets SMP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used&lt;/li&gt;
&lt;li&gt;This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X&lt;/li&gt;
&lt;li&gt;NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released&lt;/li&gt;
&lt;li&gt;There are also a few nice pictures in the article
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" rel="nofollow noopener"&gt;A high performance mid-range NAS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This blog post is about FreeNAS and optimizing iSCSI performance&lt;/li&gt;
&lt;li&gt;It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance&lt;/li&gt;
&lt;li&gt;There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings&lt;/li&gt;
&lt;li&gt;They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2xGCUj8mC" rel="nofollow noopener"&gt;Heto writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2SJ8xppDJ" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Ktl6BMk" rel="nofollow noopener"&gt;Tyler writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2AsrxU0ZQ" rel="nofollow noopener"&gt;Tim writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21yn0xLv2" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141379917200003&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;Suspicious contributions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141538800019451&amp;amp;w=2" rel="nofollow noopener"&gt;La puissance du fromage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" rel="nofollow noopener"&gt;Nothing unusual here&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, mandoc, sysjail, mdocml, mdoc, mancgi, mult, random, arc4random, libressl, meetbsd, fortuna, yarrow, soekris, alix, apu, altq, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=273872" rel="nofollow noopener">Updates to FreeBSD's random(4)</a></h3>

<ul>
<li>FreeBSD's random device, which presents itself as "/dev/random" to <a href="https://news.ycombinator.com/item?id=8550457" rel="nofollow noopener">users</a>, has gotten a fairly major overhaul in -CURRENT</li>
<li>The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna</li>
<li>Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)</li>
<li>Pluggable modules can now be written to add more sources of entropy</li>
<li>These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***</li>
</ul>

<h3><a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" rel="nofollow noopener">OpenBSD Tor relays and network diversity</a></h3>

<ul>
<li>We've talked about getting <a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" rel="nofollow noopener">more BSD-based Tor nodes</a> a few times in previous episodes</li>
<li>The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes</li>
<li>With the security features and attention to detail, it makes for an excellent dedicated Tor box</li>
<li>More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large</li>
<li>A few users are even saying they'll <em>convert their Linux nodes</em> to OpenBSD to help out</li>
<li>Check the archive for the full conversation, and maybe <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">run a node yourself</a> on any of the BSDs</li>
<li>The Tor wiki page on OpenBSD is pretty <a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" rel="nofollow noopener">out of date</a> (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" rel="nofollow noopener">SSP now default for FreeBSD ports</a></h3>

<ul>
<li>SSP, or <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener">Stack Smashing Protection</a>, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces</li>
<li>It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)</li>
<li>This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates</li>
<li>If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over</li>
<li>NetBSD made this the default on i386 and amd64 <a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" rel="nofollow noopener">two years ago</a> and OpenBSD made this the default on all architectures <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=103881967909595&amp;w=2" rel="nofollow noopener">twelve years ago</a></li>
<li>Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" rel="nofollow noopener">Building an OpenBSD firewall and router</a></h3>

<ul>
<li>While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side</li>
<li>The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris</li>
<li>Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community</li>
<li>They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.</li>
<li>Through the comments, we also find out that <strong>QuakeCon runs OpenBSD</strong> on their network</li>
<li>Hopefully most of our listeners are running some kind of BSD as their gateway - <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">try it out</a> if you haven't already
***</li>
</ul>

<h2>Interview - Kristaps Džonsons - <a href="mailto:kristaps@bsd.lv" rel="nofollow noopener">kristaps@bsd.lv</a></h2>

<p>Mandoc, historical man pages, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" rel="nofollow noopener">Throttling bandwidth with PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" rel="nofollow noopener">NetBSD at Kansai Open Forum 2014</a></h3>

<ul>
<li>Japanese NetBSD users invade yet another conference, demonstrating that they <strong>can and will</strong> install NetBSD <em>on everything</em></li>
<li>From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all</li>
<li>As always, you can find lots of pictures in the trip report
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The lovable "getting to know your portmgr" series makes its triumphant return</li>
<li>This time around, they interview Alex, one of the portmgr lurkers that joined just this month</li>
<li>"How would you describe yourself?" "Too lazy."</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" rel="nofollow noopener">Another post</a> includes a short interview with Emanuel, another new lurker</li>
<li>We discussed the portmgr lurkers initiative with Steve Wills <a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" rel="nofollow noopener">a while back</a>
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" rel="nofollow noopener">NetBSD's ARM port gets SMP</a></h3>

<ul>
<li>The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used</li>
<li>This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X</li>
<li>NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released</li>
<li>There are also a few nice pictures in the article
***</li>
</ul>

<h3><a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" rel="nofollow noopener">A high performance mid-range NAS</a></h3>

<ul>
<li>This blog post is about FreeNAS and optimizing iSCSI performance</li>
<li>It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance</li>
<li>There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings</li>
<li>They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xGCUj8mC" rel="nofollow noopener">Heto writes in</a></li>
<li><a href="http://slexy.org/view/s2SJ8xppDJ" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s20Ktl6BMk" rel="nofollow noopener">Tyler writes in</a></li>
<li><a href="http://slexy.org/view/s2AsrxU0ZQ" rel="nofollow noopener">Tim writes in</a></li>
<li><a href="http://slexy.org/view/s21yn0xLv2" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141379917200003&amp;r=1&amp;w=2" rel="nofollow noopener">Suspicious contributions</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141538800019451&amp;w=2" rel="nofollow noopener">La puissance du fromage</a></li>
<li><a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" rel="nofollow noopener">Nothing unusual here</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we've got an interview with Kristaps Džonsons, the creator of mandoc. He tells us how the project got started and what its current status is across the various BSDs. We also have a mini-tutorial on using PF to throttle bandwidth. This week's news, answers to your emails and even some cheesy mailing list gold, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=273872" rel="nofollow noopener">Updates to FreeBSD's random(4)</a></h3>

<ul>
<li>FreeBSD's random device, which presents itself as "/dev/random" to <a href="https://news.ycombinator.com/item?id=8550457" rel="nofollow noopener">users</a>, has gotten a fairly major overhaul in -CURRENT</li>
<li>The CSPRNG (cryptographically secure pseudo-random number generator) algorithm, Yarrow, now has a new alternative called Fortuna</li>
<li>Yarrow is still the default for now, but Fortuna can be used with a kernel option (and will likely be the new default in 11.0-RELEASE)</li>
<li>Pluggable modules can now be written to add more sources of entropy</li>
<li>These changes are expected to make it in 11.0-RELEASE, but there hasn't been any mention of MFCing them to 10 or 9
***</li>
</ul>

<h3><a href="https://lists.torproject.org/pipermail/tor-relays/2014-November/005661.html" rel="nofollow noopener">OpenBSD Tor relays and network diversity</a></h3>

