<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Mon, 15 Jun 2026 08:27:55 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Openntpd”</title>
    <link>https://www.bsdnow.tv/tags/openntpd</link>
    <pubDate>Wed, 20 May 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>90: ZFS Armistice</title>
  <link>https://www.bsdnow.tv/90</link>
  <guid isPermaLink="false">5faad566-284e-4d62-b377-5144cf232cdb</guid>
  <pubDate>Wed, 20 May 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/5faad566-284e-4d62-b377-5144cf232cdb.mp3" length="52647700" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be chatting with Jed Reynolds about ZFS. He's been using it extensively on a certain other OS, and we can both learn a bit about the other side's implementation. Answers to your questions and all this week's news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:13:07</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be chatting with Jed Reynolds about ZFS. He's been using it extensively on a certain other OS, and we can both learn a bit about the other side's implementation. Answers to your questions and all this week's news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.conviso.com.br/2015/05/playing-with-sandbox-analysis-of_13.html" rel="nofollow noopener"&gt;Playing with sandboxing&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Sandboxing and privilege separation are popular topics these days - they're the goal of the new "shill" scripting language, they're used heavily throughout OpenBSD, and they're gaining traction with the capsicum framework&lt;/li&gt;
&lt;li&gt;This blog post explores capsicum in FreeBSD, some of its history and where it's used in the base system&lt;/li&gt;
&lt;li&gt;They also include some code samples so you can verify that capsicum is actually denying the program access to certain system calls&lt;/li&gt;
&lt;li&gt;Check our &lt;a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" rel="nofollow noopener"&gt;interview about capsicum&lt;/a&gt; from a while back if you haven't seen it already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=143195693612629&amp;amp;w=4" rel="nofollow noopener"&gt;OpenNTPD on by default&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD has enabled &lt;a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener"&gt;ntpd&lt;/a&gt; by default in the installer, rather than prompting the user if they want to turn it on&lt;/li&gt;
&lt;li&gt;In nearly every case, you're going to want to have your clock synced via NTP&lt;/li&gt;
&lt;li&gt;With the HTTPS constraints feature also enabled by default, this should keep the time checked and accurate, even against spoofing attacks&lt;/li&gt;
&lt;li&gt;Lots of problems can be traced back to the time on one system or another being wrong, so this will also eliminate some of those cases&lt;/li&gt;
&lt;li&gt;For those who might be &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/etc/ntpd.conf" rel="nofollow noopener"&gt;curious&lt;/a&gt;, they're using the "&lt;a href="http://www.pool.ntp.org/en/" rel="nofollow noopener"&gt;pool.ntp.org&lt;/a&gt;" cluster of addresses and google for HTTPS constraints (but these can be &lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;easily changed&lt;/a&gt;)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.banym.de/freebsd/review-first-freebsd-workshop-in-landshut-on-15-may-2015" rel="nofollow noopener"&gt;FreeBSD workshop in Landshut&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned a BSD installfest happening in Germany a few weeks back, and the organizer wrote in with a review of the event&lt;/li&gt;
&lt;li&gt;The installfest instead became a "FreeBSD workshop" session, introducing curious new users to some of the flagship features of the OS&lt;/li&gt;
&lt;li&gt;They covered when to use UFS or ZFS, firewall options, the release/stable/current branches and finally how to automate installations with Ansible&lt;/li&gt;
&lt;li&gt;If you're in south Germany and want to give similar introduction talks or Q&amp;amp;A sessions about the other BSDs, get in touch&lt;/li&gt;
&lt;li&gt;We'll hear more from him about how it went in the feedback section today
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207690.html" rel="nofollow noopener"&gt;Swap encryption in DragonFly&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Doing &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;full disk encryption&lt;/a&gt; is very important, but something that people sometimes overlook is encrypting their swap&lt;/li&gt;
&lt;li&gt;This can actually be &lt;em&gt;more&lt;/em&gt; important than the contents of your disks, especially if an unencrypted password or key hits your swap (as it can be recovered quite easily)&lt;/li&gt;
&lt;li&gt;DragonFlyBSD has added a new experimental option to automatically encrypt your swap partition in fstab&lt;/li&gt;
&lt;li&gt;There was &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207691.html" rel="nofollow noopener"&gt;another way&lt;/a&gt; to do it previously, but this is a lot easier&lt;/li&gt;
&lt;li&gt;You can achieve similar results in FreeBSD by adding ".eli" to the end of the swap device in fstab, there are &lt;a href="https://www.netbsd.org/docs/misc/#cgd-swap" rel="nofollow noopener"&gt;a few steps&lt;/a&gt; to do it in NetBSD and swap in OpenBSD is encrypted by default&lt;/li&gt;
&lt;li&gt;A one-time key will be created and then destroyed in each case, making recovery of the plaintext nearly impossible
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jed Reynolds - &lt;a href="mailto:jed@bitratchet.com" rel="nofollow noopener"&gt;jed@bitratchet.com&lt;/a&gt; / &lt;a href="https://twitter.com/jed_reynolds" rel="nofollow noopener"&gt;@jed_reynolds&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Comparing ZFS on Linux and FreeBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.cambus.net/rding-temper-gold-usb-thermometer-on-openbsd/" rel="nofollow noopener"&gt;USB thermometer on OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;So maybe you've got BSD on your server or router, maybe NetBSD on a toaster, but have you ever used a thermometer with one?&lt;/li&gt;
&lt;li&gt;This blog post introduces the RDing TEMPer Gold USB thermometer, a small device that can tell the room temperature, and how to get it working on OpenBSD&lt;/li&gt;
&lt;li&gt;Wouldn't you know it, OpenBSD has a native "&lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/ugold.4" rel="nofollow noopener"&gt;ugold&lt;/a&gt;" driver to support it with the sensors framework&lt;/li&gt;
&lt;li&gt;How useful such a device would be is another story though
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://sourceforge.net/projects/nas4free/files/NAS4Free-ARM/10.1.0.2.1511/" rel="nofollow noopener"&gt;NAS4Free now on ARM&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We talk a lot about hardware for network-attached storage devices on the show, but ARM doesn't come up a lot&lt;/li&gt;
&lt;li&gt;That might be changing soon, as NAS4Free has just released some ARM builds&lt;/li&gt;
&lt;li&gt;These new (somewhat experimental) images are based on FreeBSD 11-CURRENT&lt;/li&gt;
&lt;li&gt;Included in the announcement is a list of fully-supported and partially-supported hardware that they've tested it with&lt;/li&gt;
&lt;li&gt;If anyone has experience with running a NAS on slightly exotic hardware, write in to us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://pkgsrc.pub/pkgsrcCon/2015/" rel="nofollow noopener"&gt;pkgsrcCon 2015 CFP and info&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's pkgsrcCon will be in Berlin, Germany &lt;a href="https://mail-index.netbsd.org/pkgsrc-users/2015/05/16/msg021560.html" rel="nofollow noopener"&gt;on July 4th and 5th&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;They're looking for talk proposals and ideas for things you'd like to see&lt;/li&gt;
&lt;li&gt;If you or your company uses pkgsrc, or if you're just interested in NetBSD in general, it would be a good event to check out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsdtalk.blogspot.com/2015/05/bsdtalk253-george-neville-neil.html" rel="nofollow noopener"&gt;BSDTalk episode 253&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;BSDTalk has released another new episode&lt;/li&gt;
&lt;li&gt;In it, he interviews George Neville-Neil about the 2nd edition of "The Design and Implementation of the FreeBSD Operating System"&lt;/li&gt;
&lt;li&gt;They discuss what's new since the last edition, who the book's target audience is and a lot more&lt;/li&gt;
&lt;li&gt;We're up to 90 episodes now, slowly catching up to Will...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2SWlyuOeb" rel="nofollow noopener"&gt;Dominik writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216z44lDU" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2djtX0dSE" rel="nofollow noopener"&gt;Corvin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21XM4hPRh" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, zfs, zpool, openzfs, zfsonlinux, nas4free, capsicum, systrace, arm, rfc7539, bsdrp, openntpd, landshut, pkgsrc, pkgsrccon</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be chatting with Jed Reynolds about ZFS. He's been using it extensively on a certain other OS, and we can both learn a bit about the other side's implementation. Answers to your questions and all this week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blog.conviso.com.br/2015/05/playing-with-sandbox-analysis-of_13.html" rel="nofollow noopener">Playing with sandboxing</a></h3>

<ul>
<li>Sandboxing and privilege separation are popular topics these days - they're the goal of the new "shill" scripting language, they're used heavily throughout OpenBSD, and they're gaining traction with the capsicum framework</li>
<li>This blog post explores capsicum in FreeBSD, some of its history and where it's used in the base system</li>
<li>They also include some code samples so you can verify that capsicum is actually denying the program access to certain system calls</li>
<li>Check our <a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" rel="nofollow noopener">interview about capsicum</a> from a while back if you haven't seen it already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143195693612629&amp;w=4" rel="nofollow noopener">OpenNTPD on by default</a></h3>

<ul>
<li>OpenBSD has enabled <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">ntpd</a> by default in the installer, rather than prompting the user if they want to turn it on</li>
<li>In nearly every case, you're going to want to have your clock synced via NTP</li>
<li>With the HTTPS constraints feature also enabled by default, this should keep the time checked and accurate, even against spoofing attacks</li>
<li>Lots of problems can be traced back to the time on one system or another being wrong, so this will also eliminate some of those cases</li>
<li>For those who might be <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/etc/ntpd.conf" rel="nofollow noopener">curious</a>, they're using the "<a href="http://www.pool.ntp.org/en/" rel="nofollow noopener">pool.ntp.org</a>" cluster of addresses and google for HTTPS constraints (but these can be <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">easily changed</a>)
***</li>
</ul>

<h3><a href="https://www.banym.de/freebsd/review-first-freebsd-workshop-in-landshut-on-15-may-2015" rel="nofollow noopener">FreeBSD workshop in Landshut</a></h3>

<ul>
<li>We mentioned a BSD installfest happening in Germany a few weeks back, and the organizer wrote in with a review of the event</li>
<li>The installfest instead became a "FreeBSD workshop" session, introducing curious new users to some of the flagship features of the OS</li>
<li>They covered when to use UFS or ZFS, firewall options, the release/stable/current branches and finally how to automate installations with Ansible</li>
<li>If you're in south Germany and want to give similar introduction talks or Q&amp;A sessions about the other BSDs, get in touch</li>
<li>We'll hear more from him about how it went in the feedback section today
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207690.html" rel="nofollow noopener">Swap encryption in DragonFly</a></h3>

<ul>
<li>Doing <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">full disk encryption</a> is very important, but something that people sometimes overlook is encrypting their swap</li>
<li>This can actually be <em>more</em> important than the contents of your disks, especially if an unencrypted password or key hits your swap (as it can be recovered quite easily)</li>
<li>DragonFlyBSD has added a new experimental option to automatically encrypt your swap partition in fstab</li>
<li>There was <a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207691.html" rel="nofollow noopener">another way</a> to do it previously, but this is a lot easier</li>
<li>You can achieve similar results in FreeBSD by adding ".eli" to the end of the swap device in fstab, there are <a href="https://www.netbsd.org/docs/misc/#cgd-swap" rel="nofollow noopener">a few steps</a> to do it in NetBSD and swap in OpenBSD is encrypted by default</li>
<li>A one-time key will be created and then destroyed in each case, making recovery of the plaintext nearly impossible
***</li>
</ul>

<h2>Interview - Jed Reynolds - <a href="mailto:jed@bitratchet.com" rel="nofollow noopener">jed@bitratchet.com</a> / <a href="https://twitter.com/jed_reynolds" rel="nofollow noopener">@jed_reynolds</a></h2>

<p>Comparing ZFS on Linux and FreeBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.cambus.net/rding-temper-gold-usb-thermometer-on-openbsd/" rel="nofollow noopener">USB thermometer on OpenBSD</a></h3>

<ul>
<li>So maybe you've got BSD on your server or router, maybe NetBSD on a toaster, but have you ever used a thermometer with one?</li>
<li>This blog post introduces the RDing TEMPer Gold USB thermometer, a small device that can tell the room temperature, and how to get it working on OpenBSD</li>
<li>Wouldn't you know it, OpenBSD has a native "<a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/ugold.4" rel="nofollow noopener">ugold</a>" driver to support it with the sensors framework</li>
<li>How useful such a device would be is another story though
***</li>
</ul>

<h3><a href="http://sourceforge.net/projects/nas4free/files/NAS4Free-ARM/10.1.0.2.1511/" rel="nofollow noopener">NAS4Free now on ARM</a></h3>

<ul>
<li>We talk a lot about hardware for network-attached storage devices on the show, but ARM doesn't come up a lot</li>
<li>That might be changing soon, as NAS4Free has just released some ARM builds</li>
<li>These new (somewhat experimental) images are based on FreeBSD 11-CURRENT</li>
<li>Included in the announcement is a list of fully-supported and partially-supported hardware that they've tested it with</li>
<li>If anyone has experience with running a NAS on slightly exotic hardware, write in to us
***</li>
</ul>

<h3><a href="http://pkgsrc.pub/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon 2015 CFP and info</a></h3>

<ul>
<li>This year's pkgsrcCon will be in Berlin, Germany <a href="https://mail-index.netbsd.org/pkgsrc-users/2015/05/16/msg021560.html" rel="nofollow noopener">on July 4th and 5th</a></li>
<li>They're looking for talk proposals and ideas for things you'd like to see</li>
<li>If you or your company uses pkgsrc, or if you're just interested in NetBSD in general, it would be a good event to check out
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2015/05/bsdtalk253-george-neville-neil.html" rel="nofollow noopener">BSDTalk episode 253</a></h3>

<ul>
<li>BSDTalk has released another new episode</li>
<li>In it, he interviews George Neville-Neil about the 2nd edition of "The Design and Implementation of the FreeBSD Operating System"</li>
<li>They discuss what's new since the last edition, who the book's target audience is and a lot more</li>
<li>We're up to 90 episodes now, slowly catching up to Will...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2SWlyuOeb" rel="nofollow noopener">Dominik writes in</a></li>
<li><a href="http://slexy.org/view/s216z44lDU" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2djtX0dSE" rel="nofollow noopener">Corvin writes in</a></li>
<li><a href="http://slexy.org/view/s21XM4hPRh" rel="nofollow noopener">James writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be chatting with Jed Reynolds about ZFS. He's been using it extensively on a certain other OS, and we can both learn a bit about the other side's implementation. Answers to your questions and all this week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://blog.conviso.com.br/2015/05/playing-with-sandbox-analysis-of_13.html" rel="nofollow noopener">Playing with sandboxing</a></h3>

<ul>
<li>Sandboxing and privilege separation are popular topics these days - they're the goal of the new "shill" scripting language, they're used heavily throughout OpenBSD, and they're gaining traction with the capsicum framework</li>
<li>This blog post explores capsicum in FreeBSD, some of its history and where it's used in the base system</li>
<li>They also include some code samples so you can verify that capsicum is actually denying the program access to certain system calls</li>
<li>Check our <a href="http://www.bsdnow.tv/episodes/2014_05_28-the_friendly_sandbox" rel="nofollow noopener">interview about capsicum</a> from a while back if you haven't seen it already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143195693612629&amp;w=4" rel="nofollow noopener">OpenNTPD on by default</a></h3>

<ul>
<li>OpenBSD has enabled <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">ntpd</a> by default in the installer, rather than prompting the user if they want to turn it on</li>
<li>In nearly every case, you're going to want to have your clock synced via NTP</li>
<li>With the HTTPS constraints feature also enabled by default, this should keep the time checked and accurate, even against spoofing attacks</li>
<li>Lots of problems can be traced back to the time on one system or another being wrong, so this will also eliminate some of those cases</li>
<li>For those who might be <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/etc/ntpd.conf" rel="nofollow noopener">curious</a>, they're using the "<a href="http://www.pool.ntp.org/en/" rel="nofollow noopener">pool.ntp.org</a>" cluster of addresses and google for HTTPS constraints (but these can be <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">easily changed</a>)
***</li>
</ul>

<h3><a href="https://www.banym.de/freebsd/review-first-freebsd-workshop-in-landshut-on-15-may-2015" rel="nofollow noopener">FreeBSD workshop in Landshut</a></h3>

<ul>
<li>We mentioned a BSD installfest happening in Germany a few weeks back, and the organizer wrote in with a review of the event</li>
<li>The installfest instead became a "FreeBSD workshop" session, introducing curious new users to some of the flagship features of the OS</li>
<li>They covered when to use UFS or ZFS, firewall options, the release/stable/current branches and finally how to automate installations with Ansible</li>
<li>If you're in south Germany and want to give similar introduction talks or Q&amp;A sessions about the other BSDs, get in touch</li>
<li>We'll hear more from him about how it went in the feedback section today
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207690.html" rel="nofollow noopener">Swap encryption in DragonFly</a></h3>

<ul>
<li>Doing <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">full disk encryption</a> is very important, but something that people sometimes overlook is encrypting their swap</li>
<li>This can actually be <em>more</em> important than the contents of your disks, especially if an unencrypted password or key hits your swap (as it can be recovered quite easily)</li>
<li>DragonFlyBSD has added a new experimental option to automatically encrypt your swap partition in fstab</li>
<li>There was <a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207691.html" rel="nofollow noopener">another way</a> to do it previously, but this is a lot easier</li>
<li>You can achieve similar results in FreeBSD by adding ".eli" to the end of the swap device in fstab, there are <a href="https://www.netbsd.org/docs/misc/#cgd-swap" rel="nofollow noopener">a few steps</a> to do it in NetBSD and swap in OpenBSD is encrypted by default</li>
<li>A one-time key will be created and then destroyed in each case, making recovery of the plaintext nearly impossible
***</li>
</ul>

<h2>Interview - Jed Reynolds - <a href="mailto:jed@bitratchet.com" rel="nofollow noopener">jed@bitratchet.com</a> / <a href="https://twitter.com/jed_reynolds" rel="nofollow noopener">@jed_reynolds</a></h2>

<p>Comparing ZFS on Linux and FreeBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.cambus.net/rding-temper-gold-usb-thermometer-on-openbsd/" rel="nofollow noopener">USB thermometer on OpenBSD</a></h3>

<ul>
<li>So maybe you've got BSD on your server or router, maybe NetBSD on a toaster, but have you ever used a thermometer with one?</li>
<li>This blog post introduces the RDing TEMPer Gold USB thermometer, a small device that can tell the room temperature, and how to get it working on OpenBSD</li>
<li>Wouldn't you know it, OpenBSD has a native "<a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/ugold.4" rel="nofollow noopener">ugold</a>" driver to support it with the sensors framework</li>
<li>How useful such a device would be is another story though
***</li>
</ul>

<h3><a href="http://sourceforge.net/projects/nas4free/files/NAS4Free-ARM/10.1.0.2.1511/" rel="nofollow noopener">NAS4Free now on ARM</a></h3>

<ul>
<li>We talk a lot about hardware for network-attached storage devices on the show, but ARM doesn't come up a lot</li>
<li>That might be changing soon, as NAS4Free has just released some ARM builds</li>
<li>These new (somewhat experimental) images are based on FreeBSD 11-CURRENT</li>
<li>Included in the announcement is a list of fully-supported and partially-supported hardware that they've tested it with</li>
<li>If anyone has experience with running a NAS on slightly exotic hardware, write in to us
***</li>
</ul>

<h3><a href="http://pkgsrc.pub/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon 2015 CFP and info</a></h3>

<ul>
<li>This year's pkgsrcCon will be in Berlin, Germany <a href="https://mail-index.netbsd.org/pkgsrc-users/2015/05/16/msg021560.html" rel="nofollow noopener">on July 4th and 5th</a></li>
<li>They're looking for talk proposals and ideas for things you'd like to see</li>
<li>If you or your company uses pkgsrc, or if you're just interested in NetBSD in general, it would be a good event to check out
***</li>
</ul>

<h3><a href="http://bsdtalk.blogspot.com/2015/05/bsdtalk253-george-neville-neil.html" rel="nofollow noopener">BSDTalk episode 253</a></h3>

