<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>web02.fireside.fm</fireside:hostname>
    <fireside:genDate>Wed, 17 Jun 2026 03:37:37 -0500</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Pcengines”</title>
    <link>https://www.bsdnow.tv/tags/pcengines</link>
    <pubDate>Wed, 08 Jul 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>97: Big Network, SmallWall</title>
  <link>https://www.bsdnow.tv/97</link>
  <guid isPermaLink="false">8ae01f5e-8be5-4cbc-bb95-094f2d536681</guid>
  <pubDate>Wed, 08 Jul 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/8ae01f5e-8be5-4cbc-bb95-094f2d536681.mp3" length="56408980" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:18:20</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener"&gt;BSDCan and pkgsrcCon videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Even more BSDCan 2015 videos are slowly but surely making their way to the internet&lt;/li&gt;
&lt;li&gt;Nigel Williams, &lt;a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener"&gt;Multipath TCP for FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Stephen Bourne, &lt;a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener"&gt;Early days of Unix and design of sh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;John Criswell, &lt;a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener"&gt;Protecting FreeBSD with Secure Virtual Architecture&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Shany Michaely, &lt;a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener"&gt;Expanding RDMA capability over Ethernet in FreeBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;John-Mark Gurney, &lt;a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener"&gt;Adding AES-ICM and AES-GCM to OpenCrypto&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sevan Janiyan, &lt;a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener"&gt;Adventures in building&lt;/a&gt; &lt;a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener"&gt;open source software&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;And finally, &lt;a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener"&gt;the BSDCan 2015 closing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener"&gt;videos&lt;/a&gt; from this year's &lt;a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener"&gt;pkgsrcCon&lt;/a&gt; are also starting to appear online&lt;/li&gt;
&lt;li&gt;Sevan Janiyan, &lt;a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener"&gt;A year of pkgsrc 2014 - 2015&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Pierre Pronchery, &lt;a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener"&gt;pkgsrc meets pkg-ng&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jonathan Perkin, &lt;a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener"&gt;pkgsrc at Joyent&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jörg Sonnenberger, &lt;a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener"&gt;pkg_install script framework&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Benny Siegert, &lt;a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener"&gt;New Features in BulkTracker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener"&gt;OPNsense 15.7 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OPNsense team has released version 15.7, almost exactly six months after &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;their initial debut&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server&lt;/li&gt;
&lt;li&gt;Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140419151959" rel="nofollow noopener"&gt;completely removed&lt;/a&gt; just over a year ago)&lt;/li&gt;
&lt;li&gt;The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed&lt;/li&gt;
&lt;li&gt;Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included&lt;/li&gt;
&lt;li&gt;Shortly afterwards, &lt;a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener"&gt;15.7.1&lt;/a&gt; was released with a few more small fixes
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener"&gt;NetBSD at Open Source Conference 2015 Okinawa&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you liked &lt;a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener"&gt;last week's episode&lt;/a&gt; then you'll probably know what to expect with this one&lt;/li&gt;
&lt;li&gt;The NetBSD users group of Japan hit another open source conference, this time in Okinawa&lt;/li&gt;
&lt;li&gt;This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week&lt;/li&gt;
&lt;li&gt;We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://firstyear.id.au/entry/21" rel="nofollow noopener"&gt;OpenBSD BGP and VRFs&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;"&lt;a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener"&gt;VRFs&lt;/a&gt;, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"&lt;/li&gt;
&lt;li&gt;This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness&lt;/li&gt;
&lt;li&gt;With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them&lt;/li&gt;
&lt;li&gt;The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues&lt;/li&gt;
&lt;li&gt;Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener"&gt;BSDCan talk on rdomains&lt;/a&gt; expands on the subject a bit more if you haven't seen it, as well as a few &lt;a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener"&gt;related&lt;/a&gt; &lt;a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener"&gt;posts&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Lee Sharp - &lt;a href="mailto:lee@smallwall.org" rel="nofollow noopener"&gt;lee@smallwall.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://smallwall.org" rel="nofollow noopener"&gt;SmallWall&lt;/a&gt;, a continuation of m0n0wall&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener"&gt;Solaris adopts more BSD goodies&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes&lt;/li&gt;
&lt;li&gt;They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls&lt;/li&gt;
&lt;li&gt;Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a &lt;a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener"&gt;second blog post&lt;/a&gt; up about their "SunSSH" fork&lt;/li&gt;
&lt;li&gt;Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that&lt;/li&gt;
&lt;li&gt;The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two&lt;/li&gt;
&lt;li&gt;In &lt;a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener"&gt;a third blog post&lt;/a&gt;, they talk about a new system call they're borrowing from OpenBSD, &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener"&gt;getentropy(2)&lt;/a&gt;, as well as the addition of &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener"&gt;arc4random&lt;/a&gt; to their libc&lt;/li&gt;
&lt;li&gt;With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming &lt;em&gt;better than us&lt;/em&gt;?&lt;/li&gt;
&lt;li&gt;Look forward to the upcoming "Solaris Now" podcast &lt;sub&gt;(not really)&lt;/sub&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener"&gt;EuroBSDCon 2015 talks and tutorials&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published&lt;/li&gt;
&lt;li&gt;The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us&lt;/li&gt;
&lt;li&gt;It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course&lt;/li&gt;
&lt;li&gt;There are also &lt;a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener"&gt;a few tutorials&lt;/a&gt; planned for the event, some you've probably seen already and some you haven't&lt;/li&gt;
&lt;li&gt;Registration for the event will be opening very soon (likely this week or next)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener"&gt;Using ZFS replication to improve offsite backups&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data&lt;/li&gt;
&lt;li&gt;This article covers doing just that, but with a focus on making use of the replication capability&lt;/li&gt;
&lt;li&gt;It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it&lt;/li&gt;
&lt;li&gt;Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer&lt;/li&gt;
&lt;li&gt;Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them&lt;/li&gt;
&lt;li&gt;One thing the author didn't mention in his post: having an &lt;strong&gt;offline&lt;/strong&gt; copy of the data, ideally sealed in a safe place, is also important
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener"&gt;Block encryption in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;covered&lt;/a&gt; ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data&lt;/li&gt;
&lt;li&gt;This blog post takes you through the process of creating encrypted &lt;em&gt;containers&lt;/em&gt; in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem&lt;/li&gt;
&lt;li&gt;It goes through creating a file that looks like random data, pointing &lt;strong&gt;vnconfig&lt;/strong&gt; at it, setting up the crypto and finally using it as a fake storage device&lt;/li&gt;
&lt;li&gt;The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/ports?view=revision&amp;amp;revision=391421" rel="nofollow noopener"&gt;Docker hits FreeBSD ports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The inevitable has happened, and an early FreeBSD port of docker is finally here &lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener"&gt;details and directions&lt;/a&gt; are available to read if you'd like to give it a try, as well as a list of which features work and which don't&lt;/li&gt;
&lt;li&gt;There was also some &lt;a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener"&gt;Hacker News discussion&lt;/a&gt; on the topic
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150708134520&amp;amp;mode=flat" rel="nofollow noopener"&gt;Microsoft donates to OpenSSH&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn&lt;/li&gt;
&lt;li&gt;With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor&lt;/li&gt;
&lt;li&gt;They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener"&gt;Joe writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener"&gt;Mike writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener"&gt;Randy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener"&gt;Tony writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener"&gt;Kevin writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, smallwall, m0n0wall, opnsense, pfsense, router, mini-itx, apu, alix, soekris, pcengines, edgerouter, lite, encryption, containers, zfs, replication, docker</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener">BSDCan and pkgsrcCon videos</a></h3>