<ul>
<li>We've talked about getting <a href="http://lists.nycbug.org/mailman/listinfo/tor-bsd" rel="nofollow noopener">more BSD-based Tor nodes</a> a few times in previous episodes</li>
<li>The "tor-relays" mailing list has had some recent discussion about increasing diversity in the Tor network, specifically by adding more OpenBSD nodes</li>
<li>With the security features and attention to detail, it makes for an excellent dedicated Tor box</li>
<li>More and more adversaries are attacking Tor nodes, so having something that can withstand that will help the greater network at large</li>
<li>A few users are even saying they'll <em>convert their Linux nodes</em> to OpenBSD to help out</li>
<li>Check the archive for the full conversation, and maybe <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">run a node yourself</a> on any of the BSDs</li>
<li>The Tor wiki page on OpenBSD is pretty <a href="https://lists.torproject.org/pipermail/tor-dev/2014-November/007715.html" rel="nofollow noopener">out of date</a> (nine years old!?) and uses the old pf syntax, maybe one of our listeners can modernize it
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096344.html" rel="nofollow noopener">SSP now default for FreeBSD ports</a></h3>

<ul>
<li>SSP, or <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener">Stack Smashing Protection</a>, is an additional layer of protection against buffer overflows that the compiler can give to the binaries it produces</li>
<li>It's now enabled by default in FreeBSD's ports tree, and the pkgng packages will have it as well - but only for amd64 (all supported releases) and i386 (10.0-RELEASE or newer)</li>
<li>This will only apply to regular ports and binary packages, not the quarterly branch that only receives security updates</li>
<li>If you were using the temporary "new Xorg" or SSP package repositories instead of the default ones, you need to switch back over</li>
<li>NetBSD made this the default on i386 and amd64 <a href="https://www.netbsd.org/releases/formal-6/NetBSD-6.0.html" rel="nofollow noopener">two years ago</a> and OpenBSD made this the default on all architectures <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=103881967909595&amp;w=2" rel="nofollow noopener">twelve years ago</a></li>
<li>Next time you rebuild your ports, things should be automatically hardened without any extra steps or configuration needed
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2ld0yw/building_an_openbsd_firewall_and_router/" rel="nofollow noopener">Building an OpenBSD firewall and router</a></h3>

<ul>
<li>While we've discussed the software and configuration of an OpenBSD router, this Reddit thread focuses more on the hardware side</li>
<li>The OP lists some of his potential choices, but was originally looking for something a bit cheaper than a Soekris</li>
<li>Most agree that, if it's for a business especially, it's worth the extra money to go with something that's well known in the BSD community</li>
<li>They also list a few other popular alternatives: ALIX or the APU series from PC Engines, some Supermicro boards, etc.</li>
<li>Through the comments, we also find out that <strong>QuakeCon runs OpenBSD</strong> on their network</li>
<li>Hopefully most of our listeners are running some kind of BSD as their gateway - <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">try it out</a> if you haven't already
***</li>
</ul>

<h2>Interview - Kristaps Džonsons - <a href="mailto:kristaps@bsd.lv" rel="nofollow noopener">kristaps@bsd.lv</a></h2>

<p>Mandoc, historical man pages, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openbsd-router#queues" rel="nofollow noopener">Throttling bandwidth with PF</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2014/11/08/msg000672.html" rel="nofollow noopener">NetBSD at Kansai Open Forum 2014</a></h3>

<ul>
<li>Japanese NetBSD users invade yet another conference, demonstrating that they <strong>can and will</strong> install NetBSD <em>on everything</em></li>
<li>From a Raspberry Pi to SHARP Netwalkers to various luna68k devices, they had it all</li>
<li>As always, you can find lots of pictures in the trip report
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/11/04/getting-to-know-your-portmgr-lurker-ak/" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The lovable "getting to know your portmgr" series makes its triumphant return</li>
<li>This time around, they interview Alex, one of the portmgr lurkers that joined just this month</li>
<li>"How would you describe yourself?" "Too lazy."</li>
<li><a href="http://blogs.freebsdish.org/portmgr/2014/11/08/getting-to-know-your-portmgr-lurker-ehaupt/" rel="nofollow noopener">Another post</a> includes a short interview with Emanuel, another new lurker</li>
<li>We discussed the portmgr lurkers initiative with Steve Wills <a href="http://www.bsdnow.tv/episodes/2014_10_01-the_daemons_apprentice" rel="nofollow noopener">a while back</a>
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/working_arm_multiprocessor_support" rel="nofollow noopener">NetBSD's ARM port gets SMP</a></h3>

<ul>
<li>The ARM port of NetBSD now has SMP support, allowing more than one CPU to be used</li>
<li>This blog post on the website has a list of supported boards: Banana Pi, Cubieboard 2, Cubietruck, Merrii Hummingbird A31, CUBOX-I and NITROGEN6X</li>
<li>NetBSD's release team is working on getting these changes into the 7 branch before 7.0 is released</li>
<li>There are also a few nice pictures in the article
***</li>
</ul>

<h3><a href="http://pivotallabs.com/high-performing-mid-range-nas-server-part-2-performance-tuning-iscsi/" rel="nofollow noopener">A high performance mid-range NAS</a></h3>

<ul>
<li>This blog post is about FreeNAS and optimizing iSCSI performance</li>
<li>It talks about using mid-range hardware with FreeNAS and different tunables you can change to affect performance</li>
<li>There are some nice graphs and lots of detail if you're interested in tweaking some of your own settings</li>
<li>They conclude "there is no optimal configuration; rather, FreeNAS can be configured to suit a particular workload"
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2xGCUj8mC" rel="nofollow noopener">Heto writes in</a></li>
<li><a href="http://slexy.org/view/s2SJ8xppDJ" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s20Ktl6BMk" rel="nofollow noopener">Tyler writes in</a></li>
<li><a href="http://slexy.org/view/s2AsrxU0ZQ" rel="nofollow noopener">Tim writes in</a></li>
<li><a href="http://slexy.org/view/s21yn0xLv2" rel="nofollow noopener">Brad writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141379917200003&amp;r=1&amp;w=2" rel="nofollow noopener">Suspicious contributions</a></li>
<li><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141538800019451&amp;w=2" rel="nofollow noopener">La puissance du fromage</a></li>
<li><a href="https://mail-index.netbsd.org/tech-ports/2002/07/05/0000.html" rel="nofollow noopener">Nothing unusual here</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>62: Gift from the Sun</title>
  <link>https://www.bsdnow.tv/62</link>
  <guid isPermaLink="false">1a099eb3-3c03-4d49-ba89-e6381381718d</guid>
  <pubDate>Wed, 05 Nov 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/1a099eb3-3c03-4d49-ba89-e6381381718d.mp3" length="24585844" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're away at MeetBSD this week, but we've still got a great show for you. We'll be joined by Pawel Dawidek, who's done quite a lot of things in FreeBSD over the years, including the initial ZFS port. We'll get to hear how that came about, what he's up to now and a whole lot more. We'll be back next week with a normal episode of BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>34:08</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're away at MeetBSD this week, but we've still got a great show for you. We'll be joined by Pawel Dawidek, who's done quite a lot of things in FreeBSD over the years, including the initial ZFS port. We'll get to hear how that came about, what he's up to now and a whole lot more. We'll be back next week with a normal episode of BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Interview - Pawel Jakub Dawidek - &lt;a href="mailto:pjd@freebsd.org" rel="nofollow noopener"&gt;pjd@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Porting ZFS, GEOM, GELI, Capsicum, various topics&lt;/p&gt;