<ul>
<li>BSDTalk has released another new episode</li>
<li>In it, he interviews George Neville-Neil about the 2nd edition of "The Design and Implementation of the FreeBSD Operating System"</li>
<li>They discuss what's new since the last edition, who the book's target audience is and a lot more</li>
<li>We're up to 90 episodes now, slowly catching up to Will...
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2SWlyuOeb" rel="nofollow noopener">Dominik writes in</a></li>
<li><a href="http://slexy.org/view/s216z44lDU" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s2djtX0dSE" rel="nofollow noopener">Corvin writes in</a></li>
<li><a href="http://slexy.org/view/s21XM4hPRh" rel="nofollow noopener">James writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>88: Below the Clouds</title>
  <link>https://www.bsdnow.tv/88</link>
  <guid isPermaLink="false">26ef6d0e-ea2a-4032-88ee-121e1b2be033</guid>
  <pubDate>Wed, 06 May 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/26ef6d0e-ea2a-4032-88ee-121e1b2be033.mp3" length="67680724" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:34:00</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" rel="nofollow noopener"&gt;FreeBSD quarterly status report&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD team has posted a report of the activities that went on between January and March of this year&lt;/li&gt;
&lt;li&gt;As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)&lt;/li&gt;
&lt;li&gt;The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter&lt;/li&gt;
&lt;li&gt;The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward&lt;/li&gt;
&lt;li&gt;FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team&lt;/li&gt;
&lt;li&gt;Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code&lt;/li&gt;
&lt;li&gt;Lots of activity is happening in bhyve, some of which we've covered &lt;a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" rel="nofollow noopener"&gt;recently&lt;/a&gt;, and a number of improvements were made this quarter&lt;/li&gt;
&lt;li&gt;Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT&lt;/li&gt;
&lt;li&gt;Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being&lt;/li&gt;
&lt;li&gt;The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener"&gt;ASLR work&lt;/a&gt; is still being done by the HardenedBSD guys, and their next aim is position-independent executable&lt;/li&gt;
&lt;li&gt;The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more&lt;/li&gt;
&lt;li&gt;Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.openbsd.org/57.html" rel="nofollow noopener"&gt;OpenBSD 5.7 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD has formally released another new version, complete with the giant changelog we've come to expect&lt;/li&gt;
&lt;li&gt;In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs&lt;/li&gt;
&lt;li&gt;If you're using one of the Soekris boards, there's even &lt;a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" rel="nofollow noopener"&gt;a new driver&lt;/a&gt; to manipulate the GPIO and LEDs on them - this has some fun possibilities&lt;/li&gt;
&lt;li&gt;Some new security improvements include: &lt;a href="https://en.wikipedia.org/wiki/SipHash" rel="nofollow noopener"&gt;SipHash&lt;/a&gt; being sprinkled in some areas to protect hashing functions, big &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" rel="nofollow noopener"&gt;W&lt;sup&gt;X&lt;/sup&gt; improvements&lt;/a&gt; in the kernel space, &lt;a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" rel="nofollow noopener"&gt;static PIE&lt;/a&gt; on all architectures, deterministic "random" functions &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141807224826859&amp;amp;w=2" rel="nofollow noopener"&gt;being replaced&lt;/a&gt; with strong randomness, and support for remote logging over TLS&lt;/li&gt;
&lt;li&gt;The entire source tree has also been audited to use &lt;a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener"&gt;reallocarray&lt;/a&gt;, which unintentionally &lt;a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" rel="nofollow noopener"&gt;saved&lt;/a&gt; OpenBSD's libc from being vulnerable to &lt;a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" rel="nofollow noopener"&gt;earlier attacks&lt;/a&gt; affecting other BSDs' implementations&lt;/li&gt;
&lt;li&gt;Being that it's OpenBSD, a number of things have also been &lt;em&gt;removed&lt;/em&gt; from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)&lt;/li&gt;
&lt;li&gt;Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily&lt;/li&gt;
&lt;li&gt;BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon&lt;/li&gt;
&lt;li&gt;Speaking of httpd, it's gotten a number of &lt;a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" rel="nofollow noopener"&gt;new&lt;/a&gt; &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" rel="nofollow noopener"&gt;features&lt;/a&gt;, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so&lt;/li&gt;
&lt;li&gt;This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and &lt;a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" rel="nofollow noopener"&gt;mandoc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Check the &lt;a href="http://www.openbsd.org/errata57.html" rel="nofollow noopener"&gt;errata page&lt;/a&gt; for any post-release fixes, and the &lt;a href="http://www.openbsd.org/faq/upgrade57.html" rel="nofollow noopener"&gt;upgrade guide&lt;/a&gt; for specific instructions on updating from 5.6&lt;/li&gt;
&lt;li&gt;Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases&lt;/li&gt;
&lt;li&gt;There's a &lt;a href="http://www.openbsd.org/lyrics.html#57" rel="nofollow noopener"&gt;song and artwork&lt;/a&gt; to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week&lt;/li&gt;
&lt;li&gt;Consider &lt;a href="https://www.openbsdstore.com" rel="nofollow noopener"&gt;picking one up&lt;/a&gt; to support the project (and it's the only way to get puffy stickers)&lt;/li&gt;
&lt;li&gt;For those of you paying close attention, the &lt;a href="http://www.openbsd.org/images/puffy57.gif" rel="nofollow noopener"&gt;banner image&lt;/a&gt; for this release just might remind you of a &lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener"&gt;certain special episode&lt;/a&gt; of BSD Now...
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://torbsd.github.io/" rel="nofollow noopener"&gt;Tor-BSD diversity project&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)&lt;/li&gt;
&lt;li&gt;A new initiative has started to do just that, called the Tor-BSD diversity project&lt;/li&gt;
&lt;li&gt;"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."&lt;/li&gt;
&lt;li&gt;In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy&lt;/li&gt;
&lt;li&gt;There's an additional &lt;a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" rel="nofollow noopener"&gt;progress report&lt;/a&gt; for that part specifically, and it looks like most of the work is done now&lt;/li&gt;
&lt;li&gt;Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list &lt;/li&gt;
&lt;li&gt;If you've been considering running a node to help out, there's always &lt;a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener"&gt;our handy tutorial&lt;/a&gt; on getting set up
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" rel="nofollow noopener"&gt;PC-BSD 10.1.2-RC1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab&lt;/li&gt;
&lt;li&gt;This quarterly update includes a number of new features, improvements and even some additional utilities&lt;/li&gt;
&lt;li&gt;PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems&lt;/li&gt;
&lt;li&gt;A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use&lt;/li&gt;
&lt;li&gt;Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network&lt;/li&gt;
&lt;li&gt;IPFW is now the default firewall, offering improved VIMAGE capabilities&lt;/li&gt;
&lt;li&gt;The life preserver backup tool now allows for bare-metal restores via the install CD&lt;/li&gt;
&lt;li&gt;ISC's NTP daemon has been replaced with &lt;a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener"&gt;OpenNTPD&lt;/a&gt;, and OpenSSL has been replaced with &lt;a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" rel="nofollow noopener"&gt;LibreSSL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;It also includes the latest &lt;a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" rel="nofollow noopener"&gt;Lumina&lt;/a&gt; desktop, and there's another &lt;a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" rel="nofollow noopener"&gt;post dedicated to that&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Binary packages have also been updated to fresh versions from the ports tree&lt;/li&gt;
&lt;li&gt;More details, including upgrade instructions, can be found in the linked blog post
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ed Schouten - &lt;a href="mailto:ed@freebsd.org" rel="nofollow noopener"&gt;ed@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/edschouten" rel="nofollow noopener"&gt;@edschouten&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" rel="nofollow noopener"&gt;CloudABI&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" rel="nofollow noopener"&gt;Open Household Router Contraption&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This article introduces OpenHRC, the "Open Household Router Contraption"&lt;/li&gt;
&lt;li&gt;In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device&lt;/li&gt;
&lt;li&gt;It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup&lt;/li&gt;
&lt;li&gt;Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation&lt;/li&gt;
&lt;li&gt;All the code is open source &lt;a href="https://github.com/ioc32/openhrc" rel="nofollow noopener"&gt;and on Github&lt;/a&gt;, so you can read through what's actually being changed and put in place&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="https://www.youtube.com/watch?v=LZeKDM5jc90" rel="nofollow noopener"&gt;video guide&lt;/a&gt; to the entire process, if you're more of a visual person
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=365.0" rel="nofollow noopener"&gt;OPNsense 15.1.10 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version&lt;/li&gt;
&lt;li&gt;15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code&lt;/li&gt;
&lt;li&gt;Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree&lt;/li&gt;
&lt;li&gt;Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed&lt;/li&gt;
&lt;li&gt;NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well&lt;/li&gt;
&lt;li&gt;Version &lt;a href="https://twitter.com/opnsense/status/596009164746432512" rel="nofollow noopener"&gt;15.1.10.1&lt;/a&gt; was released shortly thereafter, including a hotfix for VLANs
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" rel="nofollow noopener"&gt;IBM Workpad Z50 and NetBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same&lt;/li&gt;
&lt;li&gt;Back in 1999, they released &lt;a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" rel="nofollow noopener"&gt;the Workpad Z50&lt;/a&gt; with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display&lt;/li&gt;
&lt;li&gt;You can probably tell where this is going... the article is about installing NetBSD it&lt;/li&gt;
&lt;li&gt;"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"&lt;/li&gt;
&lt;li&gt;The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern&lt;/li&gt;
&lt;li&gt;He's also got a &lt;a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" rel="nofollow noopener"&gt;couple&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" rel="nofollow noopener"&gt;videos&lt;/a&gt; of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" rel="nofollow noopener"&gt;FreeBSD from the trenches&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases&lt;/li&gt;
&lt;li&gt;In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI&lt;/li&gt;
&lt;li&gt;While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually&lt;/li&gt;
&lt;li&gt;Each command is explained, and he walks you through the process of doing &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;an encrypted installation&lt;/a&gt; on your root zpool
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" rel="nofollow noopener"&gt;Broadwell in DragonFly&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver&lt;/li&gt;
&lt;li&gt;Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too&lt;/li&gt;
&lt;li&gt;It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s216QQcHyX" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21hGSk3c0" rel="nofollow noopener"&gt;Hunter writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20JwPw9Je" rel="nofollow noopener"&gt;Hrishi writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2x1GYr7y6" rel="nofollow noopener"&gt;Clint writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2swXxr2PX" rel="nofollow noopener"&gt;Sergei writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" rel="nofollow noopener"&gt;How did you guess&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, 5.7, libressl, opensmtpd, openntpd, openssh, cloudabi, capsicum, 5.7, tor-bsd, tor, diversity, browser bundle, ipfw, openhrc, opnsense, router, workpad z50, gateway</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted a report of the activities that went on between January and March of this year</li>
<li>As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)</li>
<li>The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter</li>
<li>The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward</li>
<li>FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team</li>
<li>Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code</li>
<li>Lots of activity is happening in bhyve, some of which we've covered <a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" rel="nofollow noopener">recently</a>, and a number of improvements were made this quarter</li>
<li>Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT</li>
<li>Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being</li>
<li>The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener">ASLR work</a> is still being done by the HardenedBSD guys, and their next aim is position-independent executable</li>
<li>The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more</li>
<li>Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***</li>
</ul>

<h3><a href="http://www.openbsd.org/57.html" rel="nofollow noopener">OpenBSD 5.7 released</a></h3>

<ul>
<li>OpenBSD has formally released another new version, complete with the giant changelog we've come to expect</li>
<li>In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs</li>
<li>If you're using one of the Soekris boards, there's even <a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" rel="nofollow noopener">a new driver</a> to manipulate the GPIO and LEDs on them - this has some fun possibilities</li>
<li>Some new security improvements include: <a href="https://en.wikipedia.org/wiki/SipHash" rel="nofollow noopener">SipHash</a> being sprinkled in some areas to protect hashing functions, big <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">W<sup>X</sup> improvements</a> in the kernel space, <a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" rel="nofollow noopener">static PIE</a> on all architectures, deterministic "random" functions <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141807224826859&amp;w=2" rel="nofollow noopener">being replaced</a> with strong randomness, and support for remote logging over TLS</li>
<li>The entire source tree has also been audited to use <a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener">reallocarray</a>, which unintentionally <a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" rel="nofollow noopener">saved</a> OpenBSD's libc from being vulnerable to <a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" rel="nofollow noopener">earlier attacks</a> affecting other BSDs' implementations</li>
<li>Being that it's OpenBSD, a number of things have also been <em>removed</em> from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)</li>
<li>Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily</li>
<li>BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon</li>
<li>Speaking of httpd, it's gotten a number of <a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" rel="nofollow noopener">new</a> <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" rel="nofollow noopener">features</a>, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so</li>
<li>This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and <a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" rel="nofollow noopener">mandoc</a></li>
<li>Check the <a href="http://www.openbsd.org/errata57.html" rel="nofollow noopener">errata page</a> for any post-release fixes, and the <a href="http://www.openbsd.org/faq/upgrade57.html" rel="nofollow noopener">upgrade guide</a> for specific instructions on updating from 5.6</li>
<li>Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases</li>
<li>There's a <a href="http://www.openbsd.org/lyrics.html#57" rel="nofollow noopener">song and artwork</a> to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week</li>
<li>Consider <a href="https://www.openbsdstore.com" rel="nofollow noopener">picking one up</a> to support the project (and it's the only way to get puffy stickers)</li>
<li>For those of you paying close attention, the <a href="http://www.openbsd.org/images/puffy57.gif" rel="nofollow noopener">banner image</a> for this release just might remind you of a <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">certain special episode</a> of BSD Now...
***</li>
</ul>

<h3><a href="https://torbsd.github.io/" rel="nofollow noopener">Tor-BSD diversity project</a></h3>

<ul>
<li>We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)</li>
<li>A new initiative has started to do just that, called the Tor-BSD diversity project</li>
<li>"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."</li>
<li>In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy</li>
<li>There's an additional <a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" rel="nofollow noopener">progress report</a> for that part specifically, and it looks like most of the work is done now</li>
<li>Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list </li>
<li>If you've been considering running a node to help out, there's always <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">our handy tutorial</a> on getting set up
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" rel="nofollow noopener">PC-BSD 10.1.2-RC1 released</a></h3>

<ul>
<li>If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab</li>
<li>This quarterly update includes a number of new features, improvements and even some additional utilities</li>
<li>PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems</li>
<li>A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use</li>
<li>Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network</li>
<li>IPFW is now the default firewall, offering improved VIMAGE capabilities</li>
<li>The life preserver backup tool now allows for bare-metal restores via the install CD</li>
<li>ISC's NTP daemon has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">OpenNTPD</a>, and OpenSSL has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" rel="nofollow noopener">LibreSSL</a></li>
<li>It also includes the latest <a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" rel="nofollow noopener">Lumina</a> desktop, and there's another <a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" rel="nofollow noopener">post dedicated to that</a></li>
<li>Binary packages have also been updated to fresh versions from the ports tree</li>
<li>More details, including upgrade instructions, can be found in the linked blog post
***</li>
</ul>

<h2>Interview - Ed Schouten - <a href="mailto:ed@freebsd.org" rel="nofollow noopener">ed@freebsd.org</a> / <a href="https://twitter.com/edschouten" rel="nofollow noopener">@edschouten</a></h2>

<p><a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" rel="nofollow noopener">CloudABI</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" rel="nofollow noopener">Open Household Router Contraption</a></h3>

<ul>
<li>This article introduces OpenHRC, the "Open Household Router Contraption"</li>
<li>In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device</li>
<li>It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup</li>
<li>Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation</li>
<li>All the code is open source <a href="https://github.com/ioc32/openhrc" rel="nofollow noopener">and on Github</a>, so you can read through what's actually being changed and put in place</li>
<li>There's also a <a href="https://www.youtube.com/watch?v=LZeKDM5jc90" rel="nofollow noopener">video guide</a> to the entire process, if you're more of a visual person
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=365.0" rel="nofollow noopener">OPNsense 15.1.10 released</a></h3>

<ul>
<li>Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version</li>
<li>15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code</li>
<li>Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree</li>
<li>Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed</li>
<li>NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well</li>
<li>Version <a href="https://twitter.com/opnsense/status/596009164746432512" rel="nofollow noopener">15.1.10.1</a> was released shortly thereafter, including a hotfix for VLANs
***</li>
</ul>

<h3><a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" rel="nofollow noopener">IBM Workpad Z50 and NetBSD</a></h3>

<ul>
<li>Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same</li>
<li>Back in 1999, they released <a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" rel="nofollow noopener">the Workpad Z50</a> with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display</li>
<li>You can probably tell where this is going... the article is about installing NetBSD it</li>
<li>"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"</li>
<li>The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern</li>
<li>He's also got a <a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" rel="nofollow noopener">couple</a> <a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" rel="nofollow noopener">videos</a> of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" rel="nofollow noopener">FreeBSD from the trenches</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases</li>
<li>In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI</li>
<li>While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually</li>
<li>Each command is explained, and he walks you through the process of doing <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">an encrypted installation</a> on your root zpool
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" rel="nofollow noopener">Broadwell in DragonFly</a></h3>

<ul>
<li>DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver</li>
<li>Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too</li>
<li>It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216QQcHyX" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21hGSk3c0" rel="nofollow noopener">Hunter writes in</a></li>
<li><a href="http://slexy.org/view/s20JwPw9Je" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2x1GYr7y6" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s2swXxr2PX" rel="nofollow noopener">Sergei writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" rel="nofollow noopener">How did you guess</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Ed Schouten about CloudABI. It's a new application binary interface with a strong focus on isolation and restricted capabilities. As always, all this week's BSD news and answers to your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/news/status/report-2015-01-2015-03.html" rel="nofollow noopener">FreeBSD quarterly status report</a></h3>

<ul>
<li>The FreeBSD team has posted a report of the activities that went on between January and March of this year</li>
<li>As usual, it's broken down into separate reports from the various teams in the project (ports, kernel, virtualization, etc)</li>
<li>The ports team continuing battling the flood of PRs, closing quite a lot of them and boasting nearly 7,000 commits this quarter</li>
<li>The core team and cluster admins dealt with the accidental deletion of the Bugzilla database, and are making plans for an improved backup strategy within the project going forward</li>
<li>FreeBSD's future release support model was also finalized and published in February, which should be a big improvement for both users and the release team</li>
<li>Some topics are still being discussed internally, mainly MFCing ZFS ARC responsiveness patches to the 10 branch and deciding whether to maintain or abandon C89 support in the kernel code</li>
<li>Lots of activity is happening in bhyve, some of which we've covered <a href="http://www.bsdnow.tv/episodes/2015_04_29-on_the_list" rel="nofollow noopener">recently</a>, and a number of improvements were made this quarter</li>
<li>Clang, LLVM and LLDB have been updated to the 3.6.0 branch in -CURRENT</li>
<li>Work to get FreeBSD booting natively on the POWER8 CPU architecture is also still in progress, but it does boot in KVM for the time being</li>
<li>The project to replace forth in the bootloader with lua is in its final stages, and can be used on x86 already</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener">ASLR work</a> is still being done by the HardenedBSD guys, and their next aim is position-independent executable</li>
<li>The report also touches on multipath TCP support, the new automounter, opaque ifnet, pkgng updates, secureboot (which should be in 10.2-RELEASE), GNOME and KDE on FreeBSD, PCIe hotplugging, nested kernel support and more</li>
<li>Also of note: work is going on to make ARM a Tier 1 platform in the upcoming 11.0-RELEASE (and support for more ARM boards is still being added, including ARM64)
***</li>
</ul>

<h3><a href="http://www.openbsd.org/57.html" rel="nofollow noopener">OpenBSD 5.7 released</a></h3>