<ul>
<li>Even more BSDCan 2015 videos are slowly but surely making their way to the internet</li>
<li>Nigel Williams, <a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener">Multipath TCP for FreeBSD</a></li>
<li>Stephen Bourne, <a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener">Early days of Unix and design of sh</a></li>
<li>John Criswell, <a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener">Protecting FreeBSD with Secure Virtual Architecture</a></li>
<li>Shany Michaely, <a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener">Expanding RDMA capability over Ethernet in FreeBSD</a></li>
<li>John-Mark Gurney, <a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener">Adding AES-ICM and AES-GCM to OpenCrypto</a></li>
<li>Sevan Janiyan, <a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener">Adventures in building</a> <a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener">open source software</a></li>
<li>And finally, <a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener">the BSDCan 2015 closing</a></li>
<li>Some <a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener">videos</a> from this year's <a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon</a> are also starting to appear online</li>
<li>Sevan Janiyan, <a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener">A year of pkgsrc 2014 - 2015</a></li>
<li>Pierre Pronchery, <a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener">pkgsrc meets pkg-ng</a></li>
<li>Jonathan Perkin, <a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener">pkgsrc at Joyent</a></li>
<li>Jörg Sonnenberger, <a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener">pkg_install script framework</a></li>
<li>Benny Siegert, <a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener">New Features in BulkTracker</a></li>
<li>This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener">OPNsense 15.7 released</a></h3>

<ul>
<li>The OPNsense team has released version 15.7, almost exactly six months after <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">their initial debut</a></li>
<li>In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server</li>
<li>Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was <a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">completely removed</a> just over a year ago)</li>
<li>The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed</li>
<li>Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included</li>
<li>Shortly afterwards, <a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener">15.7.1</a> was released with a few more small fixes
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Okinawa</a></h3>

<ul>
<li>If you liked <a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener">last week's episode</a> then you'll probably know what to expect with this one</li>
<li>The NetBSD users group of Japan hit another open source conference, this time in Okinawa</li>
<li>This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week</li>
<li>We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***</li>
</ul>

<h3><a href="http://firstyear.id.au/entry/21" rel="nofollow noopener">OpenBSD BGP and VRFs</a></h3>

<ul>
<li>"<a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener">VRFs</a>, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"</li>
<li>This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness</li>
<li>With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them</li>
<li>The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues</li>
<li>Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here</li>
<li>The <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">BSDCan talk on rdomains</a> expands on the subject a bit more if you haven't seen it, as well as a few <a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener">related</a> <a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener">posts</a>
***</li>
</ul>

<h2>Interview - Lee Sharp - <a href="mailto:lee@smallwall.org" rel="nofollow noopener">lee@smallwall.org</a></h2>

<p><a href="http://smallwall.org" rel="nofollow noopener">SmallWall</a>, a continuation of m0n0wall</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener">Solaris adopts more BSD goodies</a></h3>

<ul>
<li>We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes</li>
<li>They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls</li>
<li>Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a <a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener">second blog post</a> up about their "SunSSH" fork</li>
<li>Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that</li>
<li>The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two</li>
<li>In <a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener">a third blog post</a>, they talk about a new system call they're borrowing from OpenBSD, <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener">getentropy(2)</a>, as well as the addition of <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener">arc4random</a> to their libc</li>
<li>With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming <em>better than us</em>?</li>
<li>Look forward to the upcoming "Solaris Now" podcast <sub>(not really)</sub>
***</li>
</ul>

<h3><a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener">EuroBSDCon 2015 talks and tutorials</a></h3>

<ul>
<li>This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published</li>
<li>The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us</li>
<li>It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course</li>
<li>There are also <a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener">a few tutorials</a> planned for the event, some you've probably seen already and some you haven't</li>
<li>Registration for the event will be opening very soon (likely this week or next)
***</li>
</ul>

<h3><a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener">Using ZFS replication to improve offsite backups</a></h3>

<ul>
<li>If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data</li>
<li>This article covers doing just that, but with a focus on making use of the replication capability</li>
<li>It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it</li>
<li>Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer</li>
<li>Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them</li>
<li>One thing the author didn't mention in his post: having an <strong>offline</strong> copy of the data, ideally sealed in a safe place, is also important
***</li>
</ul>

<h3><a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener">Block encryption in OpenBSD</a></h3>

<ul>
<li>We've <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">covered</a> ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data</li>
<li>This blog post takes you through the process of creating encrypted <em>containers</em> in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem</li>
<li>It goes through creating a file that looks like random data, pointing <strong>vnconfig</strong> at it, setting up the crypto and finally using it as a fake storage device</li>
<li>The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=391421" rel="nofollow noopener">Docker hits FreeBSD ports</a></h3>

<ul>
<li>The inevitable has happened, and an early FreeBSD port of docker is finally here </li>
<li>Some <a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener">details and directions</a> are available to read if you'd like to give it a try, as well as a list of which features work and which don't</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener">Hacker News discussion</a> on the topic
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520&amp;mode=flat" rel="nofollow noopener">Microsoft donates to OpenSSH</a></h3>

<ul>
<li>We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn</li>
<li>With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor</li>
<li>They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener">Joe writes in</a></li>
<li><a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener">Tony writes in</a></li>
<li><a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this time on the show, we'll be chatting with Lee Sharp. He's recently revived the m0n0wall codebase, now known as SmallWall, and we'll find out what the future holds for this new addition to the BSD family. Answers to your emails and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.youtube.com/channel/UCAEx6zhR2sD2pAGKezasAjA/videos" rel="nofollow noopener">BSDCan and pkgsrcCon videos</a></h3>