&lt;hr&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, zfs, capsicum, geom, geli, openzfs, jails, solaris, illumos, opensolaris, openindiana, sun, oracle, meetbsd, meetbsdca, ixsystems</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're away at MeetBSD this week, but we've still got a great show for you. We'll be joined by Pawel Dawidek, who's done quite a lot of things in FreeBSD over the years, including the initial ZFS port. We'll get to hear how that came about, what he's up to now and a whole lot more. We'll be back next week with a normal episode of BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Interview - Pawel Jakub Dawidek - <a href="mailto:pjd@freebsd.org" rel="nofollow noopener">pjd@freebsd.org</a></h2>

<p>Porting ZFS, GEOM, GELI, Capsicum, various topics</p>

<hr>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're away at MeetBSD this week, but we've still got a great show for you. We'll be joined by Pawel Dawidek, who's done quite a lot of things in FreeBSD over the years, including the initial ZFS port. We'll get to hear how that came about, what he's up to now and a whole lot more. We'll be back next week with a normal episode of BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Interview - Pawel Jakub Dawidek - <a href="mailto:pjd@freebsd.org" rel="nofollow noopener">pjd@freebsd.org</a></h2>

<p>Porting ZFS, GEOM, GELI, Capsicum, various topics</p>

<hr>]]>
  </itunes:summary>
</item>
<item>
  <title>61: IPSECond Wind</title>
  <link>https://www.bsdnow.tv/61</link>
  <guid isPermaLink="false">a0bfab13-8167-4b68-b1de-74122013593a</guid>
  <pubDate>Wed, 29 Oct 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/a0bfab13-8167-4b68-b1de-74122013593a.mp3" length="53960980" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we sat down with John-Mark Gurney to talk about modernizing FreeBSD's IPSEC stack. We'll learn what he's adding, what needed to be fixed and how we'll benefit from the changes. As always, answers to your emails and all of this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:14:56</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we sat down with John-Mark Gurney to talk about modernizing FreeBSD's IPSEC stack. We'll learn what he's adding, what needed to be fixed and how we'll benefit from the changes. As always, answers to your emails and all of this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=3AOF7fm-TJ0" rel="nofollow noopener"&gt;BSD panel at Phoenix LUG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Phoenix, Arizona Linux users group had a special panel so they could learn a bit more about BSD&lt;/li&gt;
&lt;li&gt;It had one FreeBSD user and one OpenBSD user, and they answered questions from the organizer and the people in the audience&lt;/li&gt;
&lt;li&gt;They covered a variety of topics, including filesystems, firewalls, different development models, licenses and philosophy&lt;/li&gt;
&lt;li&gt;It was a good "real world" example of things potential switchers are curious to know about&lt;/li&gt;
&lt;li&gt;They closed by concluding that more diversity is always better, and even if you've got a lot of Linux boxes, putting a few BSD ones in the mix is a good idea
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2014/10/the-book-of-pf-3rd-edition-is-here.html" rel="nofollow noopener"&gt;Book of PF signed copy auction&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Peter Hansteen (who we've &lt;a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" rel="nofollow noopener"&gt;had on the show&lt;/a&gt;) is auctioning off the first signed copy of the new Book of PF&lt;/li&gt;
&lt;li&gt;All the profits from the sale will go to the &lt;a href="http://www.openbsd.org/donations.html" rel="nofollow noopener"&gt;OpenBSD Foundation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;The updated edition of the book includes all the latest pf syntax changes, but also provides examples for FreeBSD and NetBSD's versions (which still use ALTQ, among other differences)&lt;/li&gt;
&lt;li&gt;If you're interested in firewalls, security or even just advanced networking, this book is a great one to have on your shelf - and the money will also go to a good cause&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;Michael Lucas&lt;/a&gt; has &lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=141429413908567&amp;amp;w=2" rel="nofollow noopener"&gt;challenged Peter&lt;/a&gt; to raise more for the foundation than his last book selling - let's see who wins&lt;/li&gt;
&lt;li&gt;Pause the episode, &lt;a href="http://www.ebay.com/itm/321563281902" rel="nofollow noopener"&gt;go bid on it&lt;/a&gt; and then come back!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/10/freebsd-foundation-goes-to-eurobsdcon.html" rel="nofollow noopener"&gt;FreeBSD Foundation goes to EuroBSDCon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Some people from the FreeBSD Foundation went to EuroBSDCon this year, and come back with a nice trip report&lt;/li&gt;
&lt;li&gt;They also sponsored four other developers to go&lt;/li&gt;
&lt;li&gt;The foundation was there "to find out what people are working on, what kind of help they could use from the Foundation, feedback on what we can be doing to support the FreeBSD Project and community, and what features/functions people want supported in FreeBSD"&lt;/li&gt;
&lt;li&gt;They also have &lt;a href="http://freebsdfoundation.blogspot.com/2014/10/eurobsdcon-trip-report-kamil-czekirda.html" rel="nofollow noopener"&gt;a second report&lt;/a&gt; from Kamil Czekirda&lt;/li&gt;
&lt;li&gt;A total of $2000 was raised at the conference
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/56.html" rel="nofollow noopener"&gt;OpenBSD 5.6 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Note&lt;/strong&gt;: we're doing this story a couple days early - it's actually being released on November 1st (this Saturday), but we have next week off and didn't want to let this one slip through the cracks - it may be out by the time you're watching this&lt;/li&gt;
&lt;li&gt;Continuing their always-on-time six month release cycle, the OpenBSD team has released version 5.6&lt;/li&gt;
&lt;li&gt;It includes support for new hardware, lots of driver updates, network stack improvements (SMP, in particular) and new security features&lt;/li&gt;
&lt;li&gt;5.6 is the first formal release with LibreSSL, their fork of OpenSSL, and lots of ports have been fixed to work with it&lt;/li&gt;
&lt;li&gt;You can now hibernate your laptop when using a fully-encrypted filesystem (see &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;our tutorial&lt;/a&gt; for that)&lt;/li&gt;
&lt;li&gt;ALTQ, Kerberos, Lynx, Bluetooth, TCP Wrappers and Apache were all removed&lt;/li&gt;
&lt;li&gt;This will serve as a "transitional" release for a lot of services: moving from Sendmail to OpenSMTPD, from nginx to &lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener"&gt;httpd&lt;/a&gt; and from BIND to Unbound&lt;/li&gt;
&lt;li&gt;Sendmail, nginx and BIND will be gone in the next release, so either migrate to the new stuff between now and then or switch to the ports versions&lt;/li&gt;
&lt;li&gt;As always, 5.6 comes with its own &lt;a href="http://www.openbsd.org/lyrics.html#56" rel="nofollow noopener"&gt;song and artwork&lt;/a&gt; - the theme this time was obviously LibreSSL&lt;/li&gt;
&lt;li&gt;Be sure to check the &lt;a href="http://www.openbsd.org/plus56.html" rel="nofollow noopener"&gt;full changelog&lt;/a&gt; (&lt;em&gt;it's huge&lt;/em&gt;) and pick up &lt;a href="http://www.openbsd.org/orders.html" rel="nofollow noopener"&gt;a CD or tshirt&lt;/a&gt; to support their efforts&lt;/li&gt;
&lt;li&gt;If you don't already have the public key releases are signed with, getting a physical CD is a good "out of bounds" way to obtain it safely&lt;/li&gt;
&lt;li&gt;Here are some cool &lt;a href="https://imgur.com/a/5PtFe" rel="nofollow noopener"&gt;images of the set&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;After you do your installation or &lt;a href="http://www.openbsd.org/faq/upgrade56.html" rel="nofollow noopener"&gt;upgrade&lt;/a&gt;, don't forget to head over to &lt;a href="http://www.openbsd.org/errata56.html" rel="nofollow noopener"&gt;the errata page&lt;/a&gt; and apply any patches listed there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - John-Mark Gurney - &lt;a href="mailto:jmg@freebsd.org" rel="nofollow noopener"&gt;jmg@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/encthenet" rel="nofollow noopener"&gt;@encthenet&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Updating FreeBSD's IPSEC stack&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.dragonflydigest.com/2014/10/22/14942.html" rel="nofollow noopener"&gt;Clang in DragonFly BSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As we all know, FreeBSD got rid of GCC in 10.0, and now uses Clang almost exclusively on i386/amd64&lt;/li&gt;
&lt;li&gt;Some DragonFly developers are considering migrating over as well, and one of them is doing some work to make the OS more Clang-friendly&lt;/li&gt;
&lt;li&gt;We'd love to see more BSDs switch to Clang/LLVM eventually, it's a lot more modern than the old GCC most are using
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener"&gt;reallocarray(): integer overflow detection for free&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the less obvious features in OpenBSD 5.6 is a new libc function: "reallocarray()"&lt;/li&gt;
&lt;li&gt;It's a replacement function for realloc(3) that provides integer overflow detection at basically no extra cost&lt;/li&gt;
&lt;li&gt;Theo and a few other developers have &lt;a href="https://secure.freshbsd.org/search?project=openbsd&amp;amp;q=reallocarray" rel="nofollow noopener"&gt;already started&lt;/a&gt; a mass audit of the entire source tree, replacing many instances with this new feature&lt;/li&gt;
&lt;li&gt;OpenBSD's explicit_bzero was recently imported into FreeBSD, maybe someone could also port over this too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bothsidesofthence.tumblr.com/" rel="nofollow noopener"&gt;Switching from Linux blog&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A listener of the show has started a new blog series, detailing his experiences in switching over to BSD from Linux&lt;/li&gt;
&lt;li&gt;After over ten years of using Linux, he decided to give BSD a try after listening to our show (which is awesome)&lt;/li&gt;
&lt;li&gt;So far, he's put up a few posts about his initial thoughts, some documentation he's going through and his experiments so far&lt;/li&gt;
&lt;li&gt;It'll be an ongoing series, so we may check back in with him again later on
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=z6VQwOl4wE4" rel="nofollow noopener"&gt;Owncloud in a FreeNAS jail&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the most common emails we get is about running Owncloud in FreeNAS&lt;/li&gt;
&lt;li&gt;Now, finally, someone made a video on how to do just that, and it's even jailed&lt;/li&gt;
&lt;li&gt;A member of the FreeNAS community has uploaded a video on how to set it up, with lighttpd as the webserver backend&lt;/li&gt;
&lt;li&gt;If you're looking for an easy way to back up and sync your files, this might be worth a watch
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2XEsQdggZ" rel="nofollow noopener"&gt;Ernõ writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21EizH2aR" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s24SAJ5im6" rel="nofollow noopener"&gt;Kamil writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20ABZe0RD" rel="nofollow noopener"&gt;Torsten writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s208jQs9c6" rel="nofollow noopener"&gt;Dominik writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://mail-index.netbsd.org/source-changes/2014/10/17/msg059564.html" rel="nofollow noopener"&gt;That's not our IP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-acpi/2014-June/008644.html" rel="nofollow noopener"&gt;Is this thing on?&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ipsec, aes, gcm, chacha20, encryption, netsec, ike, openiked, infosec, 5.6, openhttpd, opensmtpd, meetbsd, book of pf, libressl, freenas, owncloud</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we sat down with John-Mark Gurney to talk about modernizing FreeBSD's IPSEC stack. We'll learn what he's adding, what needed to be fixed and how we'll benefit from the changes. As always, answers to your emails and all of this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/watch?v=3AOF7fm-TJ0" rel="nofollow noopener">BSD panel at Phoenix LUG</a></h3>