<ul>
<li>OpenBSD has formally released another new version, complete with the giant changelog we've come to expect</li>
<li>In the hardware department, 5.7 features many driver improvements and fixes, as well as support for some new things: USB 3.0 controllers, newer Intel and Atheros wireless cards and some additional 10gbit NICs</li>
<li>If you're using one of the Soekris boards, there's even <a href="http://bodgitandscarper.co.uk/openbsd/further-soekris-net6501-improvements-for-openbsd/" rel="nofollow noopener">a new driver</a> to manipulate the GPIO and LEDs on them - this has some fun possibilities</li>
<li>Some new security improvements include: <a href="https://en.wikipedia.org/wiki/SipHash" rel="nofollow noopener">SipHash</a> being sprinkled in some areas to protect hashing functions, big <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">W<sup>X</sup> improvements</a> in the kernel space, <a href="http://www.bsdnow.tv/episodes/2015_04_15-pie_in_the_sky" rel="nofollow noopener">static PIE</a> on all architectures, deterministic "random" functions <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141807224826859&amp;w=2" rel="nofollow noopener">being replaced</a> with strong randomness, and support for remote logging over TLS</li>
<li>The entire source tree has also been audited to use <a href="http://lteo.net/blog/2014/10/28/reallocarray-in-openbsd-integer-overflow-detection-for-free/" rel="nofollow noopener">reallocarray</a>, which unintentionally <a href="https://splone.com/blog/2015/3/11/integer-overflow-prevention-in-c" rel="nofollow noopener">saved</a> OpenBSD's libc from being vulnerable to <a href="https://guidovranken.wordpress.com/2015/02/04/full-disclosure-heap-overflow-in-h-spencers-regex-library-on-32-bit-systems/" rel="nofollow noopener">earlier attacks</a> affecting other BSDs' implementations</li>
<li>Being that it's OpenBSD, a number of things have also been <em>removed</em> from the base system: procfs, sendmail, SSLv3 support and loadable kernel modules are all gone now (not to mention the continuing massacre of dead code in LibreSSL)</li>
<li>Some people seem to be surprised about the removal of loadable modules, but almost nothing utilized them in OpenBSD, so it was really just removing old code that no one used anymore - very different from FreeBSD or Linux in this regard, where kernel modules are used pretty heavily</li>
<li>BIND and nginx have been taken out, so you'll need to either use the versions in ports or switch to Unbound and the in-base HTTP daemon</li>
<li>Speaking of httpd, it's gotten a number of <a href="http://www.openbsd.org/papers/httpd-slides-asiabsdcon2015.pdf" rel="nofollow noopener">new</a> <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man5/httpd.conf.5" rel="nofollow noopener">features</a>, and has had time to grow and mature since its initial debut - if you've been considering trying it out, now would be a great time to do so</li>
<li>This release also includes the latest OpenSSH (with stronger fingerprint types and host key rotation), OpenNTPD (with the HTTPS constraints feature), OpenSMTPD, LibreSSL and <a href="http://www.bsdnow.tv/episodes/2014_11_12-a_mans_man" rel="nofollow noopener">mandoc</a></li>
<li>Check the <a href="http://www.openbsd.org/errata57.html" rel="nofollow noopener">errata page</a> for any post-release fixes, and the <a href="http://www.openbsd.org/faq/upgrade57.html" rel="nofollow noopener">upgrade guide</a> for specific instructions on updating from 5.6</li>
<li>Groundwork has also been laid for some major SMP scalability improvements - look forward to those in future releases</li>
<li>There's a <a href="http://www.openbsd.org/lyrics.html#57" rel="nofollow noopener">song and artwork</a> to go along with the release as always, and CDs should be arriving within a few days - we'll show some pictures next week</li>
<li>Consider <a href="https://www.openbsdstore.com" rel="nofollow noopener">picking one up</a> to support the project (and it's the only way to get puffy stickers)</li>
<li>For those of you paying close attention, the <a href="http://www.openbsd.org/images/puffy57.gif" rel="nofollow noopener">banner image</a> for this release just might remind you of a <a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">certain special episode</a> of BSD Now...
***</li>
</ul>

<h3><a href="https://torbsd.github.io/" rel="nofollow noopener">Tor-BSD diversity project</a></h3>

<ul>
<li>We've talked about Tor on the show a few times, and specifically about getting more of the network on BSD (Linux has an overwhelming majority right now)</li>
<li>A new initiative has started to do just that, called the Tor-BSD diversity project</li>
<li>"Monocultures in nature are dangerous, as vulnerabilities are held in common across a broad spectrum. Diversity means single vulnerabilities are less likely to harm the entire ecosystem. [...] A single kernel vulnerability in GNU/Linux that impacting Tor relays could be devastating. We want to see a stronger Tor network, and we believe one critical ingredient for that is operating system diversity."</li>
<li>In addition to encouraging people to put up more relays, they're also continuing work on porting the Tor Browser Bundle to BSD, so more desktop users can have easy access to online privacy</li>
<li>There's an additional <a href="http://trac.haqistan.net/blog/tor-browser-ports-progress" rel="nofollow noopener">progress report</a> for that part specifically, and it looks like most of the work is done now</li>
<li>Engaging the broader BSD community about Tor and fixing up the official documentation are also both on their todo list </li>
<li>If you've been considering running a node to help out, there's always <a href="http://www.bsdnow.tv/tutorials/tor" rel="nofollow noopener">our handy tutorial</a> on getting set up
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-now-available/" rel="nofollow noopener">PC-BSD 10.1.2-RC1 released</a></h3>

<ul>
<li>If you want a sneak peek at the upcoming PC-BSD 10.1.2, the first release candidate is now available to grab</li>
<li>This quarterly update includes a number of new features, improvements and even some additional utilities</li>
<li>PersonaCrypt is one of them - it's a new tool for easily migrating encrypted home directories between systems</li>
<li>A new "stealth mode" option allows for a one-time login, using a blank home directory that gets wiped after use</li>
<li>Similarly, a new "Tor mode" allows for easy tunneling of all your traffic through the Tor network</li>
<li>IPFW is now the default firewall, offering improved VIMAGE capabilities</li>
<li>The life preserver backup tool now allows for bare-metal restores via the install CD</li>
<li>ISC's NTP daemon has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_02_11-time_for_a_change" rel="nofollow noopener">OpenNTPD</a>, and OpenSSL has been replaced with <a href="http://www.bsdnow.tv/episodes/2015_03_25-ssl_in_the_wild" rel="nofollow noopener">LibreSSL</a></li>
<li>It also includes the latest <a href="http://www.bsdnow.tv/episodes/2014_09_10-luminary_environment" rel="nofollow noopener">Lumina</a> desktop, and there's another <a href="http://blog.pcbsd.org/2015/05/pc-bsd-10-1-2-rc1-lumina-desktop-0-8-4-released/" rel="nofollow noopener">post dedicated to that</a></li>
<li>Binary packages have also been updated to fresh versions from the ports tree</li>
<li>More details, including upgrade instructions, can be found in the linked blog post
***</li>
</ul>

<h2>Interview - Ed Schouten - <a href="mailto:ed@freebsd.org" rel="nofollow noopener">ed@freebsd.org</a> / <a href="https://twitter.com/edschouten" rel="nofollow noopener">@edschouten</a></h2>

<p><a href="https://www.bsdcan.org/2015/schedule/track/Security/524.en.html" rel="nofollow noopener">CloudABI</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://code.saghul.net/index.php/2015/05/01/announcing-the-open-household-router-contraption/" rel="nofollow noopener">Open Household Router Contraption</a></h3>

<ul>
<li>This article introduces OpenHRC, the "Open Household Router Contraption"</li>
<li>In short, it's a set of bootstrapping scripts to turn a vanilla OpenBSD install into a feature-rich gateway device</li>
<li>It also makes use of Ansible playbooks for configuration, allowing for a more "mass deployment" type of setup</li>
<li>Everything is configured via a simple text file, and you end up with a local NTP server, DHCP server, firewall (obviously) and local caching DNS resolver - it even does DNSSEC validation</li>
<li>All the code is open source <a href="https://github.com/ioc32/openhrc" rel="nofollow noopener">and on Github</a>, so you can read through what's actually being changed and put in place</li>
<li>There's also a <a href="https://www.youtube.com/watch?v=LZeKDM5jc90" rel="nofollow noopener">video guide</a> to the entire process, if you're more of a visual person
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=365.0" rel="nofollow noopener">OPNsense 15.1.10 released</a></h3>

<ul>
<li>Speaking of BSD routers, if you're looking for a "prebuilt and ready to go" option, OPNsense has just released a new version</li>
<li>15.1.10 drops some of the legacy patches they inherited from pfSense, aiming to stay closer to the mainline FreeBSD source code</li>
<li>Going along with this theme, they've redone how they do ports, and are now kept totally in sync with the regular ports tree</li>
<li>Their binary packages are now signed using the fingerprint-style method, various GUI menus have been rewritten and a number of other bugs were fixed</li>
<li>NanoBSD-based images are also available now, so you can try it out on hardware with constrained resources as well</li>
<li>Version <a href="https://twitter.com/opnsense/status/596009164746432512" rel="nofollow noopener">15.1.10.1</a> was released shortly thereafter, including a hotfix for VLANs
***</li>
</ul>

<h3><a href="https://www.ibm.com/developerworks/community/blogs/hpcgoulash/entry/ibm_workpad_z50_netbsd_an_interesting_combination1?lang=en" rel="nofollow noopener">IBM Workpad Z50 and NetBSD</a></h3>

<ul>
<li>Before the infamous netbook fad came and went, IBM had a handheld PDA device that looked pretty much the same</li>
<li>Back in 1999, they released <a href="http://www.hpcfactor.com/reviews/hardware/ibm/workpad-z50/" rel="nofollow noopener">the Workpad Z50</a> with Windows CE, sporting a 131MHz MIPS CPU, 16MB of RAM and a 640x480 display</li>
<li>You can probably tell where this is going... the article is about installing NetBSD it</li>
<li>"What prevents me from taking my pristine Workpad z50 to the local electronics recycling  facility is NetBSD. With a little effort it is possible to install recent versions of NetBSD on the Workpad z50 and even have XWindows running"</li>
<li>The author got pkgsrc up and running on it too, and cleverly used distcc to offload the compiling jobs to something a bit more modern</li>
<li>He's also got a <a href="https://www.youtube.com/watch?v=hSLVnSZKB9I" rel="nofollow noopener">couple</a> <a href="https://www.youtube.com/watch?v=mIA-NWEHLM4" rel="nofollow noopener">videos</a> of the bootup process and running Xorg (neither of which we'd call "speedy" by any stretch of the imagination)
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2015/04/from-trenches-tips-tricks-edition.html" rel="nofollow noopener">FreeBSD from the trenches</a></h3>

<ul>
<li>The FreeBSD foundation has a new blog post up in their "from the trenches" series, detailing FreeBSD in some real-world use cases</li>
<li>In this installment, Glen Barber talks about how he sets up all his laptops with ZFS and GELI</li>
<li>While the installer allows for an automatic ZFS layout, Glen notes that it's not a one-size-fits-all thing, and goes through doing everything manually</li>
<li>Each command is explained, and he walks you through the process of doing <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">an encrypted installation</a> on your root zpool
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-May/207671.html" rel="nofollow noopener">Broadwell in DragonFly</a></h3>

<ul>
<li>DragonFlyBSD has officially won the race to get an Intel Broadwell graphics driver</li>
<li>Their i915 driver has been brought up to speed with Linux 3.14's, adding not only Broadwell support, but many other bugfixes for other cards too</li>
<li>It's planned for commit to the main tree very soon, but you can test it out with a git branch for the time being
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s216QQcHyX" rel="nofollow noopener">Bostjan writes in</a></li>
<li><a href="http://slexy.org/view/s21hGSk3c0" rel="nofollow noopener">Hunter writes in</a></li>
<li><a href="http://slexy.org/view/s20JwPw9Je" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2x1GYr7y6" rel="nofollow noopener">Clint writes in</a></li>
<li><a href="http://slexy.org/view/s2swXxr2PX" rel="nofollow noopener">Sergei writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-advocacy/2015-May/004541.html" rel="nofollow noopener">How did you guess</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>76: Time for a Change</title>
  <link>https://www.bsdnow.tv/76</link>
  <guid isPermaLink="false">b872a625-f3d6-477b-b162-fd4248aef998</guid>
  <pubDate>Wed, 11 Feb 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b872a625-f3d6-477b-b162-fd4248aef998.mp3" length="64285204" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week, we'll be talking to Henning Brauer about OpenNTPD and its recently revived portable version. After that, we'll be discussing different ways to securely tunnel your traffic: specifically OpenVPN, IPSEC, SSH and Tor. All that and the latest news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:29:17</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week, we'll be talking to Henning Brauer about OpenNTPD and its recently revived portable version. After that, we'll be discussing different ways to securely tunnel your traffic: specifically OpenVPN, IPSEC, SSH and Tor. All that and the latest news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054295.html" rel="nofollow noopener"&gt;Strange timer bug in FreeBSD 11&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_09_24-beastly_infrastructure" rel="nofollow noopener"&gt;Peter Wemm&lt;/a&gt; wrote in to the FreeBSD -CURRENT mailing list with an interesting observation&lt;/li&gt;
&lt;li&gt;Running the latest development code in the infrastructure, the clock would stop keeping time after 24 days of uptime&lt;/li&gt;
&lt;li&gt;This meant things like cron and sleep would break, TCP/IP wouldn't time out or resend packets, a lot of things would break&lt;/li&gt;
&lt;li&gt;A workaround until it was fixed was to reboot every 24 days, but this is BSD we're talking about - uptime is our game&lt;/li&gt;
&lt;li&gt;An initial proposal was adding a CFLAG to the build options which makes makes signed arithmetic wrap&lt;/li&gt;
&lt;li&gt;Peter disagreed and &lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054320.html" rel="nofollow noopener"&gt;gave some background&lt;/a&gt;, offering a different patch to &lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067827.html" rel="nofollow noopener"&gt;fix&lt;/a&gt; the issue and &lt;a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067828.html" rel="nofollow noopener"&gt;detect it early&lt;/a&gt; if it happens again&lt;/li&gt;
&lt;li&gt;Ultimately, the problem was traced back to an issue with a recent clang import&lt;/li&gt;
&lt;li&gt;It only affected -CURRENT, not -RELEASE or -STABLE, but was definitely a bizarre bug to track down
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://technoquarter.blogspot.com/p/series.html" rel="nofollow noopener"&gt;An OpenBSD mail server&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There's been a recent influx of blog posts about building a BSD mail server for some reason&lt;/li&gt;
&lt;li&gt;In this fancy series of posts, the author sets up OpenSMTPD in its native OpenBSD home, whereas previous posts have been aimed at FreeBSD and Linux&lt;/li&gt;
&lt;li&gt;In addition to the usual steps, this one also covers DKIMproxy, ClamAV for scanning attachments, Dovecot for IMAP and also multiple choices of spam filtering: spamd or SpamAssassin&lt;/li&gt;
&lt;li&gt;It also shows you how to set up Roundcube for building a web interface, using the new in-base httpd&lt;/li&gt;
&lt;li&gt;That means this is more of a "complete solution" - right down to what the end users see&lt;/li&gt;
&lt;li&gt;The series is split up into categories so it's very easy to follow along step-by-step
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207421.html" rel="nofollow noopener"&gt;How DragonFlyBSD uses git&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;DragonFlyBSD, along with PCBSD and EdgeBSD, uses git as its version control system for the system source code&lt;/li&gt;
&lt;li&gt;In a &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207422.html" rel="nofollow noopener"&gt;series&lt;/a&gt; of &lt;a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207424.html" rel="nofollow noopener"&gt;posts&lt;/a&gt;, Matthew Dillon (the project lead) details their internal setup&lt;/li&gt;
&lt;li&gt;They're using vanilla git over ssh, with the developers' accounts set to git-only (no shell access)&lt;/li&gt;
&lt;li&gt;The maintainers of the server are the only ones with shell access available&lt;/li&gt;
&lt;li&gt;He also details how a cron job syncs from the master to a public box that anyone can check out code from&lt;/li&gt;
&lt;li&gt;It would be interesting to hear about how other BSD projects manage their master source repository
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.itwire.com/business-it-news/open-source/66900-fed-up-with-systemd-and-linux?-why-not-try-pc-bsd" rel="nofollow noopener"&gt;Why not try PCBSD?&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;ITwire, another more mainstream tech site, published a recent article about switching to PCBSD&lt;/li&gt;
&lt;li&gt;They interview a guy named Kris that we've never heard of before&lt;/li&gt;
&lt;li&gt;In the article, they touch on how easy it can potentially be for Linux users looking to switch over to the BSD side - lots of applications are exactly the same&lt;/li&gt;
&lt;li&gt;"With the growing adoption of systemd, dissatisfaction with Linux has reached proportions not seen in recent years, to the extent that people have started talking of switching to FreeBSD."&lt;/li&gt;
&lt;li&gt;If you have some friends who complain to you about systemd all the time, this might be a good article to show them
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Henning Brauer - &lt;a href="mailto:henning@openbsd.org" rel="nofollow noopener"&gt;henning@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/henningbrauer" rel="nofollow noopener"&gt;@henningbrauer&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://openntpd.org/" rel="nofollow noopener"&gt;OpenNTPD&lt;/a&gt; and its portable variant&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142356166731390&amp;amp;w=2" rel="nofollow noopener"&gt;Authenticated time in OpenNTPD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We recorded that interview with Henning just a few days ago, and it looks like part of it may be outdated &lt;em&gt;already&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;While at the hackathon, some developers came up with an &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142355043928397&amp;amp;w=2" rel="nofollow noopener"&gt;alternate way&lt;/a&gt; to get authenticated NTP responses&lt;/li&gt;
&lt;li&gt;You can now add an HTTPS URL to your ntpd.conf in addition to the time server pool&lt;/li&gt;
&lt;li&gt;OpenNTPD will query it (over TLS, with CA verification) and look at the date sent in the HTTPS header&lt;/li&gt;
&lt;li&gt;It's not intended to be a direct time source, just a constraint to keep things within reason&lt;/li&gt;
&lt;li&gt;If you receive regular NTP packets that are way off from the TLS packet, those will be discarded and the server(s) marked as invalid&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142363215730069&amp;amp;w=2" rel="nofollow noopener"&gt;Henning&lt;/a&gt; and &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142363400330522&amp;amp;w=2" rel="nofollow noopener"&gt;Theo&lt;/a&gt; also weigh in to give some of the backstory on the idea&lt;/li&gt;
&lt;li&gt;Lots more detail can be found in Reyk's email explaining the new feature (and it's optional of course)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/08/msg000678.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference 2015 Oita and Hamanako&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;It's been a while since we've featured one of these trip reports, but the Japanese NetBSD users group is still doing them&lt;/li&gt;
&lt;li&gt;This time the conferences were in Oita &lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/11/msg000679.html" rel="nofollow noopener"&gt;and Hamanako&lt;/a&gt;, Japan&lt;/li&gt;
&lt;li&gt;Machines running NetBSD included the CubieBoard2 Allwinner A20, Raspberry Pi and Banana Pi, Sharp NetWalker and a couple Zaurus devices&lt;/li&gt;
&lt;li&gt;As always, they took lots of pictures from the event of NetBSD on all these weird machines
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tobeannounced.org/2015/02/poudriere-in-a-jail/" rel="nofollow noopener"&gt;Poudriere in a jail&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A common question we get about our &lt;a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener"&gt;poudriere tutorial&lt;/a&gt; is "how do I run it in a jail?" - this blog post is about exactly that&lt;/li&gt;
&lt;li&gt;It takes you through the networking setup, zpool setup, nginx setup, making the jail and finally poking the right holes in the jail to allow poudriere to work its magic
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://easyos.net/articles/bsd/freebsd/bruteblock_protection_against_bruteforce_attacks_in_ssh" rel="nofollow noopener"&gt;Bruteblock, another way to stop bruteforce&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've mentioned a few different ways to stop ssh bruteforce attempts in the past: fail2ban, denyhosts, or even just with pf's built-in rate limiting&lt;/li&gt;
&lt;li&gt;Bruteblock is a similar tool, but it's not just for ssh logins - it can do a number of other services&lt;/li&gt;
&lt;li&gt;It can also work directly with IPFW, which is a plus if you're using that as your firewall&lt;/li&gt;
&lt;li&gt;Add a few lines to your syslog.conf and bruteblock will get executed automatically&lt;/li&gt;
&lt;li&gt;The rest of the article takes you through the different settings you can configure for blocking
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142325218626853&amp;amp;w=2" rel="nofollow noopener"&gt;New iwm(4) driver and cross-polination&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenBSD guys recently imported a new "iwm" driver for newer Intel 7260 wireless cards (commonly found in Thinkpads)&lt;/li&gt;
&lt;li&gt;NetBSD wasted no time in &lt;a href="https://mail-index.netbsd.org/source-changes/2015/02/07/msg062979.html" rel="nofollow noopener"&gt;porting it over&lt;/a&gt;, giving a bit of interesting backstory&lt;/li&gt;
&lt;li&gt;According to &lt;a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener"&gt;Antti Kantee&lt;/a&gt;, "it was created for OpenBSD by writing and porting a NetBSD driver which was developed in a rump kernel in Linux userspace"&lt;/li&gt;
&lt;li&gt;Both projects would appreciate further testing if you have the hardware and can provide useful bug reports&lt;/li&gt;
&lt;li&gt;Maybe FreeBSD and DragonFly will port it over too, or come up with something that's partially based on the code
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/02/pc-bsd-11-0-current-images-now-available/" rel="nofollow noopener"&gt;PCBSD current images&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The first PCBSD -CURRENT images should be available this weekend&lt;/li&gt;
&lt;li&gt;This image will be tagged 11.0-CURRENTFEB2015, with planned monthly updates&lt;/li&gt;
&lt;li&gt;For the more adventurous this will allow testing both FreeBSD and PCBSD bleeding edge
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2E4NbJwzs" rel="nofollow noopener"&gt;Antonio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2FkxcSYKy" rel="nofollow noopener"&gt;Richard writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s217EgA1JC" rel="nofollow noopener"&gt;Charlie writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21vlCbGDt" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00360.html" rel="nofollow noopener"&gt;A systematic effort&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00457.html" rel="nofollow noopener"&gt;GCC's lunch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://marc.info/?l=openbsd-cvs&amp;amp;m=142331891908776&amp;amp;w=2" rel="nofollow noopener"&gt;Hopes and dreams&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Discussion&lt;/h2&gt;