<ul>
<li>Even more BSDCan 2015 videos are slowly but surely making their way to the internet</li>
<li>Nigel Williams, <a href="https://www.youtube.com/watch?v=P3vB_FWtyIs" rel="nofollow noopener">Multipath TCP for FreeBSD</a></li>
<li>Stephen Bourne, <a href="https://www.youtube.com/watch?v=2kEJoWfobpA" rel="nofollow noopener">Early days of Unix and design of sh</a></li>
<li>John Criswell, <a href="https://www.youtube.com/watch?v=hRIC_aF_u24" rel="nofollow noopener">Protecting FreeBSD with Secure Virtual Architecture</a></li>
<li>Shany Michaely, <a href="https://www.youtube.com/watch?v=stsaeKvF3no" rel="nofollow noopener">Expanding RDMA capability over Ethernet in FreeBSD</a></li>
<li>John-Mark Gurney, <a href="https://www.youtube.com/watch?v=JaufZ7yCrLU" rel="nofollow noopener">Adding AES-ICM and AES-GCM to OpenCrypto</a></li>
<li>Sevan Janiyan, <a href="https://www.youtube.com/watch?v=-HMXyzybgdM" rel="nofollow noopener">Adventures in building</a> <a href="https://www.youtube.com/watch?v=Xof-uKnQ6cY" rel="nofollow noopener">open source software</a></li>
<li>And finally, <a href="https://www.youtube.com/watch?v=Ynm0bGnYdfY" rel="nofollow noopener">the BSDCan 2015 closing</a></li>
<li>Some <a href="https://vimeo.com/channels/pkgsrccon/videos" rel="nofollow noopener">videos</a> from this year's <a href="http://pkgsrc.org/pkgsrcCon/2015/" rel="nofollow noopener">pkgsrcCon</a> are also starting to appear online</li>
<li>Sevan Janiyan, <a href="https://vimeo.com/channels/pkgsrccon/132767946" rel="nofollow noopener">A year of pkgsrc 2014 - 2015</a></li>
<li>Pierre Pronchery, <a href="https://vimeo.com/channels/pkgsrccon/132766052" rel="nofollow noopener">pkgsrc meets pkg-ng</a></li>
<li>Jonathan Perkin, <a href="https://vimeo.com/channels/pkgsrccon/132760863" rel="nofollow noopener">pkgsrc at Joyent</a></li>
<li>Jörg Sonnenberger, <a href="https://vimeo.com/channels/pkgsrccon/132757658" rel="nofollow noopener">pkg_install script framework</a></li>
<li>Benny Siegert, <a href="https://vimeo.com/channels/pkgsrccon/132751897" rel="nofollow noopener">New Features in BulkTracker</a></li>
<li>This is the first time we've ever seen recordings from the conference - hopefully they continue this trend
***</li>
</ul>

<h3><a href="https://forum.opnsense.org/index.php?topic=839.0" rel="nofollow noopener">OPNsense 15.7 released</a></h3>

<ul>
<li>The OPNsense team has released version 15.7, almost exactly six months after <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">their initial debut</a></li>
<li>In addition to pulling in the latest security fixes from upstream FreeBSD, 15.7 also includes new integration of an intrusion detection system (and new GUI for it) as well as new blacklisting options for the proxy server</li>
<li>Taking a note from upstream PF's playbook, ALTQ traffic shaping support has finally been retired as of this release (it was deprecated from OpenBSD a few years ago, and the code was <a href="http://undeadly.org/cgi?action=article&amp;sid=20140419151959" rel="nofollow noopener">completely removed</a> just over a year ago)</li>
<li>The LibreSSL flavor has been promoted to production-ready, and users can easily migrate over from OpenSSL via the GUI - switching between the two is simple; no commitment needed</li>
<li>Various third party ports have also been bumped up to their latest versions to keep things fresh, and there's the usual round of bug fixes included</li>
<li>Shortly afterwards, <a href="https://forum.opnsense.org/index.php?topic=915.0" rel="nofollow noopener">15.7.1</a> was released with a few more small fixes
***</li>
</ul>

<h3><a href="https://mail-index.netbsd.org/netbsd-advocacy/2015/07/04/msg000688.html" rel="nofollow noopener">NetBSD at Open Source Conference 2015 Okinawa</a></h3>

<ul>
<li>If you liked <a href="http://www.bsdnow.tv/episodes/2015_07_01-lost_technology" rel="nofollow noopener">last week's episode</a> then you'll probably know what to expect with this one</li>
<li>The NetBSD users group of Japan hit another open source conference, this time in Okinawa</li>
<li>This time, they had a few interesting NetBSD machines on display that we didn't get to see in the interview last week</li>
<li>We'd love to see something like this in North America or Europe too - anyone up for installing BSD on some interesting devices and showing them off at a Linux con?
***</li>
</ul>

<h3><a href="http://firstyear.id.au/entry/21" rel="nofollow noopener">OpenBSD BGP and VRFs</a></h3>

<ul>
<li>"<a href="https://en.wikipedia.org/wiki/Virtual_routing_and_forwarding" rel="nofollow noopener">VRFs</a>, or in OpenBSD rdomains, are a simple, yet powerful (and sometimes confusing) topic"</li>
<li>This article aims to explain both BGP and rdomains, using network diagrams, for some network isolation goodness</li>
<li>With multiple rdomains, it's also possible to have two upstream internet connections, but lock different groups of your internal network to just one of them</li>
<li>The idea of a "guest network" can greatly benefit from this separation as well, even allowing for the same IP ranges to be used without issues</li>
<li>Combining rdomains with the BGP protocol allows for some very selective and precise blocking/passing of traffic between networks, which is also covered in detail here</li>
<li>The <a href="https://www.youtube.com/watch?v=BizrC8Zr-YY" rel="nofollow noopener">BSDCan talk on rdomains</a> expands on the subject a bit more if you haven't seen it, as well as a few <a href="https://www.packetmischief.ca/2011/09/20/virtualizing-the-openbsd-routing-table/" rel="nofollow noopener">related</a> <a href="http://cybermashup.com/2013/05/21/complex-routing-with-openbsd/" rel="nofollow noopener">posts</a>
***</li>
</ul>

<h2>Interview - Lee Sharp - <a href="mailto:lee@smallwall.org" rel="nofollow noopener">lee@smallwall.org</a></h2>