<ul>
<li>The Phoenix, Arizona Linux users group had a special panel so they could learn a bit more about BSD</li>
<li>It had one FreeBSD user and one OpenBSD user, and they answered questions from the organizer and the people in the audience</li>
<li>They covered a variety of topics, including filesystems, firewalls, different development models, licenses and philosophy</li>
<li>It was a good "real world" example of things potential switchers are curious to know about</li>
<li>They closed by concluding that more diversity is always better, and even if you've got a lot of Linux boxes, putting a few BSD ones in the mix is a good idea
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/10/the-book-of-pf-3rd-edition-is-here.html" rel="nofollow noopener">Book of PF signed copy auction</a></h3>

<ul>
<li>Peter Hansteen (who we've <a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" rel="nofollow noopener">had on the show</a>) is auctioning off the first signed copy of the new Book of PF</li>
<li>All the profits from the sale will go to the <a href="http://www.openbsd.org/donations.html" rel="nofollow noopener">OpenBSD Foundation</a></li>
<li>The updated edition of the book includes all the latest pf syntax changes, but also provides examples for FreeBSD and NetBSD's versions (which still use ALTQ, among other differences)</li>
<li>If you're interested in firewalls, security or even just advanced networking, this book is a great one to have on your shelf - and the money will also go to a good cause</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">Michael Lucas</a> has <a href="https://www.marc.info/?l=openbsd-misc&amp;m=141429413908567&amp;w=2" rel="nofollow noopener">challenged Peter</a> to raise more for the foundation than his last book selling - let's see who wins</li>
<li>Pause the episode, <a href="http://www.ebay.com/itm/321563281902" rel="nofollow noopener">go bid on it</a> and then come back!
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/10/freebsd-foundation-goes-to-eurobsdcon.html" rel="nofollow noopener">FreeBSD Foundation goes to EuroBSDCon</a></h3>

<ul>
<li>Some people from the FreeBSD Foundation went to EuroBSDCon this year, and come back with a nice trip report</li>
<li>They also sponsored four other developers to go</li>
<li>The foundation was there "to find out what people are working on, what kind of help they could use from the Foundation, feedback on what we can be doing to support the FreeBSD Project and community, and what features/functions people want supported in FreeBSD"</li>
<li>They also have <a href="http://freebsdfoundation.blogspot.com/2014/10/eurobsdcon-trip-report-kamil-czekirda.html" rel="nofollow noopener">a second report</a> from Kamil Czekirda</li>
<li>A total of $2000 was raised at the conference
***</li>
</ul>

<h3><a href="http://www.openbsd.org/56.html" rel="nofollow noopener">OpenBSD 5.6 released</a></h3>