&lt;h3&gt;Comparison of ways to securely tunnel your traffic&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://openvpn.net/index.php/open-source.html" rel="nofollow noopener"&gt;OpenVPN&lt;/a&gt;, &lt;a href="http://www.openiked.org/" rel="nofollow noopener"&gt;OpenBSD IKED&lt;/a&gt;, &lt;a href="https://www.freebsd.org/doc/handbook/ipsec.html" rel="nofollow noopener"&gt;FreeBSD IPSEC&lt;/a&gt;, &lt;a href="http://www.openssh.com/" rel="nofollow noopener"&gt;OpenSSH&lt;/a&gt;, &lt;a href="https://www.torproject.org/" rel="nofollow noopener"&gt;Tor&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ntp, ntpd, ntimed, openntpd, time keeping, stratum, ipsec, openvpn, ssh, openiked, ike, tor, tunneling, bhws, afl-fuzz, opensmtpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week, we'll be talking to Henning Brauer about OpenNTPD and its recently revived portable version. After that, we'll be discussing different ways to securely tunnel your traffic: specifically OpenVPN, IPSEC, SSH and Tor. All that and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054295.html" rel="nofollow noopener">Strange timer bug in FreeBSD 11</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_24-beastly_infrastructure" rel="nofollow noopener">Peter Wemm</a> wrote in to the FreeBSD -CURRENT mailing list with an interesting observation</li>
<li>Running the latest development code in the infrastructure, the clock would stop keeping time after 24 days of uptime</li>
<li>This meant things like cron and sleep would break, TCP/IP wouldn't time out or resend packets, a lot of things would break</li>
<li>A workaround until it was fixed was to reboot every 24 days, but this is BSD we're talking about - uptime is our game</li>
<li>An initial proposal was adding a CFLAG to the build options which makes makes signed arithmetic wrap</li>
<li>Peter disagreed and <a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054320.html" rel="nofollow noopener">gave some background</a>, offering a different patch to <a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067827.html" rel="nofollow noopener">fix</a> the issue and <a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067828.html" rel="nofollow noopener">detect it early</a> if it happens again</li>
<li>Ultimately, the problem was traced back to an issue with a recent clang import</li>
<li>It only affected -CURRENT, not -RELEASE or -STABLE, but was definitely a bizarre bug to track down
***</li>
</ul>

<h3><a href="http://technoquarter.blogspot.com/p/series.html" rel="nofollow noopener">An OpenBSD mail server</a></h3>

<ul>
<li>There's been a recent influx of blog posts about building a BSD mail server for some reason</li>
<li>In this fancy series of posts, the author sets up OpenSMTPD in its native OpenBSD home, whereas previous posts have been aimed at FreeBSD and Linux</li>
<li>In addition to the usual steps, this one also covers DKIMproxy, ClamAV for scanning attachments, Dovecot for IMAP and also multiple choices of spam filtering: spamd or SpamAssassin</li>
<li>It also shows you how to set up Roundcube for building a web interface, using the new in-base httpd</li>
<li>That means this is more of a "complete solution" - right down to what the end users see</li>
<li>The series is split up into categories so it's very easy to follow along step-by-step
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207421.html" rel="nofollow noopener">How DragonFlyBSD uses git</a></h3>

<ul>
<li>DragonFlyBSD, along with PCBSD and EdgeBSD, uses git as its version control system for the system source code</li>
<li>In a <a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207422.html" rel="nofollow noopener">series</a> of <a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207424.html" rel="nofollow noopener">posts</a>, Matthew Dillon (the project lead) details their internal setup</li>
<li>They're using vanilla git over ssh, with the developers' accounts set to git-only (no shell access)</li>
<li>The maintainers of the server are the only ones with shell access available</li>
<li>He also details how a cron job syncs from the master to a public box that anyone can check out code from</li>
<li>It would be interesting to hear about how other BSD projects manage their master source repository
***</li>
</ul>

<h3><a href="http://www.itwire.com/business-it-news/open-source/66900-fed-up-with-systemd-and-linux?-why-not-try-pc-bsd" rel="nofollow noopener">Why not try PCBSD?</a></h3>

<ul>
<li>ITwire, another more mainstream tech site, published a recent article about switching to PCBSD</li>
<li>They interview a guy named Kris that we've never heard of before</li>
<li>In the article, they touch on how easy it can potentially be for Linux users looking to switch over to the BSD side - lots of applications are exactly the same</li>
<li>"With the growing adoption of systemd, dissatisfaction with Linux has reached proportions not seen in recent years, to the extent that people have started talking of switching to FreeBSD."</li>
<li>If you have some friends who complain to you about systemd all the time, this might be a good article to show them
***</li>
</ul>

<h2>Interview - Henning Brauer - <a href="mailto:henning@openbsd.org" rel="nofollow noopener">henning@openbsd.org</a> / <a href="https://twitter.com/henningbrauer" rel="nofollow noopener">@henningbrauer</a></h2>

<p><a href="http://openntpd.org/" rel="nofollow noopener">OpenNTPD</a> and its portable variant</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142356166731390&amp;w=2" rel="nofollow noopener">Authenticated time in OpenNTPD</a></h3>

<ul>
<li>We recorded that interview with Henning just a few days ago, and it looks like part of it may be outdated <em>already</em></li>
<li>While at the hackathon, some developers came up with an <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142355043928397&amp;w=2" rel="nofollow noopener">alternate way</a> to get authenticated NTP responses</li>
<li>You can now add an HTTPS URL to your ntpd.conf in addition to the time server pool</li>
<li>OpenNTPD will query it (over TLS, with CA verification) and look at the date sent in the HTTPS header</li>
<li>It's not intended to be a direct time source, just a constraint to keep things within reason</li>
<li>If you receive regular NTP packets that are way off from the TLS packet, those will be discarded and the server(s) marked as invalid</li>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142363215730069&amp;w=2" rel="nofollow noopener">Henning</a> and <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142363400330522&amp;w=2" rel="nofollow noopener">Theo</a> also weigh in to give some of the backstory on the idea</li>
<li>Lots more detail can be found in Reyk's email explaining the new feature (and it's optional of course)
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/08/msg000678.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Oita and Hamanako</a></h3>

<ul>
<li>It's been a while since we've featured one of these trip reports, but the Japanese NetBSD users group is still doing them</li>
<li>This time the conferences were in Oita <a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/11/msg000679.html" rel="nofollow noopener">and Hamanako</a>, Japan</li>
<li>Machines running NetBSD included the CubieBoard2 Allwinner A20, Raspberry Pi and Banana Pi, Sharp NetWalker and a couple Zaurus devices</li>
<li>As always, they took lots of pictures from the event of NetBSD on all these weird machines
***</li>
</ul>

<h3><a href="http://www.tobeannounced.org/2015/02/poudriere-in-a-jail/" rel="nofollow noopener">Poudriere in a jail</a></h3>

<ul>
<li>A common question we get about our <a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener">poudriere tutorial</a> is "how do I run it in a jail?" - this blog post is about exactly that</li>
<li>It takes you through the networking setup, zpool setup, nginx setup, making the jail and finally poking the right holes in the jail to allow poudriere to work its magic
***</li>
</ul>

<h3><a href="http://easyos.net/articles/bsd/freebsd/bruteblock_protection_against_bruteforce_attacks_in_ssh" rel="nofollow noopener">Bruteblock, another way to stop bruteforce</a></h3>

<ul>
<li>We've mentioned a few different ways to stop ssh bruteforce attempts in the past: fail2ban, denyhosts, or even just with pf's built-in rate limiting</li>
<li>Bruteblock is a similar tool, but it's not just for ssh logins - it can do a number of other services</li>
<li>It can also work directly with IPFW, which is a plus if you're using that as your firewall</li>
<li>Add a few lines to your syslog.conf and bruteblock will get executed automatically</li>
<li>The rest of the article takes you through the different settings you can configure for blocking
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142325218626853&amp;w=2" rel="nofollow noopener">New iwm(4) driver and cross-polination</a></h3>

<ul>
<li>The OpenBSD guys recently imported a new "iwm" driver for newer Intel 7260 wireless cards (commonly found in Thinkpads)</li>
<li>NetBSD wasted no time in <a href="https://mail-index.netbsd.org/source-changes/2015/02/07/msg062979.html" rel="nofollow noopener">porting it over</a>, giving a bit of interesting backstory</li>
<li>According to <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">Antti Kantee</a>, "it was created for OpenBSD by writing and porting a NetBSD driver which was developed in a rump kernel in Linux userspace"</li>
<li>Both projects would appreciate further testing if you have the hardware and can provide useful bug reports</li>
<li>Maybe FreeBSD and DragonFly will port it over too, or come up with something that's partially based on the code
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/02/pc-bsd-11-0-current-images-now-available/" rel="nofollow noopener">PCBSD current images</a></h3>

<ul>
<li>The first PCBSD -CURRENT images should be available this weekend</li>
<li>This image will be tagged 11.0-CURRENTFEB2015, with planned monthly updates</li>
<li>For the more adventurous this will allow testing both FreeBSD and PCBSD bleeding edge
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2E4NbJwzs" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2FkxcSYKy" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s217EgA1JC" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21vlCbGDt" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00360.html" rel="nofollow noopener">A systematic effort</a></li>
<li><a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00457.html" rel="nofollow noopener">GCC's lunch</a></li>
<li><a href="https://marc.info/?l=openbsd-cvs&amp;m=142331891908776&amp;w=2" rel="nofollow noopener">Hopes and dreams</a>
***</li>
</ul>

<h2>Discussion</h2>

<h3>Comparison of ways to securely tunnel your traffic</h3>

<ul>
<li><a href="https://openvpn.net/index.php/open-source.html" rel="nofollow noopener">OpenVPN</a>, <a href="http://www.openiked.org/" rel="nofollow noopener">OpenBSD IKED</a>, <a href="https://www.freebsd.org/doc/handbook/ipsec.html" rel="nofollow noopener">FreeBSD IPSEC</a>, <a href="http://www.openssh.com/" rel="nofollow noopener">OpenSSH</a>, <a href="https://www.torproject.org/" rel="nofollow noopener">Tor</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week, we'll be talking to Henning Brauer about OpenNTPD and its recently revived portable version. After that, we'll be discussing different ways to securely tunnel your traffic: specifically OpenVPN, IPSEC, SSH and Tor. All that and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054295.html" rel="nofollow noopener">Strange timer bug in FreeBSD 11</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_24-beastly_infrastructure" rel="nofollow noopener">Peter Wemm</a> wrote in to the FreeBSD -CURRENT mailing list with an interesting observation</li>
<li>Running the latest development code in the infrastructure, the clock would stop keeping time after 24 days of uptime</li>
<li>This meant things like cron and sleep would break, TCP/IP wouldn't time out or resend packets, a lot of things would break</li>
<li>A workaround until it was fixed was to reboot every 24 days, but this is BSD we're talking about - uptime is our game</li>
<li>An initial proposal was adding a CFLAG to the build options which makes makes signed arithmetic wrap</li>
<li>Peter disagreed and <a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-February/054320.html" rel="nofollow noopener">gave some background</a>, offering a different patch to <a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067827.html" rel="nofollow noopener">fix</a> the issue and <a href="https://lists.freebsd.org/pipermail/svn-src-head/2015-February/067828.html" rel="nofollow noopener">detect it early</a> if it happens again</li>
<li>Ultimately, the problem was traced back to an issue with a recent clang import</li>
<li>It only affected -CURRENT, not -RELEASE or -STABLE, but was definitely a bizarre bug to track down
***</li>
</ul>

<h3><a href="http://technoquarter.blogspot.com/p/series.html" rel="nofollow noopener">An OpenBSD mail server</a></h3>

<ul>
<li>There's been a recent influx of blog posts about building a BSD mail server for some reason</li>
<li>In this fancy series of posts, the author sets up OpenSMTPD in its native OpenBSD home, whereas previous posts have been aimed at FreeBSD and Linux</li>
<li>In addition to the usual steps, this one also covers DKIMproxy, ClamAV for scanning attachments, Dovecot for IMAP and also multiple choices of spam filtering: spamd or SpamAssassin</li>
<li>It also shows you how to set up Roundcube for building a web interface, using the new in-base httpd</li>
<li>That means this is more of a "complete solution" - right down to what the end users see</li>
<li>The series is split up into categories so it's very easy to follow along step-by-step
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207421.html" rel="nofollow noopener">How DragonFlyBSD uses git</a></h3>

<ul>
<li>DragonFlyBSD, along with PCBSD and EdgeBSD, uses git as its version control system for the system source code</li>
<li>In a <a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207422.html" rel="nofollow noopener">series</a> of <a href="http://lists.dragonflybsd.org/pipermail/users/2015-January/207424.html" rel="nofollow noopener">posts</a>, Matthew Dillon (the project lead) details their internal setup</li>
<li>They're using vanilla git over ssh, with the developers' accounts set to git-only (no shell access)</li>
<li>The maintainers of the server are the only ones with shell access available</li>
<li>He also details how a cron job syncs from the master to a public box that anyone can check out code from</li>
<li>It would be interesting to hear about how other BSD projects manage their master source repository
***</li>
</ul>

<h3><a href="http://www.itwire.com/business-it-news/open-source/66900-fed-up-with-systemd-and-linux?-why-not-try-pc-bsd" rel="nofollow noopener">Why not try PCBSD?</a></h3>

<ul>
<li>ITwire, another more mainstream tech site, published a recent article about switching to PCBSD</li>
<li>They interview a guy named Kris that we've never heard of before</li>
<li>In the article, they touch on how easy it can potentially be for Linux users looking to switch over to the BSD side - lots of applications are exactly the same</li>
<li>"With the growing adoption of systemd, dissatisfaction with Linux has reached proportions not seen in recent years, to the extent that people have started talking of switching to FreeBSD."</li>
<li>If you have some friends who complain to you about systemd all the time, this might be a good article to show them
***</li>
</ul>

<h2>Interview - Henning Brauer - <a href="mailto:henning@openbsd.org" rel="nofollow noopener">henning@openbsd.org</a> / <a href="https://twitter.com/henningbrauer" rel="nofollow noopener">@henningbrauer</a></h2>

<p><a href="http://openntpd.org/" rel="nofollow noopener">OpenNTPD</a> and its portable variant</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142356166731390&amp;w=2" rel="nofollow noopener">Authenticated time in OpenNTPD</a></h3>

<ul>
<li>We recorded that interview with Henning just a few days ago, and it looks like part of it may be outdated <em>already</em></li>
<li>While at the hackathon, some developers came up with an <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142355043928397&amp;w=2" rel="nofollow noopener">alternate way</a> to get authenticated NTP responses</li>
<li>You can now add an HTTPS URL to your ntpd.conf in addition to the time server pool</li>
<li>OpenNTPD will query it (over TLS, with CA verification) and look at the date sent in the HTTPS header</li>
<li>It's not intended to be a direct time source, just a constraint to keep things within reason</li>
<li>If you receive regular NTP packets that are way off from the TLS packet, those will be discarded and the server(s) marked as invalid</li>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142363215730069&amp;w=2" rel="nofollow noopener">Henning</a> and <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142363400330522&amp;w=2" rel="nofollow noopener">Theo</a> also weigh in to give some of the backstory on the idea</li>
<li>Lots more detail can be found in Reyk's email explaining the new feature (and it's optional of course)
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/08/msg000678.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Oita and Hamanako</a></h3>

<ul>
<li>It's been a while since we've featured one of these trip reports, but the Japanese NetBSD users group is still doing them</li>
<li>This time the conferences were in Oita <a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/02/11/msg000679.html" rel="nofollow noopener">and Hamanako</a>, Japan</li>
<li>Machines running NetBSD included the CubieBoard2 Allwinner A20, Raspberry Pi and Banana Pi, Sharp NetWalker and a couple Zaurus devices</li>
<li>As always, they took lots of pictures from the event of NetBSD on all these weird machines
***</li>
</ul>

<h3><a href="http://www.tobeannounced.org/2015/02/poudriere-in-a-jail/" rel="nofollow noopener">Poudriere in a jail</a></h3>

<ul>
<li>A common question we get about our <a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener">poudriere tutorial</a> is "how do I run it in a jail?" - this blog post is about exactly that</li>
<li>It takes you through the networking setup, zpool setup, nginx setup, making the jail and finally poking the right holes in the jail to allow poudriere to work its magic
***</li>
</ul>

<h3><a href="http://easyos.net/articles/bsd/freebsd/bruteblock_protection_against_bruteforce_attacks_in_ssh" rel="nofollow noopener">Bruteblock, another way to stop bruteforce</a></h3>

<ul>
<li>We've mentioned a few different ways to stop ssh bruteforce attempts in the past: fail2ban, denyhosts, or even just with pf's built-in rate limiting</li>
<li>Bruteblock is a similar tool, but it's not just for ssh logins - it can do a number of other services</li>
<li>It can also work directly with IPFW, which is a plus if you're using that as your firewall</li>
<li>Add a few lines to your syslog.conf and bruteblock will get executed automatically</li>
<li>The rest of the article takes you through the different settings you can configure for blocking
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142325218626853&amp;w=2" rel="nofollow noopener">New iwm(4) driver and cross-polination</a></h3>

<ul>
<li>The OpenBSD guys recently imported a new "iwm" driver for newer Intel 7260 wireless cards (commonly found in Thinkpads)</li>
<li>NetBSD wasted no time in <a href="https://mail-index.netbsd.org/source-changes/2015/02/07/msg062979.html" rel="nofollow noopener">porting it over</a>, giving a bit of interesting backstory</li>
<li>According to <a href="http://www.bsdnow.tv/episodes/2013_10_23-a_brief_intorduction" rel="nofollow noopener">Antti Kantee</a>, "it was created for OpenBSD by writing and porting a NetBSD driver which was developed in a rump kernel in Linux userspace"</li>
<li>Both projects would appreciate further testing if you have the hardware and can provide useful bug reports</li>
<li>Maybe FreeBSD and DragonFly will port it over too, or come up with something that's partially based on the code
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/02/pc-bsd-11-0-current-images-now-available/" rel="nofollow noopener">PCBSD current images</a></h3>

<ul>
<li>The first PCBSD -CURRENT images should be available this weekend</li>
<li>This image will be tagged 11.0-CURRENTFEB2015, with planned monthly updates</li>
<li>For the more adventurous this will allow testing both FreeBSD and PCBSD bleeding edge
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2E4NbJwzs" rel="nofollow noopener">Antonio writes in</a></li>
<li><a href="http://slexy.org/view/s2FkxcSYKy" rel="nofollow noopener">Richard writes in</a></li>
<li><a href="http://slexy.org/view/s217EgA1JC" rel="nofollow noopener">Charlie writes in</a></li>
<li><a href="http://slexy.org/view/s21vlCbGDt" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00360.html" rel="nofollow noopener">A systematic effort</a></li>
<li><a href="https://lists.gnu.org/archive/html/emacs-devel/2015-02/msg00457.html" rel="nofollow noopener">GCC's lunch</a></li>
<li><a href="https://marc.info/?l=openbsd-cvs&amp;m=142331891908776&amp;w=2" rel="nofollow noopener">Hopes and dreams</a>
***</li>
</ul>