<p><a href="http://smallwall.org" rel="nofollow noopener">SmallWall</a>, a continuation of m0n0wall</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://blogs.oracle.com/solarisfw/entry/pf_for_solaris" rel="nofollow noopener">Solaris adopts more BSD goodies</a></h3>

<ul>
<li>We mentioned a while back that Oracle developers have begun porting a current version of OpenBSD's PF firewall to their next version, even contributing back patches for SMP and other bug fixes</li>
<li>They recently published an article about PF, talking about what's different about it on their platform compared to others - not especially useful for BSD users, but interesting to read if you like firewalls</li>
<li>Darren Moffat, who was part of originally getting an SSH implementation into Solaris, has a <a href="https://blogs.oracle.com/darren/entry/openssh_in_solaris_11_3" rel="nofollow noopener">second blog post</a> up about their "SunSSH" fork</li>
<li>Going forward, their next version is going to offer a completely vanilla OpenSSH option as well, with the plan being to phase out SunSSH after that</li>
<li>The article talks a bit about the history of getting SSH into the OS, forking the code and also lists some of the differences between the two</li>
<li>In <a href="https://blogs.oracle.com/darren/entry/solaris_new_system_calls_getentropy" rel="nofollow noopener">a third blog post</a>, they talk about a new system call they're borrowing from OpenBSD, <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man2/getentropy.2" rel="nofollow noopener">getentropy(2)</a>, as well as the addition of <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man3/arc4random.3" rel="nofollow noopener">arc4random</a> to their libc</li>
<li>With an up-to-date and SMP-capable PF, ZFS with native encryption, jail-like Zones, unaltered OpenSSH and secure entropy calls… is Solaris becoming <em>better than us</em>?</li>
<li>Look forward to the upcoming "Solaris Now" podcast <sub>(not really)</sub>
***</li>
</ul>

<h3><a href="https://2015.eurobsdcon.org/talks/" rel="nofollow noopener">EuroBSDCon 2015 talks and tutorials</a></h3>

<ul>
<li>This year's EuroBSDCon is set to be held in Sweden at the beginning of October, and the preliminary list of accepted presentations has been published</li>
<li>The list looks pretty well-balanced between the different BSDs, something Paul would be happy to see if he was still with us</li>
<li>It even includes an interesting DragonFly talk and a couple talks from NetBSD developers, in addition to plenty of FreeBSD and OpenBSD of course</li>
<li>There are also <a href="https://2015.eurobsdcon.org/tutorials/" rel="nofollow noopener">a few tutorials</a> planned for the event, some you've probably seen already and some you haven't</li>
<li>Registration for the event will be opening very soon (likely this week or next)
***</li>
</ul>

<h3><a href="https://www.iceflatline.com/2015/07/using-zfs-replication-features-in-freebsd-to-improve-my-offsite-backups/" rel="nofollow noopener">Using ZFS replication to improve offsite backups</a></h3>

<ul>
<li>If you take backups seriously, you're probably using ZFS and probably keeping an offsite copy of the data</li>
<li>This article covers doing just that, but with a focus on making use of the replication capability</li>
<li>It'll walk you through taking a snapshot of your pool and then replicating it to another remote system, using "zfs send" and SSH - this has the benefit of only transferring the files that have changed since the last time you did it</li>
<li>Steps are also taken to allow a regular user to take and manage snapshots, so you don't need to be root for the SSH transfer</li>
<li>Data integrity is a long process - filesystem-level checksums, resistance to hardware failure, ECC memory, multiple copies in different locations... they all play a role in keeping your files secure; don't skip out on any of them</li>
<li>One thing the author didn't mention in his post: having an <strong>offline</strong> copy of the data, ideally sealed in a safe place, is also important
***</li>
</ul>

<h3><a href="http://anadoxin.org/blog/blog/20150705/block-encryption-in-openbsd/" rel="nofollow noopener">Block encryption in OpenBSD</a></h3>

<ul>
<li>We've <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">covered</a> ways to do fully-encrypted installations of OpenBSD (and FreeBSD) before, but that requires dedicating a whole drive or partition to the sensitive data</li>
<li>This blog post takes you through the process of creating encrypted <em>containers</em> in OpenBSD, à la TrueCrypt - that is, a file-backed virtual device with an encrypted filesystem</li>
<li>It goes through creating a file that looks like random data, pointing <strong>vnconfig</strong> at it, setting up the crypto and finally using it as a fake storage device</li>
<li>The encrypted container method offers the advantage of being a bit more portable across installations than other ways
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/ports?view=revision&amp;revision=391421" rel="nofollow noopener">Docker hits FreeBSD ports</a></h3>

<ul>
<li>The inevitable has happened, and an early FreeBSD port of docker is finally here </li>
<li>Some <a href="https://github.com/kvasdopil/docker/blob/freebsd-compat/FREEBSD-PORTING.md" rel="nofollow noopener">details and directions</a> are available to read if you'd like to give it a try, as well as a list of which features work and which don't</li>
<li>There was also some <a href="https://news.ycombinator.com/item?id=9840025" rel="nofollow noopener">Hacker News discussion</a> on the topic
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150708134520&amp;mode=flat" rel="nofollow noopener">Microsoft donates to OpenSSH</a></h3>