<ul>
<li><strong>Note</strong>: we're doing this story a couple days early - it's actually being released on November 1st (this Saturday), but we have next week off and didn't want to let this one slip through the cracks - it may be out by the time you're watching this</li>
<li>Continuing their always-on-time six month release cycle, the OpenBSD team has released version 5.6</li>
<li>It includes support for new hardware, lots of driver updates, network stack improvements (SMP, in particular) and new security features</li>
<li>5.6 is the first formal release with LibreSSL, their fork of OpenSSL, and lots of ports have been fixed to work with it</li>
<li>You can now hibernate your laptop when using a fully-encrypted filesystem (see <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">our tutorial</a> for that)</li>
<li>ALTQ, Kerberos, Lynx, Bluetooth, TCP Wrappers and Apache were all removed</li>
<li>This will serve as a "transitional" release for a lot of services: moving from Sendmail to OpenSMTPD, from nginx to <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">httpd</a> and from BIND to Unbound</li>
<li>Sendmail, nginx and BIND will be gone in the next release, so either migrate to the new stuff between now and then or switch to the ports versions</li>
<li>As always, 5.6 comes with its own <a href="http://www.openbsd.org/lyrics.html#56" rel="nofollow noopener">song and artwork</a> - the theme this time was obviously LibreSSL</li>
<li>Be sure to check the <a href="http://www.openbsd.org/plus56.html" rel="nofollow noopener">full changelog</a> (<em>it's huge</em>) and pick up <a href="http://www.openbsd.org/orders.html" rel="nofollow noopener">a CD or tshirt</a> to support their efforts</li>
<li>If you don't already have the public key releases are signed with, getting a physical CD is a good "out of bounds" way to obtain it safely</li>
<li>Here are some cool <a href="https://imgur.com/a/5PtFe" rel="nofollow noopener">images of the set</a></li>
<li>After you do your installation or <a href="http://www.openbsd.org/faq/upgrade56.html" rel="nofollow noopener">upgrade</a>, don't forget to head over to <a href="http://www.openbsd.org/errata56.html" rel="nofollow noopener">the errata page</a> and apply any patches listed there
***</li>
</ul>

<h2>Interview - John-Mark Gurney - <a href="mailto:jmg@freebsd.org" rel="nofollow noopener">jmg@freebsd.org</a> / <a href="https://twitter.com/encthenet" rel="nofollow noopener">@encthenet</a></h2>

<p>Updating FreeBSD's IPSEC stack</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.dragonflydigest.com/2014/10/22/14942.html" rel="nofollow noopener">Clang in DragonFly BSD</a></h3>

<ul>
<li>As we all know, FreeBSD got rid of GCC in 10.0, and now uses Clang almost exclusively on i386/amd64</li>
<li>Some DragonFly developers are considering migrating over as well, and one of them is doing some work to make the OS more Clang-friendly</li>
<li>We'd love to see more BSDs switch to Clang/LLVM eventually, it's a lot more modern than the old GCC most are using
***</li>
</ul>

<h3><a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener">reallocarray(): integer overflow detection for free</a></h3>

<ul>
<li>One of the less obvious features in OpenBSD 5.6 is a new libc function: "reallocarray()"</li>
<li>It's a replacement function for realloc(3) that provides integer overflow detection at basically no extra cost</li>
<li>Theo and a few other developers have <a href="https://secure.freshbsd.org/search?project=openbsd&amp;q=reallocarray" rel="nofollow noopener">already started</a> a mass audit of the entire source tree, replacing many instances with this new feature</li>
<li>OpenBSD's explicit_bzero was recently imported into FreeBSD, maybe someone could also port over this too
***</li>
</ul>

<h3><a href="http://bothsidesofthence.tumblr.com/" rel="nofollow noopener">Switching from Linux blog</a></h3>

<ul>
<li>A listener of the show has started a new blog series, detailing his experiences in switching over to BSD from Linux</li>
<li>After over ten years of using Linux, he decided to give BSD a try after listening to our show (which is awesome)</li>
<li>So far, he's put up a few posts about his initial thoughts, some documentation he's going through and his experiments so far</li>
<li>It'll be an ongoing series, so we may check back in with him again later on
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=z6VQwOl4wE4" rel="nofollow noopener">Owncloud in a FreeNAS jail</a></h3>

<ul>
<li>One of the most common emails we get is about running Owncloud in FreeNAS</li>
<li>Now, finally, someone made a video on how to do just that, and it's even jailed</li>
<li>A member of the FreeNAS community has uploaded a video on how to set it up, with lighttpd as the webserver backend</li>
<li>If you're looking for an easy way to back up and sync your files, this might be worth a watch
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2XEsQdggZ" rel="nofollow noopener">Ernõ writes in</a></li>
<li><a href="http://slexy.org/view/s21EizH2aR" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s24SAJ5im6" rel="nofollow noopener">Kamil writes in</a></li>
<li><a href="http://slexy.org/view/s20ABZe0RD" rel="nofollow noopener">Torsten writes in</a></li>
<li><a href="http://slexy.org/view/s208jQs9c6" rel="nofollow noopener">Dominik writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://mail-index.netbsd.org/source-changes/2014/10/17/msg059564.html" rel="nofollow noopener">That's not our IP</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-acpi/2014-June/008644.html" rel="nofollow noopener">Is this thing on?</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we sat down with John-Mark Gurney to talk about modernizing FreeBSD's IPSEC stack. We'll learn what he's adding, what needed to be fixed and how we'll benefit from the changes. As always, answers to your emails and all of this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/watch?v=3AOF7fm-TJ0" rel="nofollow noopener">BSD panel at Phoenix LUG</a></h3>

<ul>
<li>The Phoenix, Arizona Linux users group had a special panel so they could learn a bit more about BSD</li>
<li>It had one FreeBSD user and one OpenBSD user, and they answered questions from the organizer and the people in the audience</li>
<li>They covered a variety of topics, including filesystems, firewalls, different development models, licenses and philosophy</li>
<li>It was a good "real world" example of things potential switchers are curious to know about</li>
<li>They closed by concluding that more diversity is always better, and even if you've got a lot of Linux boxes, putting a few BSD ones in the mix is a good idea
***</li>
</ul>

<h3><a href="http://bsdly.blogspot.com/2014/10/the-book-of-pf-3rd-edition-is-here.html" rel="nofollow noopener">Book of PF signed copy auction</a></h3>

<ul>
<li>Peter Hansteen (who we've <a href="http://www.bsdnow.tv/episodes/2014_04_30-puffy_firewall" rel="nofollow noopener">had on the show</a>) is auctioning off the first signed copy of the new Book of PF</li>
<li>All the profits from the sale will go to the <a href="http://www.openbsd.org/donations.html" rel="nofollow noopener">OpenBSD Foundation</a></li>
<li>The updated edition of the book includes all the latest pf syntax changes, but also provides examples for FreeBSD and NetBSD's versions (which still use ALTQ, among other differences)</li>
<li>If you're interested in firewalls, security or even just advanced networking, this book is a great one to have on your shelf - and the money will also go to a good cause</li>
<li><a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">Michael Lucas</a> has <a href="https://www.marc.info/?l=openbsd-misc&amp;m=141429413908567&amp;w=2" rel="nofollow noopener">challenged Peter</a> to raise more for the foundation than his last book selling - let's see who wins</li>
<li>Pause the episode, <a href="http://www.ebay.com/itm/321563281902" rel="nofollow noopener">go bid on it</a> and then come back!
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/10/freebsd-foundation-goes-to-eurobsdcon.html" rel="nofollow noopener">FreeBSD Foundation goes to EuroBSDCon</a></h3>

<ul>
<li>Some people from the FreeBSD Foundation went to EuroBSDCon this year, and come back with a nice trip report</li>
<li>They also sponsored four other developers to go</li>
<li>The foundation was there "to find out what people are working on, what kind of help they could use from the Foundation, feedback on what we can be doing to support the FreeBSD Project and community, and what features/functions people want supported in FreeBSD"</li>
<li>They also have <a href="http://freebsdfoundation.blogspot.com/2014/10/eurobsdcon-trip-report-kamil-czekirda.html" rel="nofollow noopener">a second report</a> from Kamil Czekirda</li>
<li>A total of $2000 was raised at the conference
***</li>
</ul>