<h2>Discussion</h2>

<h3>Comparison of ways to securely tunnel your traffic</h3>

<ul>
<li><a href="https://openvpn.net/index.php/open-source.html" rel="nofollow noopener">OpenVPN</a>, <a href="http://www.openiked.org/" rel="nofollow noopener">OpenBSD IKED</a>, <a href="https://www.freebsd.org/doc/handbook/ipsec.html" rel="nofollow noopener">FreeBSD IPSEC</a>, <a href="http://www.openssh.com/" rel="nofollow noopener">OpenSSH</a>, <a href="https://www.torproject.org/" rel="nofollow noopener">Tor</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>71: System Disaster</title>
  <link>https://www.bsdnow.tv/71</link>
  <guid isPermaLink="false">b9b0efcb-197e-4dfc-a239-5ae487a72e51</guid>
  <pubDate>Wed, 07 Jan 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/b9b0efcb-197e-4dfc-a239-5ae487a72e51.mp3" length="48002836" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking to Ian Sutton about his new BSD compatibility wrappers for various systemd dependencies. Don't worry, systemd is not being ported to BSD! We're still safe! We've also got all the week's news and answers to your emails, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:06:40</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking to Ian Sutton about his new BSD compatibility wrappers for various systemd dependencies. Don't worry, systemd is not being ported to BSD! We're still safe! We've also got all the week's news and answers to your emails, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://opnsense.org/" rel="nofollow noopener"&gt;Introducing OPNsense, a pfSense fork&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OPNsense is a new BSD-based firewall project that was &lt;a href="http://www.prnewswire.com/news-releases/deciso-launches-opnsense-a-new-open-source-firewall-initiative-287334371.html" rel="nofollow noopener"&gt;recently started&lt;/a&gt;, forked from the pfSense codebase&lt;/li&gt;
&lt;li&gt;Even though it's just been announced, they already have a formal release based on FreeBSD 10 (pfSense's latest stable release is based on 8.3)&lt;/li&gt;
&lt;li&gt;The &lt;a href="http://opnsense.org/about/about-opnsense/#opnsense-core-team" rel="nofollow noopener"&gt;core team&lt;/a&gt; includes a well-known DragonFlyBSD developer&lt;/li&gt;
&lt;li&gt;You can check out their code &lt;a href="https://github.com/opnsense" rel="nofollow noopener"&gt;on Github&lt;/a&gt; now, or download an image and try it out - &lt;a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener"&gt;let us know&lt;/a&gt; if you do and what you think about it&lt;/li&gt;
&lt;li&gt;They also have a nice wiki and some &lt;a href="http://wiki.opnsense.org/index.php/Manual:Installation_and_Initial_Configuration" rel="nofollow noopener"&gt;instructions on getting started&lt;/a&gt; for new users&lt;/li&gt;
&lt;li&gt;We plan on having them on the show &lt;strong&gt;next week&lt;/strong&gt; to learn a bit more about how the project got started and why you might want to use it - stay tuned
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/01/code-rot-openbsd.html" rel="nofollow noopener"&gt;Code rot and why I chose OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Here we have a blog post about rotting codebases - a core banking system in this example&lt;/li&gt;
&lt;li&gt;The author tells the story of how his last days spent at the job were mostly removing old, dead code from a giant project&lt;/li&gt;
&lt;li&gt;He goes on to compare it to OpenSSL and the hearbleed disaster, from which LibreSSL was born&lt;/li&gt;
&lt;li&gt;Instead of just bikeshedding like the rest of the internet, OpenBSD "silently started putting the beast into shape" as he puts it&lt;/li&gt;
&lt;li&gt;The article continues on to mention OpenBSD's code review process, and how it catches any bugs so we don't have more heartbleeds&lt;/li&gt;
&lt;li&gt;"In OpenBSD you are encouraged to run current and the whole team tries its best to make current as stable as it can. You know why? They eat their own dog food. That's so simple yet so amazing that it blows my mind. Developers actually run OpenBSD on their machines daily."&lt;/li&gt;
&lt;li&gt;It's a very long and detailed story about how the author has gotten more involved with BSD, learned from the mailing lists and even started contributing back - he says "In summary, I'm learning more than ever - computing is fun again"&lt;/li&gt;
&lt;li&gt;Look for the phrase "Getting Started" in the blog post for a nice little gem
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forums.freebsd.org/threads/zfs-vs-hammer.49789/" rel="nofollow noopener"&gt;ZFS vs HAMMER FS&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;One of the topics we've seen come up from time to time is how &lt;a href="http://www.bsdnow.tv/tutorials/zfs" rel="nofollow noopener"&gt;FreeBSD's ZFS&lt;/a&gt; and &lt;a href="http://www.bsdnow.tv/tutorials/hammer" rel="nofollow noopener"&gt;DragonFly's HAMMER FS&lt;/a&gt; compare to each other&lt;/li&gt;
&lt;li&gt;They both have a lot of features that traditional filesystems lack&lt;/li&gt;
&lt;li&gt;A forum thread was opened for discussion about them both and what they're typically used for&lt;/li&gt;
&lt;li&gt;It compares resource requirements, ideal hardware and pros/cons of each&lt;/li&gt;
&lt;li&gt;Hopefully someone will do another new comparison when HAMMER 2 is finished&lt;/li&gt;
&lt;li&gt;This is not to be confused with the &lt;a href="https://www.youtube.com/watch?v=HBXlVl5Ll6k" rel="nofollow noopener"&gt;other "hammer" filesystem&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.mail-archive.com/tech@openbsd.org/msg21886.html" rel="nofollow noopener"&gt;Portable OpenNTPD revived&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With ISC's NTPd having so many security vulnerabilities recently, people need an alternative &lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;NTP daemon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenBSD has developed &lt;a href="http://openntpd.org/" rel="nofollow noopener"&gt;OpenNTPD&lt;/a&gt; since 2004, but the portable version for other operating systems hasn't been actively maintained in a few years&lt;/li&gt;
&lt;li&gt;The older version still works fine, and is in FreeBSD ports and NetBSD pkgsrc, but it would be nice to have some of the newer features and fixes from the native version&lt;/li&gt;
&lt;li&gt;Brent Cook, who we've &lt;a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener"&gt;had on the show before&lt;/a&gt; to talk about LibreSSL, decided it was time to fix this&lt;/li&gt;
&lt;li&gt;While looking through the code, he also found &lt;a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/ntpd/?sortby=date#dirlist" rel="nofollow noopener"&gt;some fixes&lt;/a&gt; for the native version as well&lt;/li&gt;
&lt;li&gt;You can grab it from &lt;a href="https://github.com/openntpd-portable/openntpd-portable" rel="nofollow noopener"&gt;Github&lt;/a&gt; now, or just wait for &lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097400.html" rel="nofollow noopener"&gt;the updated release&lt;/a&gt; to hit the repos of your OS of choice
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ian Sutton - &lt;a href="mailto:ian@kremlin.cc" rel="nofollow noopener"&gt;ian@kremlin.cc&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://uglyman.kremlin.cc/gitweb/gitweb.cgi?p=systembsd.git;a=summary" rel="nofollow noopener"&gt;BSD replacements&lt;/a&gt; for &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140915064856" rel="nofollow noopener"&gt;systemd dependencies&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/freebsd/pkg/pull/1113" rel="nofollow noopener"&gt;pkgng adds OS X support&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD's next-gen &lt;a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener"&gt;package manager&lt;/a&gt; has just added support for Mac OS X&lt;/li&gt;
&lt;li&gt;Why would you want that? Well.. we don't really know, but it's cool&lt;/li&gt;
&lt;li&gt;The author of the patch &lt;a href="https://github.com/freebsd/pkg/pull/1113#issuecomment-68063964" rel="nofollow noopener"&gt;may have some insight&lt;/a&gt; about what his goal is though&lt;/li&gt;
&lt;li&gt;This could open up the door for a cross-platform pkgng solution, similar to NetBSD's pkgsrc&lt;/li&gt;
&lt;li&gt;There's also the possibility of pkgng being used as a packaging format for MacPorts in the future&lt;/li&gt;
&lt;li&gt;While we're on the topic of pkgng, you can also watch &lt;a href="http://www.bsdnow.tv/episodes/2014_01_01-eclipsing_binaries" rel="nofollow noopener"&gt;bapt&lt;/a&gt;'s latest presentation about it from ruBSD 2014 - "&lt;a href="http://is.gd/4AvUwt" rel="nofollow noopener"&gt;four years of pkg&lt;/a&gt;"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://stribika.github.io/2015/01/04/secure-secure-shell.html" rel="nofollow noopener"&gt;Secure secure shell&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Almost everyone watching BSD Now probably &lt;a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener"&gt;uses OpenSSH&lt;/a&gt; and has set up a server at one point or another&lt;/li&gt;
&lt;li&gt;This guide provides a list of best practices beyond the typical "disable root login and use keys" advice you'll often hear&lt;/li&gt;
&lt;li&gt;It specifically goes in-depth with server and client configuration with the best key types, KEX methods and encryption ciphers to use&lt;/li&gt;
&lt;li&gt;There are also good explanations for all the choices, based both on history and probability&lt;/li&gt;
&lt;li&gt;Minimal backwards compatibility is kept, but most of the old and insecure stuff gets disabled&lt;/li&gt;
&lt;li&gt;We've also got &lt;a href="http://ssh-comparison.quendi.de/comparison.html" rel="nofollow noopener"&gt;a handy chart&lt;/a&gt; to show which SSH implementations support which ciphers, in case you need to support Windows users or people who use weird clients
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lteo.net/blog/2015/01/06/dissecting-openbsds-divert-4-part-1-introduction/" rel="nofollow noopener"&gt;Dissecting OpenBSD's divert(4)&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;PF has a cool feature that not a lot of people seem to know about: divert&lt;/li&gt;
&lt;li&gt;It lets you send packets to userspace, allowing you to inspect them a lot easier&lt;/li&gt;
&lt;li&gt;This blog post, the first in a series, details all the cool things you can do with divert and how to use it&lt;/li&gt;
&lt;li&gt;A very common example is with intrusion detection systems like Snort
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.banym.de/freebsd/create-a-screen-recording-on-freebsd-with-kdenlive-and-external-usb-mic" rel="nofollow noopener"&gt;Screen recording on FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This is a neat article about a topic we don't cover very often: making video content on BSD&lt;/li&gt;
&lt;li&gt;In the post, you'll learn how to make screencasts with FreeBSD, using kdenlive and ffmpeg&lt;/li&gt;
&lt;li&gt;There are also notes about getting a USB microphone working, so you can do commentary on whatever you're showing&lt;/li&gt;
&lt;li&gt;It also includes lots of details and helpful screenshots throughout the process&lt;/li&gt;
&lt;li&gt;You should make cool screencasts and send them to us
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Zx0ktmb" rel="nofollow noopener"&gt;Camio writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2vVR5Orhh" rel="nofollow noopener"&gt;ezpzy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Ahb5Lxa" rel="nofollow noopener"&gt;Emett writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20oJmveN6" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2cTayMxPk" rel="nofollow noopener"&gt;Laszlo writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-January/263441.html" rel="nofollow noopener"&gt;Protocol X97&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141159429123859&amp;amp;w=2" rel="nofollow noopener"&gt;My thoughts echoed&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.openwall.com/lists/oss-security/2015/01/04/10" rel="nofollow noopener"&gt;Vulnerability sample&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, systemd, launchd, systembsd, gsoc, google summer of code, ntp, openntpd, opnsense, pfsense, hammer, zfs, gpl, license, macports</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking to Ian Sutton about his new BSD compatibility wrappers for various systemd dependencies. Don't worry, systemd is not being ported to BSD! We're still safe! We've also got all the week's news and answers to your emails, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://opnsense.org/" rel="nofollow noopener">Introducing OPNsense, a pfSense fork</a></h3>

<ul>
<li>OPNsense is a new BSD-based firewall project that was <a href="http://www.prnewswire.com/news-releases/deciso-launches-opnsense-a-new-open-source-firewall-initiative-287334371.html" rel="nofollow noopener">recently started</a>, forked from the pfSense codebase</li>
<li>Even though it's just been announced, they already have a formal release based on FreeBSD 10 (pfSense's latest stable release is based on 8.3)</li>
<li>The <a href="http://opnsense.org/about/about-opnsense/#opnsense-core-team" rel="nofollow noopener">core team</a> includes a well-known DragonFlyBSD developer</li>
<li>You can check out their code <a href="https://github.com/opnsense" rel="nofollow noopener">on Github</a> now, or download an image and try it out - <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">let us know</a> if you do and what you think about it</li>
<li>They also have a nice wiki and some <a href="http://wiki.opnsense.org/index.php/Manual:Installation_and_Initial_Configuration" rel="nofollow noopener">instructions on getting started</a> for new users</li>
<li>We plan on having them on the show <strong>next week</strong> to learn a bit more about how the project got started and why you might want to use it - stay tuned
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/01/code-rot-openbsd.html" rel="nofollow noopener">Code rot and why I chose OpenBSD</a></h3>

<ul>
<li>Here we have a blog post about rotting codebases - a core banking system in this example</li>
<li>The author tells the story of how his last days spent at the job were mostly removing old, dead code from a giant project</li>
<li>He goes on to compare it to OpenSSL and the hearbleed disaster, from which LibreSSL was born</li>
<li>Instead of just bikeshedding like the rest of the internet, OpenBSD "silently started putting the beast into shape" as he puts it</li>
<li>The article continues on to mention OpenBSD's code review process, and how it catches any bugs so we don't have more heartbleeds</li>
<li>"In OpenBSD you are encouraged to run current and the whole team tries its best to make current as stable as it can. You know why? They eat their own dog food. That's so simple yet so amazing that it blows my mind. Developers actually run OpenBSD on their machines daily."</li>
<li>It's a very long and detailed story about how the author has gotten more involved with BSD, learned from the mailing lists and even started contributing back - he says "In summary, I'm learning more than ever - computing is fun again"</li>
<li>Look for the phrase "Getting Started" in the blog post for a nice little gem
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/zfs-vs-hammer.49789/" rel="nofollow noopener">ZFS vs HAMMER FS</a></h3>

<ul>
<li>One of the topics we've seen come up from time to time is how <a href="http://www.bsdnow.tv/tutorials/zfs" rel="nofollow noopener">FreeBSD's ZFS</a> and <a href="http://www.bsdnow.tv/tutorials/hammer" rel="nofollow noopener">DragonFly's HAMMER FS</a> compare to each other</li>
<li>They both have a lot of features that traditional filesystems lack</li>
<li>A forum thread was opened for discussion about them both and what they're typically used for</li>
<li>It compares resource requirements, ideal hardware and pros/cons of each</li>
<li>Hopefully someone will do another new comparison when HAMMER 2 is finished</li>
<li>This is not to be confused with the <a href="https://www.youtube.com/watch?v=HBXlVl5Ll6k" rel="nofollow noopener">other "hammer" filesystem</a>
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/tech@openbsd.org/msg21886.html" rel="nofollow noopener">Portable OpenNTPD revived</a></h3>

<ul>
<li>With ISC's NTPd having so many security vulnerabilities recently, people need an alternative <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">NTP daemon</a></li>
<li>OpenBSD has developed <a href="http://openntpd.org/" rel="nofollow noopener">OpenNTPD</a> since 2004, but the portable version for other operating systems hasn't been actively maintained in a few years</li>
<li>The older version still works fine, and is in FreeBSD ports and NetBSD pkgsrc, but it would be nice to have some of the newer features and fixes from the native version</li>
<li>Brent Cook, who we've <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">had on the show before</a> to talk about LibreSSL, decided it was time to fix this</li>
<li>While looking through the code, he also found <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/ntpd/?sortby=date#dirlist" rel="nofollow noopener">some fixes</a> for the native version as well</li>
<li>You can grab it from <a href="https://github.com/openntpd-portable/openntpd-portable" rel="nofollow noopener">Github</a> now, or just wait for <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097400.html" rel="nofollow noopener">the updated release</a> to hit the repos of your OS of choice
***</li>
</ul>

<h2>Interview - Ian Sutton - <a href="mailto:ian@kremlin.cc" rel="nofollow noopener">ian@kremlin.cc</a></h2>

<p><a href="https://uglyman.kremlin.cc/gitweb/gitweb.cgi?p=systembsd.git;a=summary" rel="nofollow noopener">BSD replacements</a> for <a href="http://undeadly.org/cgi?action=article&amp;sid=20140915064856" rel="nofollow noopener">systemd dependencies</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/freebsd/pkg/pull/1113" rel="nofollow noopener">pkgng adds OS X support</a></h3>

<ul>
<li>FreeBSD's next-gen <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package manager</a> has just added support for Mac OS X</li>
<li>Why would you want that? Well.. we don't really know, but it's cool</li>
<li>The author of the patch <a href="https://github.com/freebsd/pkg/pull/1113#issuecomment-68063964" rel="nofollow noopener">may have some insight</a> about what his goal is though</li>
<li>This could open up the door for a cross-platform pkgng solution, similar to NetBSD's pkgsrc</li>
<li>There's also the possibility of pkgng being used as a packaging format for MacPorts in the future</li>
<li>While we're on the topic of pkgng, you can also watch <a href="http://www.bsdnow.tv/episodes/2014_01_01-eclipsing_binaries" rel="nofollow noopener">bapt</a>'s latest presentation about it from ruBSD 2014 - "<a href="http://is.gd/4AvUwt" rel="nofollow noopener">four years of pkg</a>"
***</li>
</ul>

<h3><a href="https://stribika.github.io/2015/01/04/secure-secure-shell.html" rel="nofollow noopener">Secure secure shell</a></h3>

<ul>
<li>Almost everyone watching BSD Now probably <a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener">uses OpenSSH</a> and has set up a server at one point or another</li>
<li>This guide provides a list of best practices beyond the typical "disable root login and use keys" advice you'll often hear</li>
<li>It specifically goes in-depth with server and client configuration with the best key types, KEX methods and encryption ciphers to use</li>
<li>There are also good explanations for all the choices, based both on history and probability</li>
<li>Minimal backwards compatibility is kept, but most of the old and insecure stuff gets disabled</li>
<li>We've also got <a href="http://ssh-comparison.quendi.de/comparison.html" rel="nofollow noopener">a handy chart</a> to show which SSH implementations support which ciphers, in case you need to support Windows users or people who use weird clients
***</li>
</ul>

<h3><a href="http://lteo.net/blog/2015/01/06/dissecting-openbsds-divert-4-part-1-introduction/" rel="nofollow noopener">Dissecting OpenBSD's divert(4)</a></h3>

<ul>
<li>PF has a cool feature that not a lot of people seem to know about: divert</li>
<li>It lets you send packets to userspace, allowing you to inspect them a lot easier</li>
<li>This blog post, the first in a series, details all the cool things you can do with divert and how to use it</li>
<li>A very common example is with intrusion detection systems like Snort
***</li>
</ul>

<h3><a href="https://www.banym.de/freebsd/create-a-screen-recording-on-freebsd-with-kdenlive-and-external-usb-mic" rel="nofollow noopener">Screen recording on FreeBSD</a></h3>

<ul>
<li>This is a neat article about a topic we don't cover very often: making video content on BSD</li>
<li>In the post, you'll learn how to make screencasts with FreeBSD, using kdenlive and ffmpeg</li>
<li>There are also notes about getting a USB microphone working, so you can do commentary on whatever you're showing</li>
<li>It also includes lots of details and helpful screenshots throughout the process</li>
<li>You should make cool screencasts and send them to us
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21Zx0ktmb" rel="nofollow noopener">Camio writes in</a></li>
<li><a href="http://slexy.org/view/s2vVR5Orhh" rel="nofollow noopener">ezpzy writes in</a></li>
<li><a href="http://slexy.org/view/s21Ahb5Lxa" rel="nofollow noopener">Emett writes in</a></li>
<li><a href="http://slexy.org/view/s20oJmveN6" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s2cTayMxPk" rel="nofollow noopener">Laszlo writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-January/263441.html" rel="nofollow noopener">Protocol X97</a></li>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141159429123859&amp;w=2" rel="nofollow noopener">My thoughts echoed</a></li>
<li><a href="http://www.openwall.com/lists/oss-security/2015/01/04/10" rel="nofollow noopener">Vulnerability sample</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking to Ian Sutton about his new BSD compatibility wrappers for various systemd dependencies. Don't worry, systemd is not being ported to BSD! We're still safe! We've also got all the week's news and answers to your emails, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://opnsense.org/" rel="nofollow noopener">Introducing OPNsense, a pfSense fork</a></h3>