<ul>
<li>We've talked about big businesses using BSD and contributing back before, even mentioning a few other large public donations - now it's Microsoft's turn</li>
<li>With their recent decision to integrate OpenSSH into an upcoming Windows release, Microsoft has donated a large sum of money to the OpenBSD foundation, making them a gold-level sponsor</li>
<li>They've also posted some contract work offers on the OpenSSH mailing list, and say that their changes will be upstreamed if appropriate - we're always glad to see this
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2NqbhwOoH" rel="nofollow noopener">Joe writes in</a></li>
<li><a href="http://slexy.org/view/s2T3NEia98" rel="nofollow noopener">Mike writes in</a></li>
<li><a href="http://slexy.org/view/s20RlTK6Ha" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2rjCd0bGX" rel="nofollow noopener">Tony writes in</a></li>
<li><a href="http://slexy.org/view/s21PfSIyG5" rel="nofollow noopener">Kevin writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>85: PIE in the Sky</title>
  <link>https://www.bsdnow.tv/85</link>
  <guid isPermaLink="false">7b947cd6-04e4-4210-a3a1-3f80d96ccc79</guid>
  <pubDate>Wed, 15 Apr 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/7b947cd6-04e4-4210-a3a1-3f80d96ccc79.mp3" length="58114516" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener"&gt;Solaris' networking future is with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A curious patch from someone with an Oracle email address was &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142822852613581&amp;amp;w=2" rel="nofollow noopener"&gt;recently sent in&lt;/a&gt; to one of the OpenBSD mailing lists&lt;/li&gt;
&lt;li&gt;It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the &lt;strong&gt;current&lt;/strong&gt; version of PF&lt;/li&gt;
&lt;li&gt;For anyone unfamiliar with the history of PF, it was actually made &lt;em&gt;as a replacement for&lt;/em&gt; IPFilter in OpenBSD, due to some licensing issues&lt;/li&gt;
&lt;li&gt;What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting&lt;/li&gt;
&lt;li&gt;This blog post goes through some of the backstory of the two firewalls&lt;/li&gt;
&lt;li&gt;PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too&lt;/li&gt;
&lt;li&gt;"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"&lt;/li&gt;
&lt;li&gt;You're welcome, Oracle
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener"&gt;BAFUG discussion videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos from their recent meetings&lt;/li&gt;
&lt;li&gt;Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)&lt;/li&gt;
&lt;li&gt;Craig Rodrigues also gave &lt;a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener"&gt;a talk&lt;/a&gt; about Kyua and the FreeBSD testing framework&lt;/li&gt;
&lt;li&gt;Lastly, Kip Macy gave &lt;a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener"&gt;a talk&lt;/a&gt; titled "network stack changes, user-level FreeBSD"&lt;/li&gt;
&lt;li&gt;The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics&lt;/li&gt;
&lt;li&gt;If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener"&gt;More than just a makefile&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux&lt;/li&gt;
&lt;li&gt;This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs&lt;/li&gt;
&lt;li&gt;As it turns out, the ports system really isn't that different from a binary package manager - they are what's &lt;em&gt;used&lt;/em&gt; to create binary packages, after all&lt;/li&gt;
&lt;li&gt;The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream&lt;/li&gt;
&lt;li&gt;After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community&lt;/li&gt;
&lt;li&gt;This post is very long and there's a lot more to it, so check it out (and more discussion &lt;a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt;)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener"&gt;Securing your home fences&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a &lt;a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener"&gt;bad&lt;/a&gt; &lt;a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener"&gt;idea&lt;/a&gt; by now&lt;/li&gt;
&lt;li&gt;We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now&lt;/li&gt;
&lt;li&gt;In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines &lt;a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener"&gt;APU board&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;He notes that you have a lot of options software-wise, including vanilla &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt; or even Linux, but decided to go with OPNsense because of the easy interface and configuration&lt;/li&gt;
&lt;li&gt;The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process&lt;/li&gt;
&lt;li&gt;Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up&lt;/li&gt;
&lt;li&gt;If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)&lt;/li&gt;
&lt;li&gt;We love super-detailed guides like this, so everyone should write more and send them to us immediately
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Pascal Stumpf - &lt;a href="mailto:pascal@openbsd.org" rel="nofollow noopener"&gt;pascal@openbsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Static PIE in OpenBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener"&gt;LLVM's new libFuzzer&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility&lt;/li&gt;
&lt;li&gt;It looks like LLVM is going to have their own fuzzing tool too now&lt;/li&gt;
&lt;li&gt;The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself&lt;/li&gt;
&lt;li&gt;With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener"&gt;HardenedBSD upgrades secadm&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support&lt;/li&gt;
&lt;li&gt;We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)&lt;/li&gt;
&lt;li&gt;Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142877132517229&amp;amp;w=2" rel="nofollow noopener"&gt;RAID5 returns to OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD's &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener"&gt;softraid&lt;/a&gt; subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while&lt;/li&gt;
&lt;li&gt;However, it was exactly that - experimental - and required a recompile to enable&lt;/li&gt;
&lt;li&gt;With some work from recent hackathons, the &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142876943116907&amp;amp;w=2" rel="nofollow noopener"&gt;final piece&lt;/a&gt; was added to enable resuming partial array rebuilds&lt;/li&gt;
&lt;li&gt;Now it's &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877026917030&amp;amp;w=2" rel="nofollow noopener"&gt;on by default&lt;/a&gt;, and there's a call for testing being put out, so grab a snapshot and put the code through its paces&lt;/li&gt;
&lt;li&gt;The bioctl softraid command also &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877223817406&amp;amp;w=2" rel="nofollow noopener"&gt;now supports&lt;/a&gt; DUIDs during pseudo-device detachment, possibly paving the way for the installer to &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142643313416298&amp;amp;w=2" rel="nofollow noopener"&gt;drop&lt;/a&gt; the "do you want to enable DUIDs?" question entirely
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener"&gt;pkgng 1.5.0 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Going back to what we &lt;a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener"&gt;talked about last week&lt;/a&gt;, the final version of pkgng 1.5.0 is out&lt;/li&gt;
&lt;li&gt;The "provides" and "requires" support is finally in a regular release&lt;/li&gt;
&lt;li&gt;A new "-r" switch will allow for direct installation to a chroot or alternate root directory&lt;/li&gt;
&lt;li&gt;Memory usage should be much better now, and some general code speed-ups were added&lt;/li&gt;
&lt;li&gt;This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that&lt;/li&gt;
&lt;li&gt;Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150411160247" rel="nofollow noopener"&gt;p2k15 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work&lt;/li&gt;
&lt;li&gt;As usual, the developers sent in reports of some of the things they got done at the event&lt;/li&gt;
&lt;li&gt;Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit&lt;/li&gt;
&lt;li&gt;Stefan Sperling &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150414064710" rel="nofollow noopener"&gt;wrote in&lt;/a&gt;, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports&lt;/li&gt;
&lt;li&gt;Ken Westerback &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150413163333" rel="nofollow noopener"&gt;also sent in a report&lt;/a&gt;, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener"&gt;Shaun writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener"&gt;Hrishi writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener"&gt;Randy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener"&gt;Zach writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=142884995931428&amp;amp;w=2" rel="nofollow noopener"&gt;Gstreamer hates us&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener"&gt;At least he's honest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener"&gt;I find myself in a situation&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, aslr, pie, position-independent executable, static, binary, dynamic, linking, security, llvm, fuzzing, clang, opnsense, pcengines, apu, alix, hammer2, zfs, oracle, solaris, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>72: Common *Sense Approach</title>
  <link>https://www.bsdnow.tv/72</link>
  <guid isPermaLink="false">efe89103-4a81-4974-89f3-cb650975dace</guid>
  <pubDate>Wed, 14 Jan 2015 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/efe89103-4a81-4974-89f3-cb650975dace.mp3" length="57654580" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be talking to Jos Schellevis about OPNsense, a new firewall project that was forked from pfSense. We'll learn some of the backstory and see what they've got planned for the future. We've also got all this week's news and answers to all your emails, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:04</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be talking to Jos Schellevis about OPNsense, a new firewall project that was forked from pfSense. We'll learn some of the backstory and see what they've got planned for the future. We've also got all this week's news and answers to all your emails, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://networkfilter.blogspot.com/2015/01/be-your-own-vpn-provider-with-openbsd.html" rel="nofollow noopener"&gt;Be your own VPN provider with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've covered how to build a BSD-based gateway that tunnels all your traffic through a VPN in the past - but what if you don't trust any VPN company?&lt;/li&gt;