<h3><a href="http://www.openbsd.org/56.html" rel="nofollow noopener">OpenBSD 5.6 released</a></h3>

<ul>
<li><strong>Note</strong>: we're doing this story a couple days early - it's actually being released on November 1st (this Saturday), but we have next week off and didn't want to let this one slip through the cracks - it may be out by the time you're watching this</li>
<li>Continuing their always-on-time six month release cycle, the OpenBSD team has released version 5.6</li>
<li>It includes support for new hardware, lots of driver updates, network stack improvements (SMP, in particular) and new security features</li>
<li>5.6 is the first formal release with LibreSSL, their fork of OpenSSL, and lots of ports have been fixed to work with it</li>
<li>You can now hibernate your laptop when using a fully-encrypted filesystem (see <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">our tutorial</a> for that)</li>
<li>ALTQ, Kerberos, Lynx, Bluetooth, TCP Wrappers and Apache were all removed</li>
<li>This will serve as a "transitional" release for a lot of services: moving from Sendmail to OpenSMTPD, from nginx to <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">httpd</a> and from BIND to Unbound</li>
<li>Sendmail, nginx and BIND will be gone in the next release, so either migrate to the new stuff between now and then or switch to the ports versions</li>
<li>As always, 5.6 comes with its own <a href="http://www.openbsd.org/lyrics.html#56" rel="nofollow noopener">song and artwork</a> - the theme this time was obviously LibreSSL</li>
<li>Be sure to check the <a href="http://www.openbsd.org/plus56.html" rel="nofollow noopener">full changelog</a> (<em>it's huge</em>) and pick up <a href="http://www.openbsd.org/orders.html" rel="nofollow noopener">a CD or tshirt</a> to support their efforts</li>
<li>If you don't already have the public key releases are signed with, getting a physical CD is a good "out of bounds" way to obtain it safely</li>
<li>Here are some cool <a href="https://imgur.com/a/5PtFe" rel="nofollow noopener">images of the set</a></li>
<li>After you do your installation or <a href="http://www.openbsd.org/faq/upgrade56.html" rel="nofollow noopener">upgrade</a>, don't forget to head over to <a href="http://www.openbsd.org/errata56.html" rel="nofollow noopener">the errata page</a> and apply any patches listed there
***</li>
</ul>

<h2>Interview - John-Mark Gurney - <a href="mailto:jmg@freebsd.org" rel="nofollow noopener">jmg@freebsd.org</a> / <a href="https://twitter.com/encthenet" rel="nofollow noopener">@encthenet</a></h2>

<p>Updating FreeBSD's IPSEC stack</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.dragonflydigest.com/2014/10/22/14942.html" rel="nofollow noopener">Clang in DragonFly BSD</a></h3>

<ul>
<li>As we all know, FreeBSD got rid of GCC in 10.0, and now uses Clang almost exclusively on i386/amd64</li>
<li>Some DragonFly developers are considering migrating over as well, and one of them is doing some work to make the OS more Clang-friendly</li>
<li>We'd love to see more BSDs switch to Clang/LLVM eventually, it's a lot more modern than the old GCC most are using
***</li>
</ul>

<h3><a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener">reallocarray(): integer overflow detection for free</a></h3>

<ul>
<li>One of the less obvious features in OpenBSD 5.6 is a new libc function: "reallocarray()"</li>
<li>It's a replacement function for realloc(3) that provides integer overflow detection at basically no extra cost</li>
<li>Theo and a few other developers have <a href="https://secure.freshbsd.org/search?project=openbsd&amp;q=reallocarray" rel="nofollow noopener">already started</a> a mass audit of the entire source tree, replacing many instances with this new feature</li>
<li>OpenBSD's explicit_bzero was recently imported into FreeBSD, maybe someone could also port over this too
***</li>
</ul>

<h3><a href="http://bothsidesofthence.tumblr.com/" rel="nofollow noopener">Switching from Linux blog</a></h3>

<ul>
<li>A listener of the show has started a new blog series, detailing his experiences in switching over to BSD from Linux</li>
<li>After over ten years of using Linux, he decided to give BSD a try after listening to our show (which is awesome)</li>
<li>So far, he's put up a few posts about his initial thoughts, some documentation he's going through and his experiments so far</li>
<li>It'll be an ongoing series, so we may check back in with him again later on
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=z6VQwOl4wE4" rel="nofollow noopener">Owncloud in a FreeNAS jail</a></h3>