<ul>
<li>OPNsense is a new BSD-based firewall project that was <a href="http://www.prnewswire.com/news-releases/deciso-launches-opnsense-a-new-open-source-firewall-initiative-287334371.html" rel="nofollow noopener">recently started</a>, forked from the pfSense codebase</li>
<li>Even though it's just been announced, they already have a formal release based on FreeBSD 10 (pfSense's latest stable release is based on 8.3)</li>
<li>The <a href="http://opnsense.org/about/about-opnsense/#opnsense-core-team" rel="nofollow noopener">core team</a> includes a well-known DragonFlyBSD developer</li>
<li>You can check out their code <a href="https://github.com/opnsense" rel="nofollow noopener">on Github</a> now, or download an image and try it out - <a href="mailto:feedback@bsdnow.tv" rel="nofollow noopener">let us know</a> if you do and what you think about it</li>
<li>They also have a nice wiki and some <a href="http://wiki.opnsense.org/index.php/Manual:Installation_and_Initial_Configuration" rel="nofollow noopener">instructions on getting started</a> for new users</li>
<li>We plan on having them on the show <strong>next week</strong> to learn a bit more about how the project got started and why you might want to use it - stay tuned
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/01/code-rot-openbsd.html" rel="nofollow noopener">Code rot and why I chose OpenBSD</a></h3>

<ul>
<li>Here we have a blog post about rotting codebases - a core banking system in this example</li>
<li>The author tells the story of how his last days spent at the job were mostly removing old, dead code from a giant project</li>
<li>He goes on to compare it to OpenSSL and the hearbleed disaster, from which LibreSSL was born</li>
<li>Instead of just bikeshedding like the rest of the internet, OpenBSD "silently started putting the beast into shape" as he puts it</li>
<li>The article continues on to mention OpenBSD's code review process, and how it catches any bugs so we don't have more heartbleeds</li>
<li>"In OpenBSD you are encouraged to run current and the whole team tries its best to make current as stable as it can. You know why? They eat their own dog food. That's so simple yet so amazing that it blows my mind. Developers actually run OpenBSD on their machines daily."</li>
<li>It's a very long and detailed story about how the author has gotten more involved with BSD, learned from the mailing lists and even started contributing back - he says "In summary, I'm learning more than ever - computing is fun again"</li>
<li>Look for the phrase "Getting Started" in the blog post for a nice little gem
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/zfs-vs-hammer.49789/" rel="nofollow noopener">ZFS vs HAMMER FS</a></h3>

<ul>
<li>One of the topics we've seen come up from time to time is how <a href="http://www.bsdnow.tv/tutorials/zfs" rel="nofollow noopener">FreeBSD's ZFS</a> and <a href="http://www.bsdnow.tv/tutorials/hammer" rel="nofollow noopener">DragonFly's HAMMER FS</a> compare to each other</li>
<li>They both have a lot of features that traditional filesystems lack</li>
<li>A forum thread was opened for discussion about them both and what they're typically used for</li>
<li>It compares resource requirements, ideal hardware and pros/cons of each</li>
<li>Hopefully someone will do another new comparison when HAMMER 2 is finished</li>
<li>This is not to be confused with the <a href="https://www.youtube.com/watch?v=HBXlVl5Ll6k" rel="nofollow noopener">other "hammer" filesystem</a>
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/tech@openbsd.org/msg21886.html" rel="nofollow noopener">Portable OpenNTPD revived</a></h3>

<ul>
<li>With ISC's NTPd having so many security vulnerabilities recently, people need an alternative <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">NTP daemon</a></li>
<li>OpenBSD has developed <a href="http://openntpd.org/" rel="nofollow noopener">OpenNTPD</a> since 2004, but the portable version for other operating systems hasn't been actively maintained in a few years</li>
<li>The older version still works fine, and is in FreeBSD ports and NetBSD pkgsrc, but it would be nice to have some of the newer features and fixes from the native version</li>
<li>Brent Cook, who we've <a href="http://www.bsdnow.tv/episodes/2014_07_30-liberating_ssl" rel="nofollow noopener">had on the show before</a> to talk about LibreSSL, decided it was time to fix this</li>
<li>While looking through the code, he also found <a href="http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.sbin/ntpd/?sortby=date#dirlist" rel="nofollow noopener">some fixes</a> for the native version as well</li>
<li>You can grab it from <a href="https://github.com/openntpd-portable/openntpd-portable" rel="nofollow noopener">Github</a> now, or just wait for <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2015-January/097400.html" rel="nofollow noopener">the updated release</a> to hit the repos of your OS of choice
***</li>
</ul>

<h2>Interview - Ian Sutton - <a href="mailto:ian@kremlin.cc" rel="nofollow noopener">ian@kremlin.cc</a></h2>

<p><a href="https://uglyman.kremlin.cc/gitweb/gitweb.cgi?p=systembsd.git;a=summary" rel="nofollow noopener">BSD replacements</a> for <a href="http://undeadly.org/cgi?action=article&amp;sid=20140915064856" rel="nofollow noopener">systemd dependencies</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/freebsd/pkg/pull/1113" rel="nofollow noopener">pkgng adds OS X support</a></h3>

<ul>
<li>FreeBSD's next-gen <a href="http://www.bsdnow.tv/tutorials/pkgng" rel="nofollow noopener">package manager</a> has just added support for Mac OS X</li>
<li>Why would you want that? Well.. we don't really know, but it's cool</li>
<li>The author of the patch <a href="https://github.com/freebsd/pkg/pull/1113#issuecomment-68063964" rel="nofollow noopener">may have some insight</a> about what his goal is though</li>
<li>This could open up the door for a cross-platform pkgng solution, similar to NetBSD's pkgsrc</li>
<li>There's also the possibility of pkgng being used as a packaging format for MacPorts in the future</li>
<li>While we're on the topic of pkgng, you can also watch <a href="http://www.bsdnow.tv/episodes/2014_01_01-eclipsing_binaries" rel="nofollow noopener">bapt</a>'s latest presentation about it from ruBSD 2014 - "<a href="http://is.gd/4AvUwt" rel="nofollow noopener">four years of pkg</a>"
***</li>
</ul>

<h3><a href="https://stribika.github.io/2015/01/04/secure-secure-shell.html" rel="nofollow noopener">Secure secure shell</a></h3>

<ul>
<li>Almost everyone watching BSD Now probably <a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener">uses OpenSSH</a> and has set up a server at one point or another</li>
<li>This guide provides a list of best practices beyond the typical "disable root login and use keys" advice you'll often hear</li>
<li>It specifically goes in-depth with server and client configuration with the best key types, KEX methods and encryption ciphers to use</li>
<li>There are also good explanations for all the choices, based both on history and probability</li>
<li>Minimal backwards compatibility is kept, but most of the old and insecure stuff gets disabled</li>
<li>We've also got <a href="http://ssh-comparison.quendi.de/comparison.html" rel="nofollow noopener">a handy chart</a> to show which SSH implementations support which ciphers, in case you need to support Windows users or people who use weird clients
***</li>
</ul>

<h3><a href="http://lteo.net/blog/2015/01/06/dissecting-openbsds-divert-4-part-1-introduction/" rel="nofollow noopener">Dissecting OpenBSD's divert(4)</a></h3>

<ul>
<li>PF has a cool feature that not a lot of people seem to know about: divert</li>
<li>It lets you send packets to userspace, allowing you to inspect them a lot easier</li>
<li>This blog post, the first in a series, details all the cool things you can do with divert and how to use it</li>
<li>A very common example is with intrusion detection systems like Snort
***</li>
</ul>

<h3><a href="https://www.banym.de/freebsd/create-a-screen-recording-on-freebsd-with-kdenlive-and-external-usb-mic" rel="nofollow noopener">Screen recording on FreeBSD</a></h3>

<ul>
<li>This is a neat article about a topic we don't cover very often: making video content on BSD</li>
<li>In the post, you'll learn how to make screencasts with FreeBSD, using kdenlive and ffmpeg</li>
<li>There are also notes about getting a USB microphone working, so you can do commentary on whatever you're showing</li>
<li>It also includes lots of details and helpful screenshots throughout the process</li>
<li>You should make cool screencasts and send them to us
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21Zx0ktmb" rel="nofollow noopener">Camio writes in</a></li>
<li><a href="http://slexy.org/view/s2vVR5Orhh" rel="nofollow noopener">ezpzy writes in</a></li>
<li><a href="http://slexy.org/view/s21Ahb5Lxa" rel="nofollow noopener">Emett writes in</a></li>
<li><a href="http://slexy.org/view/s20oJmveN6" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s2cTayMxPk" rel="nofollow noopener">Laszlo writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-questions/2015-January/263441.html" rel="nofollow noopener">Protocol X97</a></li>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141159429123859&amp;w=2" rel="nofollow noopener">My thoughts echoed</a></li>
<li><a href="http://www.openwall.com/lists/oss-security/2015/01/04/10" rel="nofollow noopener">Vulnerability sample</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>70: Daemons in the North</title>
  <link>https://www.bsdnow.tv/70</link>
  <guid isPermaLink="false">55684d1a-97da-439b-a037-b02c8d49de70</guid>
  <pubDate>Wed, 31 Dec 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/55684d1a-97da-439b-a037-b02c8d49de70.mp3" length="60663316" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:24:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener"&gt;More conference presentation videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Some more of the presentation videos from AsiaBSDCon are appearing online&lt;/li&gt;
&lt;li&gt;Masanobu Saitoh, &lt;a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener"&gt;Developing CPE Routers Based on NetBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener"&gt;Reyk Floeter&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener"&gt;VXLAN and Cloud-based Networking with OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jos Jansen, &lt;a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener"&gt;Adapting OS X to the enterprise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener"&gt;Pierre Pronchery&lt;/a&gt; &amp;amp; Guillaume Lasmayous, &lt;a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener"&gt;Carve your NetBSD&lt;/a&gt; &amp;lt;!-- skip to 5:06 for henning trolling --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener"&gt;Colin Percival&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener"&gt;Everything you need to know about cryptography in 1 hour&lt;/a&gt; (not from AsiaBSDCon)&lt;/li&gt;
&lt;li&gt;The "bsdconferences" YouTube channel has quite a lot of interesting &lt;a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;amp;view=0&amp;amp;flow=grid" rel="nofollow noopener"&gt;older BSD talks&lt;/a&gt; too - you may want to go back and watch them if you haven't already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141922027318727&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD PIE enhancements&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener"&gt;ASLR&lt;/a&gt; and &lt;a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener"&gt;PIE&lt;/a&gt; are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem&lt;/li&gt;
&lt;li&gt;They only work with &lt;em&gt;dynamic&lt;/em&gt; libraries and binaries, so if you have any static binaries, they don't get the same treatment&lt;/li&gt;
&lt;li&gt;For example, the default shells (and many other things in /bin and /sbin) are statically linked&lt;/li&gt;
&lt;li&gt;In the case of the static ones, you can always predict the memory layout, which is very bad and sort of &lt;a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener"&gt;defeats the whole purpose&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;With this and a few &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141927571832106&amp;amp;w=2" rel="nofollow noopener"&gt;related commits&lt;/a&gt;, OpenBSD fixes this by introducing &lt;strong&gt;static self-relocation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy&lt;/li&gt;
&lt;li&gt;It'll be available in 5.7 in May, or you can use a &lt;a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener"&gt;-current snapshot&lt;/a&gt; if you want to get a &lt;em&gt;slice&lt;/em&gt; of the action now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener"&gt;FreeBSD foundation semi-annual newsletter&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities&lt;/li&gt;
&lt;li&gt;As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved&lt;/li&gt;
&lt;li&gt;The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)&lt;/li&gt;
&lt;li&gt;You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too&lt;/li&gt;
&lt;li&gt;There are also sections about the &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;FreeBSD Journal&lt;/a&gt;'s progress, a new staff member and a testimonial from NetApp&lt;/li&gt;
&lt;li&gt;It's a very long report, so dedicate some time to read all the way through it&lt;/li&gt;
&lt;li&gt;This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too&lt;/li&gt;
&lt;li&gt;As we go into 2015, consider donating to &lt;a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener"&gt;whichever&lt;/a&gt; &lt;a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener"&gt;BSD&lt;/a&gt; &lt;a href="https://www.netbsd.org/donations/" rel="nofollow noopener"&gt;you&lt;/a&gt; &lt;a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener"&gt;use&lt;/a&gt;, it really can make a difference
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141920089614758&amp;amp;w=4" rel="nofollow noopener"&gt;Modernizing OpenSSH fingerprints&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to&lt;/li&gt;
&lt;li&gt;Up until now, the key fingerprints have been an MD5 hash, displayed as hex&lt;/li&gt;
&lt;li&gt;This &lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener"&gt;can be problematic&lt;/a&gt;, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to&lt;/li&gt;
&lt;li&gt;This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint&lt;/li&gt;
&lt;li&gt;You can add a "FingerprintHash" line in your ssh_config to force using only the new type&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141923470520906&amp;amp;w=2" rel="nofollow noopener"&gt;new option&lt;/a&gt; to require users to authenticate with &lt;strong&gt;more than one&lt;/strong&gt; public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type&lt;/li&gt;
&lt;li&gt;The new options should be in the upcoming 6.8 release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Dan Langille - &lt;a href="mailto:info@bsdcan.org" rel="nofollow noopener"&gt;info@bsdcan.org&lt;/a&gt; / &lt;a href="https://twitter.com/bsdcan" rel="nofollow noopener"&gt;@bsdcan&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Plans for the BSDCan 2015 conference&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener"&gt;Introducing ntimed, a new NTP daemon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As we've mentioned before in &lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;our tutorials&lt;/a&gt;, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD&lt;/li&gt;
&lt;li&gt;With all the recent security problems with ISC's NTPd, &lt;a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener"&gt;Poul-Henning Kamp&lt;/a&gt; has been working on a third NTP daemon&lt;/li&gt;
&lt;li&gt;It's called "ntimed" and you can try out a preview version of it right now - it's &lt;a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener"&gt;in FreeBSD ports&lt;/a&gt; or on Github&lt;/li&gt;
&lt;li&gt;PHK also has a few &lt;a href="http://phk.freebsd.dk/time/" rel="nofollow noopener"&gt;blog entries&lt;/a&gt; about the project, including status updates
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener"&gt;OpenBSD-maintained projects list&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was recently a read on the &lt;a href="https://www.marc.info/?t=141961588200003&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;misc mailing list&lt;/a&gt; asking about different projects started by OpenBSD developers&lt;/li&gt;
&lt;li&gt;The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)&lt;/li&gt;
&lt;li&gt;A developer compiled a new list from all of the replies to that thread into a nice organized webpage&lt;/li&gt;
&lt;li&gt;Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more&lt;/li&gt;
&lt;li&gt;This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener"&gt;Monitoring network traffic with FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you&lt;/li&gt;
&lt;li&gt;It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)&lt;/li&gt;
&lt;li&gt;This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener"&gt;Trapping spammers with spamd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This is a blog post about OpenBSD's &lt;a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener"&gt;spamd&lt;/a&gt; - a spam email deferral daemon - and how to use it for your mail&lt;/li&gt;
&lt;li&gt;It gives some background on the greylisting approach to spam, rather than just a typical host blacklist&lt;/li&gt;
&lt;li&gt;"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."&lt;/li&gt;
&lt;li&gt;The post also shows how to combine it with PF and other tools for a pretty fancy mail setup&lt;/li&gt;
&lt;li&gt;You can find spamd in the OpenBSD &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener"&gt;base system&lt;/a&gt;, or use it &lt;a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener"&gt;with FreeBSD&lt;/a&gt; &lt;a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener"&gt;or NetBSD&lt;/a&gt; via ports and pkgsrc&lt;/li&gt;
&lt;li&gt;You might also want to go back and listen to &lt;a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener"&gt;BSDTalk episode 68&lt;/a&gt;, where Will talks to Bob Beck about spamd
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener"&gt;Brandon writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener"&gt;Anders writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener"&gt;Kyle writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141903858708123&amp;amp;w=2" rel="nofollow noopener"&gt;NTP code comparison&lt;/a&gt; - &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141905854411370&amp;amp;w=2" rel="nofollow noopener"&gt;192870 vs. 2898&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener"&gt;NICs have feelings too&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=141998130824977&amp;amp;w=2" rel="nofollow noopener"&gt;Just think about it&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, bsdcan, call for papers, conference, talk, presentation, vxlan, static, pie, openssh, ntimed, ntp, openntpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener">More conference presentation videos</a></h3>

<ul>
<li>Some more of the presentation videos from AsiaBSDCon are appearing online</li>
<li>Masanobu Saitoh, <a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener">Developing CPE Routers Based on NetBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">VXLAN and Cloud-based Networking with OpenBSD</a></li>
<li>Jos Jansen, <a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener">Adapting OS X to the enterprise</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener">Pierre Pronchery</a> &amp; Guillaume Lasmayous, <a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener">Carve your NetBSD</a> &lt;!-- skip to 5:06 for henning trolling --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener">Colin Percival</a>, <a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener">Everything you need to know about cryptography in 1 hour</a> (not from AsiaBSDCon)</li>
<li>The "bsdconferences" YouTube channel has quite a lot of interesting <a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;view=0&amp;flow=grid" rel="nofollow noopener">older BSD talks</a> too - you may want to go back and watch them if you haven't already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141922027318727&amp;w=2" rel="nofollow noopener">OpenBSD PIE enhancements</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a> and <a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener">PIE</a> are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem</li>
<li>They only work with <em>dynamic</em> libraries and binaries, so if you have any static binaries, they don't get the same treatment</li>
<li>For example, the default shells (and many other things in /bin and /sbin) are statically linked</li>
<li>In the case of the static ones, you can always predict the memory layout, which is very bad and sort of <a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener">defeats the whole purpose</a></li>
<li>With this and a few <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141927571832106&amp;w=2" rel="nofollow noopener">related commits</a>, OpenBSD fixes this by introducing <strong>static self-relocation</strong></li>
<li>More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy</li>
<li>It'll be available in 5.7 in May, or you can use a <a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener">-current snapshot</a> if you want to get a <em>slice</em> of the action now
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities</li>
<li>As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved</li>
<li>The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)</li>
<li>You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too</li>
<li>There are also sections about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD Journal</a>'s progress, a new staff member and a testimonial from NetApp</li>
<li>It's a very long report, so dedicate some time to read all the way through it</li>
<li>This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too</li>
<li>As we go into 2015, consider donating to <a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">whichever</a> <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">BSD</a> <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">you</a> <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">use</a>, it really can make a difference
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141920089614758&amp;w=4" rel="nofollow noopener">Modernizing OpenSSH fingerprints</a></h3>

<ul>
<li>When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to</li>
<li>Up until now, the key fingerprints have been an MD5 hash, displayed as hex</li>
<li>This <a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener">can be problematic</a>, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to</li>
<li>This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint</li>
<li>You can add a "FingerprintHash" line in your ssh_config to force using only the new type</li>
<li>There's also a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141923470520906&amp;w=2" rel="nofollow noopener">new option</a> to require users to authenticate with <strong>more than one</strong> public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type</li>
<li>The new options should be in the upcoming 6.8 release
***</li>
</ul>

<h2>Interview - Dan Langille - <a href="mailto:info@bsdcan.org" rel="nofollow noopener">info@bsdcan.org</a> / <a href="https://twitter.com/bsdcan" rel="nofollow noopener">@bsdcan</a></h2>

<p>Plans for the BSDCan 2015 conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener">Introducing ntimed, a new NTP daemon</a></h3>