&lt;li&gt;It's easy for anyone to say "of course we don't run a modified version of OpenVPN that logs all your traffic... what are you talking about?"&lt;/li&gt;
&lt;li&gt;The VPN provider might also be slow to apply security patches, putting you and the rest of the users at risk&lt;/li&gt;
&lt;li&gt;With this guide, you'll be able to cut out the middleman and create your own VPN, using OpenBSD&lt;/li&gt;
&lt;li&gt;It covers topics such as protecting your server, securing DNS lookups, configuring the firewall properly, general security practices and of course actually setting up the VPN
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.iwillfolo.com/2015/01/comparison-gentoo-vs-freebsd-tweak-tweak-little-star/" rel="nofollow noopener"&gt;FreeBSD vs Gentoo comparison&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;People coming over from Linux will sometimes compare FreeBSD to Gentoo, mostly because of the ports-like portage system for installing software&lt;/li&gt;
&lt;li&gt;This article takes that notion and goes much more in-depth, with lots more comparisons between the two systems&lt;/li&gt;
&lt;li&gt;The author mentions that the installers are very different, ports and portage have many subtle differences and a few other things&lt;/li&gt;
&lt;li&gt;If you're a curious Gentoo user considering FreeBSD, this might be a good article to check out to learn a bit more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142120787308107&amp;amp;w=2" rel="nofollow noopener"&gt;Kernel W&lt;sup&gt;X&lt;/sup&gt; in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;W&lt;sup&gt;X,&lt;/sup&gt; "&lt;a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener"&gt;Write XOR Execute&lt;/a&gt;," is a security feature of OpenBSD with a rather strange-looking name&lt;/li&gt;
&lt;li&gt;It's meant to be an exploit mitigation technique, disallowing pages in the address space of a process to be both writable and executable at the same time&lt;/li&gt;
&lt;li&gt;This helps prevent some types of buffer overflows: code injected into it &lt;em&gt;won't&lt;/em&gt; execute, but &lt;em&gt;will&lt;/em&gt; crash the program (quite obviously the lesser of the two evils)&lt;/li&gt;
&lt;li&gt;Through some recent work, OpenBSD's kernel now has no part of the address space without this feature - whereas it was only enabled in the userland &lt;a href="http://www.openbsd.org/papers/ru13-deraadt/" rel="nofollow noopener"&gt;previously&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Doing this incorrectly in the kernel could lead to &lt;strong&gt;far worse&lt;/strong&gt; consequences, and is a lot harder to debug, so this is a pretty huge accomplishment that's been in the works for a while&lt;/li&gt;
&lt;li&gt;More technical details can be found in some &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141917924602780&amp;amp;w=2" rel="nofollow noopener"&gt;recent CVS commits&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;Building an IPFW-based router&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've covered building &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;routers with PF&lt;/a&gt; many times before, but what about &lt;a href="https://www.freebsd.org/doc/handbook/firewalls-ipfw.html" rel="nofollow noopener"&gt;IPFW&lt;/a&gt;?&lt;/li&gt;
&lt;li&gt;A certain host of a certain podcast decided it was finally time to replace his &lt;a href="https://github.com/jduck/asus-cmd" rel="nofollow noopener"&gt;disappointing&lt;/a&gt; consumer router with something BSD-based&lt;/li&gt;
&lt;li&gt;In this blog post, Kris details his experience building and configuring a new router for his home, using IPFW as the firewall&lt;/li&gt;
&lt;li&gt;He covers in-kernel NAT and NATD, installing a DHCP server from packages and even touches on NAT reflection a bit&lt;/li&gt;
&lt;li&gt;If you're an IPFW fan and are thinking about putting together a new router, give this post a read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jos Schellevis - &lt;a href="mailto:project@opnsense.org" rel="nofollow noopener"&gt;project@opnsense.org&lt;/a&gt; / &lt;a href="https://twitter.com/opnsense" rel="nofollow noopener"&gt;@opnsense&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The birth of &lt;a href="http://opnsense.org" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://adrianchadd.blogspot.com/2015/01/on-profiling-http-or-god-damnit-people.html" rel="nofollow noopener"&gt;On profiling HTTP&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Adrian Chadd, who &lt;a href="http://www.bsdnow.tv/episodes/2014_09_17-the_promised_wlan" rel="nofollow noopener"&gt;we've had on the show before&lt;/a&gt;, has been doing some more ultra-high performance testing&lt;/li&gt;
&lt;li&gt;Faced with the problem of how to generate a massive amount of HTTP traffic, he looked into the current state of benchmarking tools&lt;/li&gt;
&lt;li&gt;According to him, it's "not very pretty"&lt;/li&gt;
&lt;li&gt;He decided to work on a new tool to benchmark huge amounts of web traffic, and the rest of this post describes the whole process&lt;/li&gt;
&lt;li&gt;You can check out his new code &lt;a href="https://github.com/erikarn/libevhtp-http/" rel="nofollow noopener"&gt;on Github&lt;/a&gt; right now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://daemonforums.org/showthread.php?s=db0dd79ca26eb645eadd2d8abd267cae&amp;amp;t=8846" rel="nofollow noopener"&gt;Using divert(4) to reduce attacks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We talked about using &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/divert.4" rel="nofollow noopener"&gt;divert(4)&lt;/a&gt; with PF last week, and this post is a good follow-up to that introduction (though unrelated to that series)&lt;/li&gt;
&lt;li&gt;It talks about how you can use divert, combined with some blacklists, to reduce attacks on whatever public services you're running&lt;/li&gt;
&lt;li&gt;PF has good built-in rate limiting for abusive IPs that hit rapidly, but when they attack slowly over a longer period of time, that won't work&lt;/li&gt;
&lt;li&gt;The Composite Blocking List is a public DNS blocklist, operated alongside Spamhaus, that contains many IPs known to be malicious&lt;/li&gt;
&lt;li&gt;Consider setting this up to reduce the attack spam in your logs if you run public services
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046814.html" rel="nofollow noopener"&gt;ChaCha20 patchset for GELI&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A user has posted a patch to the freebsd-hackers list that adds ChaCha support to GELI, the &lt;a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener"&gt;disk encryption&lt;/a&gt; system&lt;/li&gt;
&lt;li&gt;There are also some benchmarks that look pretty good in terms of performance&lt;/li&gt;
&lt;li&gt;Currently, GELI defaults to AES &lt;a href="https://en.wikipedia.org/wiki/Disk_encryption_theory#XEX-based_tweaked-codebook_mode_with_ciphertext_stealing_.28XTS.29" rel="nofollow noopener"&gt;in XTS mode&lt;/a&gt; with a few tweakable options (but also supports Blowfish, Camellia and Triple DES)&lt;/li&gt;
&lt;li&gt;There's &lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046824.html" rel="nofollow noopener"&gt;some discussion&lt;/a&gt; going on about whether a &lt;a href="https://en.wikipedia.org/wiki/Stream_cipher" rel="nofollow noopener"&gt;stream cipher&lt;/a&gt; is &lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046834.html" rel="nofollow noopener"&gt;suitable or not&lt;/a&gt; for disk encryption though, so this might not be a match made in heaven just yet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2015/01/new-update-gui-for-pc-bsd-automatic-updates/" rel="nofollow noopener"&gt;PCBSD update system enhancements&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The PCBSD update utility has gotten an update itself, now supporting automatic upgrades&lt;/li&gt;
&lt;li&gt;You can choose what parts of your system you want to let it automatically handle (packages, security updates)&lt;/li&gt;
&lt;li&gt;The update system uses ZFS and Boot Environments for safe updating and bypasses some dubious pkgng functionality&lt;/li&gt;
&lt;li&gt;There's also a new graphical frontend available for it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2XJhAsffU" rel="nofollow noopener"&gt;Mat writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20qnSHujZ" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21O0MShqi" rel="nofollow noopener"&gt;Andy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2LutVQOXN" rel="nofollow noopener"&gt;Beau writes in&lt;/a&gt; &lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Esexdrc" rel="nofollow noopener"&gt;Kutay writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.mail-archive.com/advocacy@openbsd.org/msg02249.html" rel="nofollow noopener"&gt;Wait, a real one?&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-misc&amp;amp;m=142125454022458&amp;amp;w=2" rel="nofollow noopener"&gt;What's that glowing...&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, bsd, interview, opnsense, pfsense, m0n0wall, firewall, gateway, router, php, fork, deciso, netgate, portage, owncloud, soekris, apu, pcengines, alix, vpn, ipfw</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be talking to Jos Schellevis about OPNsense, a new firewall project that was forked from pfSense. We'll learn some of the backstory and see what they've got planned for the future. We've also got all this week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://networkfilter.blogspot.com/2015/01/be-your-own-vpn-provider-with-openbsd.html" rel="nofollow noopener">Be your own VPN provider with OpenBSD</a></h3>