<ul>
<li>One of the most common emails we get is about running Owncloud in FreeNAS</li>
<li>Now, finally, someone made a video on how to do just that, and it's even jailed</li>
<li>A member of the FreeNAS community has uploaded a video on how to set it up, with lighttpd as the webserver backend</li>
<li>If you're looking for an easy way to back up and sync your files, this might be worth a watch
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2XEsQdggZ" rel="nofollow noopener">Ernõ writes in</a></li>
<li><a href="http://slexy.org/view/s21EizH2aR" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s24SAJ5im6" rel="nofollow noopener">Kamil writes in</a></li>
<li><a href="http://slexy.org/view/s20ABZe0RD" rel="nofollow noopener">Torsten writes in</a></li>
<li><a href="http://slexy.org/view/s208jQs9c6" rel="nofollow noopener">Dominik writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://mail-index.netbsd.org/source-changes/2014/10/17/msg059564.html" rel="nofollow noopener">That's not our IP</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-acpi/2014-June/008644.html" rel="nofollow noopener">Is this thing on?</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>50: VPN, My Dear Watson</title>
  <link>https://www.bsdnow.tv/50</link>
  <guid isPermaLink="false">b0306dc5-ee87-4a03-aeea-9a89b915ff5e</guid>
  <pubDate>Wed, 13 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b0306dc5-ee87-4a03-aeea-9a89b915ff5e.mp3" length="62998996" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:27:29</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener"&gt;MeetBSD 2014 is approaching&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California&lt;/li&gt;
&lt;li&gt;MeetBSD has an "unconference" format, which means there will be both planned talks and community events&lt;/li&gt;
&lt;li&gt;All the extra details will be on &lt;a href="https://www.meetbsd.com/" rel="nofollow noopener"&gt;their site&lt;/a&gt; soon&lt;/li&gt;
&lt;li&gt;It also has hotels and various other bits of useful information - hopefully with more info on the talks to come&lt;/li&gt;
&lt;li&gt;Of course, EuroBSDCon is coming up before then
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener"&gt;First experiences with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"&lt;/li&gt;
&lt;li&gt;The author read the famous "&lt;a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener"&gt;BSD for Linux users&lt;/a&gt;" series (that most of us have surely seen) and decided to give BSD a try&lt;/li&gt;
&lt;li&gt;He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"&lt;/li&gt;
&lt;li&gt;From there, it talks about how he used the OpenBSD USB image and got a fully-working system&lt;/li&gt;
&lt;li&gt;He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration&lt;/li&gt;
&lt;li&gt;Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener"&gt;NetBSD rump kernels on bare metal (and Kansai OSC report)&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right&lt;/li&gt;
&lt;li&gt;However, NetBSD's rump kernels - a very unique concept - make this process a lot easier&lt;/li&gt;
&lt;li&gt;This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week&lt;/li&gt;
&lt;li&gt;Also have a look back at &lt;a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener"&gt;episode 8&lt;/a&gt; for our interview about rump kernels and what exactly they do&lt;/li&gt;
&lt;li&gt;While on the topic of NetBSD, there were also a couple of &lt;a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener"&gt;very detailed reports&lt;/a&gt; (with lots of pictures!) of the various NetBSD-themed booths at the 2014 &lt;a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener"&gt;Kansai Open Source Conference&lt;/a&gt; that we wanted to highlight
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener"&gt;OpenSSL and LibreSSL updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)&lt;/li&gt;
&lt;li&gt;Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more&lt;/li&gt;
&lt;li&gt;&lt;a href="http://marc.info/?l=openbsd-tech&amp;amp;m=140752295222929&amp;amp;w=2" rel="nofollow noopener"&gt;LibreSSL released a new version&lt;/a&gt; to address most of the vulnerabilities, but wasn't affected by some of them&lt;/li&gt;
&lt;li&gt;Whichever version of whatever SSL you use, make sure it's patched for these issues&lt;/li&gt;
&lt;li&gt;DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Robert Watson - &lt;a href="mailto:rwatson@freebsd.org" rel="nofollow noopener"&gt;rwatson@freebsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD architecture, security research techniques, exploit mitigation&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener"&gt;Protecting traffic with a BSD-based VPN&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener"&gt;A FreeBSD-based CGit server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you use git (like a certain host of this show) then you've probably considered setting up your own server&lt;/li&gt;
&lt;li&gt;This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend&lt;/li&gt;
&lt;li&gt;It even shows you how to set up multiple repos with key-based user separation and other cool things&lt;/li&gt;
&lt;li&gt;The author of the post is also a listener of the show, thanks for sending it in!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener"&gt;Backup devices for small businesses&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In this article, different methods of data storage and backup are compared&lt;/li&gt;
&lt;li&gt;After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer&lt;/li&gt;
&lt;li&gt;He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers&lt;/li&gt;
&lt;li&gt;It also goes over some of the hardware specifics in the FreeNAS Mini
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener"&gt;A new Xenocara interview&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara&lt;/li&gt;
&lt;li&gt;If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches&lt;/li&gt;
&lt;li&gt;In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing&lt;/li&gt;
&lt;li&gt;Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener"&gt;Building a high performance FreeBSD samba server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?&lt;/li&gt;
&lt;li&gt;FreeBSD, ZFS and Samba obviously!&lt;/li&gt;
&lt;li&gt;The master image and related files clock in at over 20GB, and will be accessed at the same time by &lt;em&gt;all&lt;/em&gt; of those clients&lt;/li&gt;
&lt;li&gt;This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)&lt;/li&gt;
&lt;li&gt;It doesn't even require the newest or best hardware with the right changes, pretty cool
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener"&gt;An interesting Reddit thread&lt;/a&gt; (&lt;a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener"&gt;or two&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener"&gt;PB writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener"&gt;Steve writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener"&gt;Lachlan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener"&gt;Justin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, vpn, vps, openvpn, tunnel, ssh, security, exploit mitigation, zfs, lzo, tls, xenocara, x11, xorg, freenas, freenas mini, ixsystems, network attached storage, nas, meetbsd, rump kernels, libressl, openssl, kansai</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener">MeetBSD 2014 is approaching</a></h3>

<ul>
<li>The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California</li>
<li>MeetBSD has an "unconference" format, which means there will be both planned talks and community events</li>
<li>All the extra details will be on <a href="https://www.meetbsd.com/" rel="nofollow noopener">their site</a> soon</li>
<li>It also has hotels and various other bits of useful information - hopefully with more info on the talks to come</li>
<li>Of course, EuroBSDCon is coming up before then
***</li>
</ul>

<h3><a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener">First experiences with OpenBSD</a></h3>

<ul>
<li>A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"</li>
<li>The author read the famous "<a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener">BSD for Linux users</a>" series (that most of us have surely seen) and decided to give BSD a try</li>
<li>He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"</li>
<li>From there, it talks about how he used the OpenBSD USB image and got a fully-working system</li>
<li>He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration</li>
<li>Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener">NetBSD rump kernels on bare metal (and Kansai OSC report)</a></h3>

<ul>
<li>When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right</li>
<li>However, NetBSD's rump kernels - a very unique concept - make this process a lot easier</li>
<li>This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week</li>
<li>Also have a look back at <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">episode 8</a> for our interview about rump kernels and what exactly they do</li>
<li>While on the topic of NetBSD, there were also a couple of <a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener">very detailed reports</a> (with lots of pictures!) of the various NetBSD-themed booths at the 2014 <a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener">Kansai Open Source Conference</a> that we wanted to highlight
***</li>
</ul>

<h3><a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener">OpenSSL and LibreSSL updates</a></h3>

<ul>
<li>OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)</li>
<li>Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more</li>
<li><a href="http://marc.info/?l=openbsd-tech&amp;m=140752295222929&amp;w=2" rel="nofollow noopener">LibreSSL released a new version</a> to address most of the vulnerabilities, but wasn't affected by some of them</li>
<li>Whichever version of whatever SSL you use, make sure it's patched for these issues</li>
<li>DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***</li>
</ul>

<h2>Interview - Robert Watson - <a href="mailto:rwatson@freebsd.org" rel="nofollow noopener">rwatson@freebsd.org</a></h2>

<p>FreeBSD architecture, security research techniques, exploit mitigation</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener">Protecting traffic with a BSD-based VPN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener">A FreeBSD-based CGit server</a></h3>

<ul>
<li>If you use git (like a certain host of this show) then you've probably considered setting up your own server</li>
<li>This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend</li>
<li>It even shows you how to set up multiple repos with key-based user separation and other cool things</li>
<li>The author of the post is also a listener of the show, thanks for sending it in!
***</li>
</ul>

<h3><a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener">Backup devices for small businesses</a></h3>

<ul>
<li>In this article, different methods of data storage and backup are compared</li>
<li>After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer</li>
<li>He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers</li>
<li>It also goes over some of the hardware specifics in the FreeNAS Mini
***</li>
</ul>

<h3><a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener">A new Xenocara interview</a></h3>

<ul>
<li>As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara</li>
<li>If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches</li>
<li>In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing</li>
<li>Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***</li>
</ul>

<h3><a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener">Building a high performance FreeBSD samba server</a></h3>

<ul>
<li>If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?</li>
<li>FreeBSD, ZFS and Samba obviously!</li>
<li>The master image and related files clock in at over 20GB, and will be accessed at the same time by <em>all</em> of those clients</li>
<li>This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)</li>
<li>It doesn't even require the newest or best hardware with the right changes, pretty cool
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener">An interesting Reddit thread</a> (<a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener">or two</a>)</li>
<li><a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener">PB writes in</a></li>
<li><a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener">Steve writes in</a></li>
<li><a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener">Justin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's our 50th episode, and we're going to show you how to protect your internet traffic with a BSD-based VPN. We'll also be talking to Robert Watson, of the FreeBSD core team, about security research, exploit mitigation and a whole lot more. The latest news and answers to all of your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://www.ixsystems.com/whats-new/ixsystems-to-host-meetbsd-california-2014-at-western-digital-in-san-jose/" rel="nofollow noopener">MeetBSD 2014 is approaching</a></h3>