<ul>
<li>As we've mentioned before in <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">our tutorials</a>, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD</li>
<li>With all the recent security problems with ISC's NTPd, <a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">Poul-Henning Kamp</a> has been working on a third NTP daemon</li>
<li>It's called "ntimed" and you can try out a preview version of it right now - it's <a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener">in FreeBSD ports</a> or on Github</li>
<li>PHK also has a few <a href="http://phk.freebsd.dk/time/" rel="nofollow noopener">blog entries</a> about the project, including status updates
***</li>
</ul>

<h3><a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener">OpenBSD-maintained projects list</a></h3>

<ul>
<li>There was recently a read on the <a href="https://www.marc.info/?t=141961588200003&amp;r=1&amp;w=2" rel="nofollow noopener">misc mailing list</a> asking about different projects started by OpenBSD developers</li>
<li>The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)</li>
<li>A developer compiled a new list from all of the replies to that thread into a nice organized webpage</li>
<li>Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more</li>
<li>This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener">Monitoring network traffic with FreeBSD</a></h3>

<ul>
<li>If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you</li>
<li>It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)</li>
<li>This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener">Trapping spammers with spamd</a></h3>

<ul>
<li>This is a blog post about OpenBSD's <a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener">spamd</a> - a spam email deferral daemon - and how to use it for your mail</li>
<li>It gives some background on the greylisting approach to spam, rather than just a typical host blacklist</li>
<li>"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."</li>
<li>The post also shows how to combine it with PF and other tools for a pretty fancy mail setup</li>
<li>You can find spamd in the OpenBSD <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener">base system</a>, or use it <a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener">with FreeBSD</a> <a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener">or NetBSD</a> via ports and pkgsrc</li>
<li>You might also want to go back and listen to <a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener">BSDTalk episode 68</a>, where Will talks to Bob Beck about spamd
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener">Brandon writes in</a></li>
<li><a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener">Anders writes in</a></li>
<li><a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener">Kyle writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141903858708123&amp;w=2" rel="nofollow noopener">NTP code comparison</a> - <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141905854411370&amp;w=2" rel="nofollow noopener">192870 vs. 2898</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener">NICs have feelings too</a></li>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=141998130824977&amp;w=2" rel="nofollow noopener">Just think about it</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener">More conference presentation videos</a></h3>

<ul>
<li>Some more of the presentation videos from AsiaBSDCon are appearing online</li>
<li>Masanobu Saitoh, <a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener">Developing CPE Routers Based on NetBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">VXLAN and Cloud-based Networking with OpenBSD</a></li>
<li>Jos Jansen, <a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener">Adapting OS X to the enterprise</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener">Pierre Pronchery</a> &amp; Guillaume Lasmayous, <a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener">Carve your NetBSD</a> &lt;!-- skip to 5:06 for henning trolling --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener">Colin Percival</a>, <a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener">Everything you need to know about cryptography in 1 hour</a> (not from AsiaBSDCon)</li>
<li>The "bsdconferences" YouTube channel has quite a lot of interesting <a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;view=0&amp;flow=grid" rel="nofollow noopener">older BSD talks</a> too - you may want to go back and watch them if you haven't already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141922027318727&amp;w=2" rel="nofollow noopener">OpenBSD PIE enhancements</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a> and <a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener">PIE</a> are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem</li>
<li>They only work with <em>dynamic</em> libraries and binaries, so if you have any static binaries, they don't get the same treatment</li>
<li>For example, the default shells (and many other things in /bin and /sbin) are statically linked</li>
<li>In the case of the static ones, you can always predict the memory layout, which is very bad and sort of <a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener">defeats the whole purpose</a></li>
<li>With this and a few <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141927571832106&amp;w=2" rel="nofollow noopener">related commits</a>, OpenBSD fixes this by introducing <strong>static self-relocation</strong></li>
<li>More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy</li>
<li>It'll be available in 5.7 in May, or you can use a <a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener">-current snapshot</a> if you want to get a <em>slice</em> of the action now
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities</li>
<li>As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved</li>
<li>The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)</li>
<li>You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too</li>
<li>There are also sections about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD Journal</a>'s progress, a new staff member and a testimonial from NetApp</li>
<li>It's a very long report, so dedicate some time to read all the way through it</li>
<li>This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too</li>
<li>As we go into 2015, consider donating to <a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">whichever</a> <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">BSD</a> <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">you</a> <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">use</a>, it really can make a difference
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141920089614758&amp;w=4" rel="nofollow noopener">Modernizing OpenSSH fingerprints</a></h3>

<ul>
<li>When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to</li>
<li>Up until now, the key fingerprints have been an MD5 hash, displayed as hex</li>
<li>This <a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener">can be problematic</a>, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to</li>
<li>This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint</li>
<li>You can add a "FingerprintHash" line in your ssh_config to force using only the new type</li>
<li>There's also a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141923470520906&amp;w=2" rel="nofollow noopener">new option</a> to require users to authenticate with <strong>more than one</strong> public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type</li>
<li>The new options should be in the upcoming 6.8 release
***</li>
</ul>

<h2>Interview - Dan Langille - <a href="mailto:info@bsdcan.org" rel="nofollow noopener">info@bsdcan.org</a> / <a href="https://twitter.com/bsdcan" rel="nofollow noopener">@bsdcan</a></h2>

<p>Plans for the BSDCan 2015 conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener">Introducing ntimed, a new NTP daemon</a></h3>

<ul>
<li>As we've mentioned before in <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">our tutorials</a>, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD</li>
<li>With all the recent security problems with ISC's NTPd, <a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">Poul-Henning Kamp</a> has been working on a third NTP daemon</li>
<li>It's called "ntimed" and you can try out a preview version of it right now - it's <a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener">in FreeBSD ports</a> or on Github</li>
<li>PHK also has a few <a href="http://phk.freebsd.dk/time/" rel="nofollow noopener">blog entries</a> about the project, including status updates
***</li>
</ul>

<h3><a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener">OpenBSD-maintained projects list</a></h3>

<ul>
<li>There was recently a read on the <a href="https://www.marc.info/?t=141961588200003&amp;r=1&amp;w=2" rel="nofollow noopener">misc mailing list</a> asking about different projects started by OpenBSD developers</li>
<li>The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)</li>
<li>A developer compiled a new list from all of the replies to that thread into a nice organized webpage</li>
<li>Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more</li>
<li>This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener">Monitoring network traffic with FreeBSD</a></h3>

<ul>
<li>If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you</li>
<li>It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)</li>
<li>This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener">Trapping spammers with spamd</a></h3>

<ul>
<li>This is a blog post about OpenBSD's <a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener">spamd</a> - a spam email deferral daemon - and how to use it for your mail</li>
<li>It gives some background on the greylisting approach to spam, rather than just a typical host blacklist</li>
<li>"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."</li>
<li>The post also shows how to combine it with PF and other tools for a pretty fancy mail setup</li>
<li>You can find spamd in the OpenBSD <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener">base system</a>, or use it <a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener">with FreeBSD</a> <a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener">or NetBSD</a> via ports and pkgsrc</li>
<li>You might also want to go back and listen to <a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener">BSDTalk episode 68</a>, where Will talks to Bob Beck about spamd
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener">Brandon writes in</a></li>
<li><a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener">Anders writes in</a></li>
<li><a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener">Kyle writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141903858708123&amp;w=2" rel="nofollow noopener">NTP code comparison</a> - <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141905854411370&amp;w=2" rel="nofollow noopener">192870 vs. 2898</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener">NICs have feelings too</a></li>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=141998130824977&amp;w=2" rel="nofollow noopener">Just think about it</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>23: Time Signatures</title>
  <link>https://www.bsdnow.tv/23</link>
  <guid isPermaLink="false">d9e9eb7a-e7aa-4029-8881-05cc5f75e8b6</guid>
  <pubDate>Wed, 05 Feb 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/d9e9eb7a-e7aa-4029-8881-05cc5f75e8b6.mp3" length="54539109" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:15:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener"&gt;FreeBSD foundation's 2013 fundraising results&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation finally counted all the money they made in 2013&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;$768,562 from 1659 donors&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Nice little blog post from the team with a giant beastie picture&lt;/li&gt;
&lt;li&gt;"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."&lt;/li&gt;
&lt;li&gt;A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener"&gt;OpenSSH 6.5 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned the CFT last week, and it's &lt;a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener"&gt;finally here&lt;/a&gt;!&lt;/li&gt;
&lt;li&gt;New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)&lt;/li&gt;
&lt;li&gt;Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA&lt;/li&gt;
&lt;li&gt;Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes &lt;a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener"&gt;can't even attempt to login&lt;/a&gt; lol~&lt;/li&gt;
&lt;li&gt;New bcrypt private key type, 500,000,000 times harder to brute force&lt;/li&gt;
&lt;li&gt;Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one&lt;/li&gt;
&lt;li&gt;Portable version &lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=261320" rel="nofollow noopener"&gt;already in&lt;/a&gt; FreeBSD -CURRENT, &lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;sortby=date&amp;amp;revision=342618" rel="nofollow noopener"&gt;and ports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots more bugfixes and features, see the full release note or &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;our interview&lt;/a&gt; with Damien&lt;/li&gt;
&lt;li&gt;Work has already started on 6.6, which &lt;a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener"&gt;can be used without OpenSSL&lt;/a&gt;!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener"&gt;Crazed Ferrets in a Berkeley Shower&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;In 2000, &lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;MWL&lt;/a&gt; wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."&lt;/li&gt;
&lt;li&gt;This is basically an updated version about why he uses the BSD license, in response to recent &lt;a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener"&gt;comments from Richard Stallman&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL&lt;/li&gt;
&lt;li&gt;Check out the full post if you're one of those people that gets into license arguments&lt;/li&gt;
&lt;li&gt;The takeaway is "BSD is about making the world a better place. For everyone."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener"&gt;OpenBSD on BeagleBone Black&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi&lt;/li&gt;
&lt;li&gt;A blog post about installing OpenBSD on a BBB from.. our guest for today!&lt;/li&gt;
&lt;li&gt;He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"&lt;/li&gt;
&lt;li&gt;It goes through the whole process, details different storage options and some workarounds&lt;/li&gt;
&lt;li&gt;Could be a really fun weekend project if you're interested in small or embedded devices
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Ted Unangst - &lt;a href="mailto:tedu@openbsd.org" rel="nofollow noopener"&gt;tedu@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/tedunangst" rel="nofollow noopener"&gt;@tedunangst&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;OpenBSD's &lt;a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener"&gt;signify&lt;/a&gt; infrastructure, ZFS on OpenBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;Running an NTP server&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener"&gt;Getting started with FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A new video and blog series about starting out with FreeBSD&lt;/li&gt;
&lt;li&gt;The author has been a fan since the 90s and has installed it on every server he's worked with&lt;/li&gt;
&lt;li&gt;He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users&lt;/li&gt;
&lt;li&gt;The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140204080515" rel="nofollow noopener"&gt;More OpenBSD hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience&lt;/li&gt;
&lt;li&gt;He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work&lt;/li&gt;
&lt;li&gt;This summary goes into detail about all the stuff he got done there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=261266" rel="nofollow noopener"&gt;X11 in a jail&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!&lt;/li&gt;
&lt;li&gt;A new tunable option will let jails access /dev/kmem and similar device nodes&lt;/li&gt;
&lt;li&gt;Along with a change to DRM, this allows full X11 in a jail&lt;/li&gt;
&lt;li&gt;Be sure to check out our &lt;a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener"&gt;jail tutorial and jailed VNC tutorial&lt;/a&gt; for ideas
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;10.0 "Joule Edition" &lt;a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener"&gt;finally released&lt;/a&gt;!&lt;/li&gt;
&lt;li&gt;AMD graphics are now officially supported&lt;/li&gt;
&lt;li&gt;GNOME3, MATE and Cinnamon desktops are available&lt;/li&gt;
&lt;li&gt;Grub updates and fixes&lt;/li&gt;
&lt;li&gt;PCBSD also &lt;a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener"&gt;got a mention in eweek&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener"&gt;Justin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener"&gt;Daniel writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener"&gt;Martin writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt; - &lt;a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener"&gt;unofficial FreeBSD RPI Images&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener"&gt;James writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, security, gpg, gnupg, signed, packages, iso, set, patches, ted unangst, verify, verification, digital signature, ed25519, chacha20, license, debate, gnu, gpl, general public license, copyleft, copyfree, free software, open source, rms, richard stallman, clang, llvm, cddl, linux, gplv2, gplv3, ntp, ntpd, openntpd, isc, network time protocol, server, ssh, openssh, 6.5, foundation, donations, gcm, aes, aes-gcm, hmac, arm, armv7, beaglebone, black, serial, tty, zol, leaseweb, zfsonlinux, ecc</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener">FreeBSD foundation's 2013 fundraising results</a></h3>

<ul>
<li>The FreeBSD foundation finally counted all the money they made in 2013</li>
<li><strong>$768,562 from 1659 donors</strong></li>
<li>Nice little blog post from the team with a giant beastie picture</li>
<li>"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."</li>
<li>A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener">OpenSSH 6.5 released</a></h3>

<ul>
<li>We mentioned the CFT last week, and it's <a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener">finally here</a>!</li>
<li>New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)</li>
<li>Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA</li>
<li>Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes <a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener">can't even attempt to login</a> lol~</li>
<li>New bcrypt private key type, 500,000,000 times harder to brute force</li>
<li>Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one</li>
<li>Portable version <a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261320" rel="nofollow noopener">already in</a> FreeBSD -CURRENT, <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=342618" rel="nofollow noopener">and ports</a></li>
<li>Lots more bugfixes and features, see the full release note or <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">our interview</a> with Damien</li>
<li>Work has already started on 6.6, which <a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener">can be used without OpenSSL</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener">Crazed Ferrets in a Berkeley Shower</a></h3>

<ul>
<li>In 2000, <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a> wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."</li>
<li>This is basically an updated version about why he uses the BSD license, in response to recent <a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener">comments from Richard Stallman</a></li>
<li>Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL</li>
<li>Check out the full post if you're one of those people that gets into license arguments</li>
<li>The takeaway is "BSD is about making the world a better place. For everyone."
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener">OpenBSD on BeagleBone Black</a></h3>

<ul>
<li>Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi</li>
<li>A blog post about installing OpenBSD on a BBB from.. our guest for today!</li>
<li>He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"</li>
<li>It goes through the whole process, details different storage options and some workarounds</li>
<li>Could be a really fun weekend project if you're interested in small or embedded devices
***</li>
</ul>

<h2>Interview - Ted Unangst - <a href="mailto:tedu@openbsd.org" rel="nofollow noopener">tedu@openbsd.org</a> / <a href="https://twitter.com/tedunangst" rel="nofollow noopener">@tedunangst</a></h2>

<p>OpenBSD's <a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener">signify</a> infrastructure, ZFS on OpenBSD</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">Running an NTP server</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener">Getting started with FreeBSD</a></h3>

<ul>
<li>A new video and blog series about starting out with FreeBSD</li>
<li>The author has been a fan since the 90s and has installed it on every server he's worked with</li>
<li>He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users</li>
<li>The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140204080515" rel="nofollow noopener">More OpenBSD hackathon reports</a></h3>

<ul>
<li>As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience</li>
<li>He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work</li>
<li>This summary goes into detail about all the stuff he got done there
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261266" rel="nofollow noopener">X11 in a jail</a></h3>

<ul>
<li>We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!</li>
<li>A new tunable option will let jails access /dev/kmem and similar device nodes</li>
<li>Along with a change to DRM, this allows full X11 in a jail</li>
<li>Be sure to check out our <a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener">jail tutorial and jailed VNC tutorial</a> for ideas
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0 "Joule Edition" <a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener">finally released</a>!</li>
<li>AMD graphics are now officially supported</li>
<li>GNOME3, MATE and Cinnamon desktops are available</li>
<li>Grub updates and fixes</li>
<li>PCBSD also <a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener">got a mention in eweek</a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener">Justin writes in</a></li>
<li><a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener">Alex writes in</a> - <a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener">unofficial FreeBSD RPI Images</a></li>
<li><a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>On this week's episode, we'll be talking with Ted Unangst of the OpenBSD team about their new signing infrastructure. After that, we've got a tutorial on how to run your own NTP server. News, your feedback and even... the winner of our tutorial contest will be announced! So stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/01/freebsd-foundation-announces-2013.html" rel="nofollow noopener">FreeBSD foundation's 2013 fundraising results</a></h3>

<ul>
<li>The FreeBSD foundation finally counted all the money they made in 2013</li>
<li><strong>$768,562 from 1659 donors</strong></li>
<li>Nice little blog post from the team with a giant beastie picture</li>
<li>"We have already started our 2014 fundraising efforts. As of the end of January we are just under $40,000. Our goal is to raise $1,000,000. We are currently finalizing our 2014 budget. We plan to publish both our 2013 financial report and our 2014 budget soon."</li>
<li>A special thanks to all the BSD Now listeners that contributed, the foundation was really glad that we sent some people their way (and they mentioned us on Facebook)
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/032152.html" rel="nofollow noopener">OpenSSH 6.5 released</a></h3>

<ul>
<li>We mentioned the CFT last week, and it's <a href="https://news.ycombinator.com/item?id=7154925" rel="nofollow noopener">finally here</a>!</li>
<li>New key exchange using elliptic-curve Diffie Hellman in Daniel Bernstein's Curve25519 (now the default when both clients support it)</li>
<li>Ed25519 public keys are now available for host keys and user keys, considered more secure than DSA and ECDSA</li>
<li>Funny side effect: if you ONLY enable ed25519 host keys, all the compromised Linux boxes <a href="http://slexy.org/view/s2rI13v8F4" rel="nofollow noopener">can't even attempt to login</a> lol~</li>
<li>New bcrypt private key type, 500,000,000 times harder to brute force</li>
<li>Chacha20-poly1305 transport cipher that builds an encrypted and authenticated stream in one</li>
<li>Portable version <a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261320" rel="nofollow noopener">already in</a> FreeBSD -CURRENT, <a href="https://svnweb.freebsd.org/ports?view=revision&amp;sortby=date&amp;revision=342618" rel="nofollow noopener">and ports</a></li>
<li>Lots more bugfixes and features, see the full release note or <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">our interview</a> with Damien</li>
<li>Work has already started on 6.6, which <a href="https://twitter.com/msfriedl/status/427902493176377344" rel="nofollow noopener">can be used without OpenSSL</a>!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1942" rel="nofollow noopener">Crazed Ferrets in a Berkeley Shower</a></h3>

<ul>
<li>In 2000, <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">MWL</a> wrote an essay for linux.com about why he uses the BSD license: "It’s actually stood up fairly well to the test of time, but it’s fourteen years old now."</li>
<li>This is basically an updated version about why he uses the BSD license, in response to recent <a href="http://gcc.gnu.org/ml/gcc/2014-01/msg00247.html" rel="nofollow noopener">comments from Richard Stallman</a></li>
<li>Very nice post that gives some history about Berkeley, the basics of the BSD-style licenses and their contrast to the GNU GPL</li>
<li>Check out the full post if you're one of those people that gets into license arguments</li>
<li>The takeaway is "BSD is about making the world a better place. For everyone."
***</li>
</ul>

<h3><a href="http://www.tedunangst.com/flak/post/OpenBSD-on-BeagleBone-Black" rel="nofollow noopener">OpenBSD on BeagleBone Black</a></h3>

<ul>
<li>Beaglebone Blacks are cheap little ARM devices similar to a Raspberry Pi</li>
<li>A blog post about installing OpenBSD on a BBB from.. our guest for today!</li>
<li>He describes it as "everything I wish I knew before installing the newly renamed armv7 port on a BeagleBone Black"</li>
<li>It goes through the whole process, details different storage options and some workarounds</li>
<li>Could be a really fun weekend project if you're interested in small or embedded devices
***</li>
</ul>

<h2>Interview - Ted Unangst - <a href="mailto:tedu@openbsd.org" rel="nofollow noopener">tedu@openbsd.org</a> / <a href="https://twitter.com/tedunangst" rel="nofollow noopener">@tedunangst</a></h2>

<p>OpenBSD's <a href="http://www.tedunangst.com/flak/post/signify" rel="nofollow noopener">signify</a> infrastructure, ZFS on OpenBSD</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">Running an NTP server</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://smyck.net/2014/02/01/getting-started-with-freebsd/" rel="nofollow noopener">Getting started with FreeBSD</a></h3>