<ul>
<li>We've covered how to build a BSD-based gateway that tunnels all your traffic through a VPN in the past - but what if you don't trust any VPN company?</li>
<li>It's easy for anyone to say "of course we don't run a modified version of OpenVPN that logs all your traffic... what are you talking about?"</li>
<li>The VPN provider might also be slow to apply security patches, putting you and the rest of the users at risk</li>
<li>With this guide, you'll be able to cut out the middleman and create your own VPN, using OpenBSD</li>
<li>It covers topics such as protecting your server, securing DNS lookups, configuring the firewall properly, general security practices and of course actually setting up the VPN
***</li>
</ul>

<h3><a href="http://www.iwillfolo.com/2015/01/comparison-gentoo-vs-freebsd-tweak-tweak-little-star/" rel="nofollow noopener">FreeBSD vs Gentoo comparison</a></h3>

<ul>
<li>People coming over from Linux will sometimes compare FreeBSD to Gentoo, mostly because of the ports-like portage system for installing software</li>
<li>This article takes that notion and goes much more in-depth, with lots more comparisons between the two systems</li>
<li>The author mentions that the installers are very different, ports and portage have many subtle differences and a few other things</li>
<li>If you're a curious Gentoo user considering FreeBSD, this might be a good article to check out to learn a bit more
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> in OpenBSD</a></h3>

<ul>
<li>W<sup>X,</sup> "<a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener">Write XOR Execute</a>," is a security feature of OpenBSD with a rather strange-looking name</li>
<li>It's meant to be an exploit mitigation technique, disallowing pages in the address space of a process to be both writable and executable at the same time</li>
<li>This helps prevent some types of buffer overflows: code injected into it <em>won't</em> execute, but <em>will</em> crash the program (quite obviously the lesser of the two evils)</li>
<li>Through some recent work, OpenBSD's kernel now has no part of the address space without this feature - whereas it was only enabled in the userland <a href="http://www.openbsd.org/papers/ru13-deraadt/" rel="nofollow noopener">previously</a></li>
<li>Doing this incorrectly in the kernel could lead to <strong>far worse</strong> consequences, and is a lot harder to debug, so this is a pretty huge accomplishment that's been in the works for a while</li>
<li>More technical details can be found in some <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141917924602780&amp;w=2" rel="nofollow noopener">recent CVS commits</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">Building an IPFW-based router</a></h3>

<ul>
<li>We've covered building <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">routers with PF</a> many times before, but what about <a href="https://www.freebsd.org/doc/handbook/firewalls-ipfw.html" rel="nofollow noopener">IPFW</a>?</li>
<li>A certain host of a certain podcast decided it was finally time to replace his <a href="https://github.com/jduck/asus-cmd" rel="nofollow noopener">disappointing</a> consumer router with something BSD-based</li>
<li>In this blog post, Kris details his experience building and configuring a new router for his home, using IPFW as the firewall</li>
<li>He covers in-kernel NAT and NATD, installing a DHCP server from packages and even touches on NAT reflection a bit</li>
<li>If you're an IPFW fan and are thinking about putting together a new router, give this post a read
***</li>
</ul>

<h2>Interview - Jos Schellevis - <a href="mailto:project@opnsense.org" rel="nofollow noopener">project@opnsense.org</a> / <a href="https://twitter.com/opnsense" rel="nofollow noopener">@opnsense</a></h2>

<p>The birth of <a href="http://opnsense.org" rel="nofollow noopener">OPNsense</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://adrianchadd.blogspot.com/2015/01/on-profiling-http-or-god-damnit-people.html" rel="nofollow noopener">On profiling HTTP</a></h3>