<ul>
<li>The MeetBSD conference is coming up, and will be held on November 1st and 2nd in San Jose, California</li>
<li>MeetBSD has an "unconference" format, which means there will be both planned talks and community events</li>
<li>All the extra details will be on <a href="https://www.meetbsd.com/" rel="nofollow noopener">their site</a> soon</li>
<li>It also has hotels and various other bits of useful information - hopefully with more info on the talks to come</li>
<li>Of course, EuroBSDCon is coming up before then
***</li>
</ul>

<h3><a href="https://www.azabani.com/2014/08/09/first-experiences-with-openbsd.html" rel="nofollow noopener">First experiences with OpenBSD</a></h3>

<ul>
<li>A new blog post that leads off with "tired of the sluggishness of Windows on my laptop and interested in experimenting with a Unix-like that I haven't tried before"</li>
<li>The author read the famous "<a href="http://www.over-yonder.net/%7Efullermd/rants/bsd4linux/01" rel="nofollow noopener">BSD for Linux users</a>" series (that most of us have surely seen) and decided to give BSD a try</li>
<li>He details his different OS and distro history, concluding with how he "eventually became annoyed at the poor quality of Linux userland software"</li>
<li>From there, it talks about how he used the OpenBSD USB image and got a fully-working system</li>
<li>He especially liked the simplicity of OpenBSD's "hostname.if" system for network configuration</li>
<li>Finally, he gets Xorg working and imports all his usual configuration files - seems to be a happy new user! 
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/an_internet_ready_os_from" rel="nofollow noopener">NetBSD rump kernels on bare metal (and Kansai OSC report)</a></h3>

<ul>
<li>When you're developing a new OS or a very specialized custom solution, working drivers become one of the hardest things to get right</li>
<li>However, NetBSD's rump kernels - a very unique concept - make this process a lot easier</li>
<li>This blog post talks about the process of starting with just a rump kernel and expanding into an internet-ready system in just a week</li>
<li>Also have a look back at <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">episode 8</a> for our interview about rump kernels and what exactly they do</li>
<li>While on the topic of NetBSD, there were also a couple of <a href="http://mail-index.netbsd.org/netbsd-advocacy/2014/08/09/msg000658.html" rel="nofollow noopener">very detailed reports</a> (with lots of pictures!) of the various NetBSD-themed booths at the 2014 <a href="http://d.hatena.ne.jp/mizuno-as/20140806/1407307913" rel="nofollow noopener">Kansai Open Source Conference</a> that we wanted to highlight
***</li>
</ul>

<h3><a href="https://www.openssl.org/news/secadv_20140806.txt" rel="nofollow noopener">OpenSSL and LibreSSL updates</a></h3>

<ul>
<li>OpenSSL pushed out a few new versions, fixing multiple vulnerabilities (nine to be precise!)</li>
<li>Security concerns include leaking memory, possible denial of service, crashing clients, memory exhaustion, TLS downgrades and more</li>
<li><a href="http://marc.info/?l=openbsd-tech&amp;m=140752295222929&amp;w=2" rel="nofollow noopener">LibreSSL released a new version</a> to address most of the vulnerabilities, but wasn't affected by some of them</li>
<li>Whichever version of whatever SSL you use, make sure it's patched for these issues</li>
<li>DragonFly and OpenBSD are patched as of the time of this recording but, even after a week, NetBSD and FreeBSD are not (outside of -CURRENT)
***</li>
</ul>

<h2>Interview - Robert Watson - <a href="mailto:rwatson@freebsd.org" rel="nofollow noopener">rwatson@freebsd.org</a></h2>

<p>FreeBSD architecture, security research techniques, exploit mitigation</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/openvpn" rel="nofollow noopener">Protecting traffic with a BSD-based VPN</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://lechindianer.de/blog/2014/08/06/freebsd-cgit/" rel="nofollow noopener">A FreeBSD-based CGit server</a></h3>

<ul>
<li>If you use git (like a certain host of this show) then you've probably considered setting up your own server</li>
<li>This article takes you through the process of setting up a jailed git server, complete with a fancy web frontend</li>
<li>It even shows you how to set up multiple repos with key-based user separation and other cool things</li>
<li>The author of the post is also a listener of the show, thanks for sending it in!
***</li>
</ul>

<h3><a href="http://www.smallbusinesscomputing.com/biztools/6-data-backup-devices-for-small-businesses.html" rel="nofollow noopener">Backup devices for small businesses</a></h3>

<ul>
<li>In this article, different methods of data storage and backup are compared</li>
<li>After weighing the various options, the author comes to an obvious conclusion: FreeNAS is the answer</li>
<li>He praises FreeNAS and the FreeNAS Mini for their tight integration, rock solid FreeBSD base and the great ZFS featureset that it offers</li>
<li>It also goes over some of the hardware specifics in the FreeNAS Mini
***</li>
</ul>

<h3><a href="http://blog.bronevichok.ru/2014/08/06/testing-of-xorg.html" rel="nofollow noopener">A new Xenocara interview</a></h3>

<ul>
<li>As a follow up to last week's OpenSMTPD interview, this Russian blog interviews Matthieu Herrb about Xenocara</li>
<li>If you're not familiar with Xenocara, it's OpenBSD's version of Xorg with some custom patches</li>
<li>In this interview, he discusses how large and complex the upstream X11 development is, how different components are worked on by different people, how they test code (including a new framework) and security auditing</li>
<li>Matthieu is both a developer of upstream Xorg and an OpenBSD developer, so it's natural for him to do a lot of the maintainership work there
***</li>
</ul>

<h3><a href="https://not.burntout.org/blog/high_performance_samba_server_on_freebsd/" rel="nofollow noopener">Building a high performance FreeBSD samba server</a></h3>

<ul>
<li>If you've got to PXE boot several hundred Windows boxes to upgrade from XP to 7, what's the best solution?</li>
<li>FreeBSD, ZFS and Samba obviously!</li>
<li>The master image and related files clock in at over 20GB, and will be accessed at the same time by <em>all</em> of those clients</li>
<li>This article documents that process, highlighting some specific configuration tweaks to maximize performance (including NIC bonding)</li>
<li>It doesn't even require the newest or best hardware with the right changes, pretty cool
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/2ctlt4/switched_from_arch_linux_to_openbsd_reference/" rel="nofollow noopener">An interesting Reddit thread</a> (<a href="http://www.reddit.com/r/BSD/comments/2dcig9/thinking_about_coming_to_bsd_from_arch" rel="nofollow noopener">or two</a>)</li>
<li><a href="http://slexy.org/view/s21t7L5bqO" rel="nofollow noopener">PB writes in</a></li>
<li><a href="http://slexy.org/view/s20MFywDqZ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s2Td6nq11J" rel="nofollow noopener">Steve writes in</a></li>
<li><a href="http://slexy.org/view/s215MlpJYV" rel="nofollow noopener">Lachlan writes in</a></li>
<li><a href="http://slexy.org/view/s2N4JKkoKt" rel="nofollow noopener">Justin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