<ul>
<li>A new video and blog series about starting out with FreeBSD</li>
<li>The author has been a fan since the 90s and has installed it on every server he's worked with</li>
<li>He mentioned some of the advantages of BSD over Linux and how to approach explaining them to new users</li>
<li>The first video is the installation, then he goes on to packages and other topics - 4 videos so far
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140204080515" rel="nofollow noopener">More OpenBSD hackathon reports</a></h3>

<ul>
<li>As a followup to last week, this time Kenneth Westerback writes about his NZ hackathon experience</li>
<li>He arrived with two goals: disklabel fixes for drives with 4k sectors and some dhclient work</li>
<li>This summary goes into detail about all the stuff he got done there
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=261266" rel="nofollow noopener">X11 in a jail</a></h3>

<ul>
<li>We've gotten at least one feedback email about running X in a jail Well.. with this commit, looks like now you can!</li>
<li>A new tunable option will let jails access /dev/kmem and similar device nodes</li>
<li>Along with a change to DRM, this allows full X11 in a jail</li>
<li>Be sure to check out our <a href="http://www.bsdnow.tv/tutorials" rel="nofollow noopener">jail tutorial and jailed VNC tutorial</a> for ideas
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/whoami-im-pc-bsd-10-0-weekly-feature-digest-15/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0 "Joule Edition" <a href="http://blog.pcbsd.org/2014/01/pc-bsd-10-0-release-is-now-available/" rel="nofollow noopener">finally released</a>!</li>
<li>AMD graphics are now officially supported</li>
<li>GNOME3, MATE and Cinnamon desktops are available</li>
<li>Grub updates and fixes</li>
<li>PCBSD also <a href="http://www.eweek.com/enterprise-apps/slideshows/freebsd-open-source-os-comes-to-the-pc-bsd-desktop.html" rel="nofollow noopener">got a mention in eweek</a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s21VnbKZsH" rel="nofollow noopener">Justin writes in</a></li>
<li><a href="http://slexy.org/view/s2nD7RF6bo" rel="nofollow noopener">Daniel writes in</a></li>
<li><a href="http://slexy.org/view/s2jwRrj7UV" rel="nofollow noopener">Martin writes in</a></li>
<li><a href="http://slexy.org/view/s201koMD2c" rel="nofollow noopener">Alex writes in</a> - <a href="http://people.freebsd.org/%7Egjb/RPI/" rel="nofollow noopener">unofficial FreeBSD RPI Images</a></li>
<li><a href="http://slexy.org/view/s2AntZmtRU" rel="nofollow noopener">James writes in</a></li>
<li><a href="http://slexy.org/view/s20bGjMsIQ" rel="nofollow noopener">John writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>21: Tendresse for Ten</title>
  <link>https://www.bsdnow.tv/21</link>
  <guid isPermaLink="false">353e6a60-9bd0-494f-ac34-4337e3dfa734</guid>
  <pubDate>Wed, 22 Jan 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/353e6a60-9bd0-494f-ac34-4337e3dfa734.mp3" length="77103576" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:47:05</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsd.org/releases/10.0R/announce.html" rel="nofollow noopener"&gt;FreeBSD 10.0-RELEASE is out&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The long awaited, giant release of FreeBSD is now official and &lt;a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" rel="nofollow noopener"&gt;ready to be downloaded&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;One of the biggest releases in FreeBSD history, with tons of new updates&lt;/li&gt;
&lt;li&gt;Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... &lt;a href="https://www.freebsd.org/releases/10.0R/relnotes.html" rel="nofollow noopener"&gt;the list goes on and on&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Start up your freebsd-update or do a source-based upgrade
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" rel="nofollow noopener"&gt;OpenSSH 6.5 CFT&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy &lt;a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener"&gt;Damien Miller&lt;/a&gt; announced a Call For Testing for OpenSSH 6.5&lt;/li&gt;
&lt;li&gt;Huge, huge release, focused on new features rather than bugfixes (but it includes those too)&lt;/li&gt;
&lt;li&gt;New ciphers, new key formats, new config options, see the mailing list for all the details&lt;/li&gt;
&lt;li&gt;Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" rel="nofollow noopener"&gt;DIY NAS story, FreeNAS 9.2.1-BETA&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another new blog post about FreeNAS!&lt;/li&gt;
&lt;li&gt;Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014&lt;/li&gt;
&lt;li&gt;"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"&lt;/li&gt;
&lt;li&gt;Really long article with lots of nice details about his setup, why you might want a NAS, etc.&lt;/li&gt;
&lt;li&gt;Speaking of FreeNAS, they released &lt;a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" rel="nofollow noopener"&gt;9.2.1-BETA&lt;/a&gt; with lots of bugfixes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://news.ycombinator.com/item?id=7069889" rel="nofollow noopener"&gt;OpenBSD needed funding for electricity.. and they got it&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Briefly mentioned at the end of last week's show, but has blown up over the internet since&lt;/li&gt;
&lt;li&gt;OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments&lt;/li&gt;
&lt;li&gt;They needed about $20,000 to cover electric costs for the &lt;a href="http://www.openbsd.org/images/rack2009.jpg" rel="nofollow noopener"&gt;server rack in Theo's basement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Lots of positive reaction from the community helping out so far, and it appears they have &lt;a href="http://www.openbsdfoundation.org/campaign2104.html" rel="nofollow noopener"&gt;reached their goal&lt;/a&gt; and got $100,000 in donations&lt;/li&gt;
&lt;li&gt;From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"&lt;/li&gt;
&lt;li&gt;This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Colin Percival - &lt;a href="mailto:cperciva@freebsd.org" rel="nofollow noopener"&gt;cperciva@freebsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/cperciva" rel="nofollow noopener"&gt;@cperciva&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;FreeBSD &lt;a href="http://www.daemonology.net/freebsd-on-ec2/" rel="nofollow noopener"&gt;on Amazon EC2&lt;/a&gt;, backups with &lt;a href="https://www.tarsnap.com/" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;, 10.0-RELEASE, various topics&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" rel="nofollow noopener"&gt;Bandwidth monitoring and testing&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1176" rel="nofollow noopener"&gt;pfSense talk at Tokyo FreeBSD Benkyoukai&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"&lt;/li&gt;
&lt;li&gt;He's also going to be looking for help to translate the pfSense documentation into Japanese&lt;/li&gt;
&lt;li&gt;The event is on February 17, 2014 if you're in the Tokyo area
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://m0n0.ch/wall/downloads.php" rel="nofollow noopener"&gt;m0n0wall 1.8.1 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications&lt;/li&gt;
&lt;li&gt;pfSense was forked from it in 2004, and has a lot more active development now&lt;/li&gt;
&lt;li&gt;They switched to FreeBSD 8.4 for this new version&lt;/li&gt;
&lt;li&gt;Full list of updates in the changelog&lt;/li&gt;
&lt;li&gt;This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blather.michaelwlucas.com/archives/1933" rel="nofollow noopener"&gt;Ansible and PF, plus NTP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another blog post from our buddy &lt;a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener"&gt;Michael Lucas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;There've been some NTP amplification attacks &lt;a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" rel="nofollow noopener"&gt;recently&lt;/a&gt; in the news&lt;/li&gt;
&lt;li&gt;The post describes how he configured ntpd on a lot of servers without a lot of work&lt;/li&gt;
&lt;li&gt;He leverages pf and ansible for the configuration&lt;/li&gt;
&lt;li&gt;OpenNTPD is, not surprisingly, unaffected - use it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140115054839" rel="nofollow noopener"&gt;ruBSD videos online&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Just a quick followup from a few weeks ago&lt;/li&gt;
&lt;li&gt;Theo and Henning's talks from ruBSD are now available for download&lt;/li&gt;
&lt;li&gt;There's also a nice interview with Theo
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;10.0-RC4 images are available&lt;/li&gt;
&lt;li&gt;Wine PBI is now available for 10&lt;/li&gt;
&lt;li&gt;9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2WQXwMASZ" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2H0FURAtZ" rel="nofollow noopener"&gt;Kjell-Aleksander writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21eKKPgqh" rel="nofollow noopener"&gt;Mike writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21UMLnV0G" rel="nofollow noopener"&gt;Charlie writes in (and gets a reply)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2SuazcfoR" rel="nofollow noopener"&gt;Kevin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, ec2, colin percival, cperciva, amazon, cloud, aws, instance, vm, virtual machine, xen, hypervisor, generic, 10.0, in the cloud, custom kernel, tarsnap, backup, backups, encrypted, dropbox, offsite, off site, crashplan, vnstat, iperf, performance, network, sysctl, throughput, speed, download, upload, check, test, freenas, m0n0wall, pfsense, zfs, vfs, tokyo, benkyokai, benkyoukai, ansible, nas, freenas, pf, ntp, openntpd, vulnerability, ntpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/10.0R/announce.html" rel="nofollow noopener">FreeBSD 10.0-RELEASE is out</a></h3>

<ul>
<li>The long awaited, giant release of FreeBSD is now official and <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" rel="nofollow noopener">ready to be downloaded</a></li>
<li>One of the biggest releases in FreeBSD history, with tons of new updates</li>
<li>Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... <a href="https://www.freebsd.org/releases/10.0R/relnotes.html" rel="nofollow noopener">the list goes on and on</a></li>
<li>Start up your freebsd-update or do a source-based upgrade
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" rel="nofollow noopener">OpenSSH 6.5 CFT</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">Damien Miller</a> announced a Call For Testing for OpenSSH 6.5</li>
<li>Huge, huge release, focused on new features rather than bugfixes (but it includes those too)</li>
<li>New ciphers, new key formats, new config options, see the mailing list for all the details</li>
<li>Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" rel="nofollow noopener">DIY NAS story, FreeNAS 9.2.1-BETA</a></h3>

<ul>
<li>Another new blog post about FreeNAS!</li>
<li>Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014</li>
<li>"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"</li>
<li>Really long article with lots of nice details about his setup, why you might want a NAS, etc.</li>
<li>Speaking of FreeNAS, they released <a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" rel="nofollow noopener">9.2.1-BETA</a> with lots of bugfixes
***</li>
</ul>

<h3><a href="https://news.ycombinator.com/item?id=7069889" rel="nofollow noopener">OpenBSD needed funding for electricity.. and they got it</a></h3>

<ul>
<li>Briefly mentioned at the end of last week's show, but has blown up over the internet since</li>
<li>OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments</li>
<li>They needed about $20,000 to cover electric costs for the <a href="http://www.openbsd.org/images/rack2009.jpg" rel="nofollow noopener">server rack in Theo's basement</a></li>
<li>Lots of positive reaction from the community helping out so far, and it appears they have <a href="http://www.openbsdfoundation.org/campaign2104.html" rel="nofollow noopener">reached their goal</a> and got $100,000 in donations</li>
<li>From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"</li>
<li>This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***</li>
</ul>

<h2>Interview - Colin Percival - <a href="mailto:cperciva@freebsd.org" rel="nofollow noopener">cperciva@freebsd.org</a> / <a href="https://twitter.com/cperciva" rel="nofollow noopener">@cperciva</a></h2>

<p>FreeBSD <a href="http://www.daemonology.net/freebsd-on-ec2/" rel="nofollow noopener">on Amazon EC2</a>, backups with <a href="https://www.tarsnap.com/" rel="nofollow noopener">Tarsnap</a>, 10.0-RELEASE, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" rel="nofollow noopener">Bandwidth monitoring and testing</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blog.pfsense.org/?p=1176" rel="nofollow noopener">pfSense talk at Tokyo FreeBSD Benkyoukai</a></h3>

<ul>
<li>Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"</li>
<li>He's also going to be looking for help to translate the pfSense documentation into Japanese</li>
<li>The event is on February 17, 2014 if you're in the Tokyo area
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/downloads.php" rel="nofollow noopener">m0n0wall 1.8.1 released</a></h3>

<ul>
<li>For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications</li>
<li>pfSense was forked from it in 2004, and has a lot more active development now</li>
<li>They switched to FreeBSD 8.4 for this new version</li>
<li>Full list of updates in the changelog</li>
<li>This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1933" rel="nofollow noopener">Ansible and PF, plus NTP</a></h3>

<ul>
<li>Another blog post from our buddy <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">Michael Lucas</a></li>
<li>There've been some NTP amplification attacks <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" rel="nofollow noopener">recently</a> in the news</li>
<li>The post describes how he configured ntpd on a lot of servers without a lot of work</li>
<li>He leverages pf and ansible for the configuration</li>
<li>OpenNTPD is, not surprisingly, unaffected - use it
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140115054839" rel="nofollow noopener">ruBSD videos online</a></h3>

<ul>
<li>Just a quick followup from a few weeks ago</li>
<li>Theo and Henning's talks from ruBSD are now available for download</li>
<li>There's also a nice interview with Theo
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0-RC4 images are available</li>
<li>Wine PBI is now available for 10</li>
<li>9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2WQXwMASZ" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2H0FURAtZ" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s21eKKPgqh" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s21UMLnV0G" rel="nofollow noopener">Charlie writes in (and gets a reply)</a></li>
<li><a href="http://slexy.org/view/s2SuazcfoR" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we've got some great news for OpenBSD, as well as the scoop on FreeBSD 10.0-RELEASE - yes it's finally here! We're gonna talk to Colin Percival about running FreeBSD 10 on EC2 and lots of other interesting stuff. After that, we'll be showing you how to do some bandwidth monitoring and network performance testing in a combo tutorial. We've got a round of your questions and the latest news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsd.org/releases/10.0R/announce.html" rel="nofollow noopener">FreeBSD 10.0-RELEASE is out</a></h3>

<ul>
<li>The long awaited, giant release of FreeBSD is now official and <a href="http://ftp.freebsd.org/pub/FreeBSD/ISO-IMAGES-amd64/10.0/" rel="nofollow noopener">ready to be downloaded</a></li>
<li>One of the biggest releases in FreeBSD history, with tons of new updates</li>
<li>Some features include: LDNS/Unbound replacing BIND, Clang by default (no GCC anymore), native Raspberry Pi support and other ARM improvements, bhyve, hyper-v support, AMD KMS, VirtIO, Xen PVHVM in GENERIC, lots of driver updates, ZFS on root in the installer, SMP patches to pf that drastically improve performance, Netmap support, pkgng by default, wireless stack improvements, a new iSCSI stack, FUSE in the base system... <a href="https://www.freebsd.org/releases/10.0R/relnotes.html" rel="nofollow noopener">the list goes on and on</a></li>
<li>Start up your freebsd-update or do a source-based upgrade
***</li>
</ul>

<h3><a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-January/031987.html" rel="nofollow noopener">OpenSSH 6.5 CFT</a></h3>

<ul>
<li>Our buddy <a href="http://www.bsdnow.tv/episodes/2013_12_18-cryptocrystalline" rel="nofollow noopener">Damien Miller</a> announced a Call For Testing for OpenSSH 6.5</li>
<li>Huge, huge release, focused on new features rather than bugfixes (but it includes those too)</li>
<li>New ciphers, new key formats, new config options, see the mailing list for all the details</li>
<li>Should be in OpenBSD 5.5 in May, look forward to it - but also help test on other platforms!
***</li>
</ul>

<h3><a href="http://blog.brianmoses.net/2014/01/diy-nas-2014-edition.html" rel="nofollow noopener">DIY NAS story, FreeNAS 9.2.1-BETA</a></h3>

<ul>
<li>Another new blog post about FreeNAS!</li>
<li>Instead of updating the older tutorials, the author started fresh and wrote a new one for 2014</li>
<li>"I did briefly consider suggesting nas4free for the EconoNAS blog, since it’s essentially a fork off the FreeNAS tree but may run better on slower hardware, but ultimately I couldn’t recommend anything other than FreeNAS"</li>
<li>Really long article with lots of nice details about his setup, why you might want a NAS, etc.</li>
<li>Speaking of FreeNAS, they released <a href="http://www.freenas.org/whats-new/2014/01/freenas-9-2-1-beta-now-ready-for-download.html" rel="nofollow noopener">9.2.1-BETA</a> with lots of bugfixes
***</li>
</ul>

<h3><a href="https://news.ycombinator.com/item?id=7069889" rel="nofollow noopener">OpenBSD needed funding for electricity.. and they got it</a></h3>

<ul>
<li>Briefly mentioned at the end of last week's show, but has blown up over the internet since</li>
<li>OpenBSD in the headlines of major tech news sites: slashdot, zdnet, the register, hacker news, reddit, twitter.. thousands of comments</li>
<li>They needed about $20,000 to cover electric costs for the <a href="http://www.openbsd.org/images/rack2009.jpg" rel="nofollow noopener">server rack in Theo's basement</a></li>
<li>Lots of positive reaction from the community helping out so far, and it appears they have <a href="http://www.openbsdfoundation.org/campaign2104.html" rel="nofollow noopener">reached their goal</a> and got $100,000 in donations</li>
<li>From Bob Beck: "we have in one week gone from being in a dire situation to having a commitment of approximately $100,000 in donations to the foundation"</li>
<li>This is a shining example of the BSD community coming together, and even the Linux people realizing how critical BSD is to the world at large
***</li>
</ul>

<h2>Interview - Colin Percival - <a href="mailto:cperciva@freebsd.org" rel="nofollow noopener">cperciva@freebsd.org</a> / <a href="https://twitter.com/cperciva" rel="nofollow noopener">@cperciva</a></h2>

<p>FreeBSD <a href="http://www.daemonology.net/freebsd-on-ec2/" rel="nofollow noopener">on Amazon EC2</a>, backups with <a href="https://www.tarsnap.com/" rel="nofollow noopener">Tarsnap</a>, 10.0-RELEASE, various topics</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/vnstat-iperf" rel="nofollow noopener">Bandwidth monitoring and testing</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blog.pfsense.org/?p=1176" rel="nofollow noopener">pfSense talk at Tokyo FreeBSD Benkyoukai</a></h3>

<ul>
<li>Isaac Levy will be presenting "pfSense Practical Experiences: from home routers, to High-Availability Datacenter Deployments"</li>
<li>He's also going to be looking for help to translate the pfSense documentation into Japanese</li>
<li>The event is on February 17, 2014 if you're in the Tokyo area
***</li>
</ul>

<h3><a href="http://m0n0.ch/wall/downloads.php" rel="nofollow noopener">m0n0wall 1.8.1 released</a></h3>

<ul>
<li>For those who don't know, m0n0wall is an older BSD-based firewall OS that's mostly focused on embedded applications</li>
<li>pfSense was forked from it in 2004, and has a lot more active development now</li>
<li>They switched to FreeBSD 8.4 for this new version</li>
<li>Full list of updates in the changelog</li>
<li>This version requires at least 128MB RAM and a disk/CF size of 32MB or more, oh no!
***</li>
</ul>

<h3><a href="http://blather.michaelwlucas.com/archives/1933" rel="nofollow noopener">Ansible and PF, plus NTP</a></h3>

<ul>
<li>Another blog post from our buddy <a href="http://www.bsdnow.tv/episodes/2013_11_06-year_of_the_bsd_desktop" rel="nofollow noopener">Michael Lucas</a></li>
<li>There've been some NTP amplification attacks <a href="https://www.freebsd.org/security/advisories/FreeBSD-SA-14:02.ntpd.asc" rel="nofollow noopener">recently</a> in the news</li>
<li>The post describes how he configured ntpd on a lot of servers without a lot of work</li>
<li>He leverages pf and ansible for the configuration</li>
<li>OpenNTPD is, not surprisingly, unaffected - use it
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140115054839" rel="nofollow noopener">ruBSD videos online</a></h3>

<ul>
<li>Just a quick followup from a few weeks ago</li>
<li>Theo and Henning's talks from ruBSD are now available for download</li>
<li>There's also a nice interview with Theo
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/01/pc-bsd-weekly-feature-digest-5/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>10.0-RC4 images are available</li>
<li>Wine PBI is now available for 10</li>
<li>9.2 systems will now be able to upgrade to version 10 and keep their PBI library
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2WQXwMASZ" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2H0FURAtZ" rel="nofollow noopener">Kjell-Aleksander writes in</a></li>
<li><a href="http://slexy.org/view/s21eKKPgqh" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s21UMLnV0G" rel="nofollow noopener">Charlie writes in (and gets a reply)</a></li>
<li><a href="http://slexy.org/view/s2SuazcfoR" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