<ul>
<li>Adrian Chadd, who <a href="http://www.bsdnow.tv/episodes/2014_09_17-the_promised_wlan" rel="nofollow noopener">we've had on the show before</a>, has been doing some more ultra-high performance testing</li>
<li>Faced with the problem of how to generate a massive amount of HTTP traffic, he looked into the current state of benchmarking tools</li>
<li>According to him, it's "not very pretty"</li>
<li>He decided to work on a new tool to benchmark huge amounts of web traffic, and the rest of this post describes the whole process</li>
<li>You can check out his new code <a href="https://github.com/erikarn/libevhtp-http/" rel="nofollow noopener">on Github</a> right now
***</li>
</ul>

<h3><a href="http://daemonforums.org/showthread.php?s=db0dd79ca26eb645eadd2d8abd267cae&amp;t=8846" rel="nofollow noopener">Using divert(4) to reduce attacks</a></h3>

<ul>
<li>We talked about using <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/divert.4" rel="nofollow noopener">divert(4)</a> with PF last week, and this post is a good follow-up to that introduction (though unrelated to that series)</li>
<li>It talks about how you can use divert, combined with some blacklists, to reduce attacks on whatever public services you're running</li>
<li>PF has good built-in rate limiting for abusive IPs that hit rapidly, but when they attack slowly over a longer period of time, that won't work</li>
<li>The Composite Blocking List is a public DNS blocklist, operated alongside Spamhaus, that contains many IPs known to be malicious</li>
<li>Consider setting this up to reduce the attack spam in your logs if you run public services
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046814.html" rel="nofollow noopener">ChaCha20 patchset for GELI</a></h3>

<ul>
<li>A user has posted a patch to the freebsd-hackers list that adds ChaCha support to GELI, the <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">disk encryption</a> system</li>
<li>There are also some benchmarks that look pretty good in terms of performance</li>
<li>Currently, GELI defaults to AES <a href="https://en.wikipedia.org/wiki/Disk_encryption_theory#XEX-based_tweaked-codebook_mode_with_ciphertext_stealing_.28XTS.29" rel="nofollow noopener">in XTS mode</a> with a few tweakable options (but also supports Blowfish, Camellia and Triple DES)</li>
<li>There's <a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046824.html" rel="nofollow noopener">some discussion</a> going on about whether a <a href="https://en.wikipedia.org/wiki/Stream_cipher" rel="nofollow noopener">stream cipher</a> is <a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046834.html" rel="nofollow noopener">suitable or not</a> for disk encryption though, so this might not be a match made in heaven just yet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/01/new-update-gui-for-pc-bsd-automatic-updates/" rel="nofollow noopener">PCBSD update system enhancements</a></h3>

<ul>
<li>The PCBSD update utility has gotten an update itself, now supporting automatic upgrades</li>
<li>You can choose what parts of your system you want to let it automatically handle (packages, security updates)</li>
<li>The update system uses ZFS and Boot Environments for safe updating and bypasses some dubious pkgng functionality</li>
<li>There's also a new graphical frontend available for it
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2XJhAsffU" rel="nofollow noopener">Mat writes in</a></li>
<li><a href="http://slexy.org/view/s20qnSHujZ" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s21O0MShqi" rel="nofollow noopener">Andy writes in</a></li>
<li><a href="http://slexy.org/view/s2LutVQOXN" rel="nofollow noopener">Beau writes in</a> </li>
<li><a href="http://slexy.org/view/s21Esexdrc" rel="nofollow noopener">Kutay writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.mail-archive.com/advocacy@openbsd.org/msg02249.html" rel="nofollow noopener">Wait, a real one?</a></li>
<li><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142125454022458&amp;w=2" rel="nofollow noopener">What's that glowing...</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be talking to Jos Schellevis about OPNsense, a new firewall project that was forked from pfSense. We'll learn some of the backstory and see what they've got planned for the future. We've also got all this week's news and answers to all your emails, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://networkfilter.blogspot.com/2015/01/be-your-own-vpn-provider-with-openbsd.html" rel="nofollow noopener">Be your own VPN provider with OpenBSD</a></h3>

<ul>
<li>We've covered how to build a BSD-based gateway that tunnels all your traffic through a VPN in the past - but what if you don't trust any VPN company?</li>
<li>It's easy for anyone to say "of course we don't run a modified version of OpenVPN that logs all your traffic... what are you talking about?"</li>
<li>The VPN provider might also be slow to apply security patches, putting you and the rest of the users at risk</li>
<li>With this guide, you'll be able to cut out the middleman and create your own VPN, using OpenBSD</li>
<li>It covers topics such as protecting your server, securing DNS lookups, configuring the firewall properly, general security practices and of course actually setting up the VPN
***</li>
</ul>

<h3><a href="http://www.iwillfolo.com/2015/01/comparison-gentoo-vs-freebsd-tweak-tweak-little-star/" rel="nofollow noopener">FreeBSD vs Gentoo comparison</a></h3>

<ul>
<li>People coming over from Linux will sometimes compare FreeBSD to Gentoo, mostly because of the ports-like portage system for installing software</li>
<li>This article takes that notion and goes much more in-depth, with lots more comparisons between the two systems</li>
<li>The author mentions that the installers are very different, ports and portage have many subtle differences and a few other things</li>
<li>If you're a curious Gentoo user considering FreeBSD, this might be a good article to check out to learn a bit more
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142120787308107&amp;w=2" rel="nofollow noopener">Kernel W<sup>X</sup> in OpenBSD</a></h3>

<ul>
<li>W<sup>X,</sup> "<a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener">Write XOR Execute</a>," is a security feature of OpenBSD with a rather strange-looking name</li>
<li>It's meant to be an exploit mitigation technique, disallowing pages in the address space of a process to be both writable and executable at the same time</li>
<li>This helps prevent some types of buffer overflows: code injected into it <em>won't</em> execute, but <em>will</em> crash the program (quite obviously the lesser of the two evils)</li>
<li>Through some recent work, OpenBSD's kernel now has no part of the address space without this feature - whereas it was only enabled in the userland <a href="http://www.openbsd.org/papers/ru13-deraadt/" rel="nofollow noopener">previously</a></li>
<li>Doing this incorrectly in the kernel could lead to <strong>far worse</strong> consequences, and is a lot harder to debug, so this is a pretty huge accomplishment that's been in the works for a while</li>
<li>More technical details can be found in some <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141917924602780&amp;w=2" rel="nofollow noopener">recent CVS commits</a>
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">Building an IPFW-based router</a></h3>

<ul>
<li>We've covered building <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">routers with PF</a> many times before, but what about <a href="https://www.freebsd.org/doc/handbook/firewalls-ipfw.html" rel="nofollow noopener">IPFW</a>?</li>
<li>A certain host of a certain podcast decided it was finally time to replace his <a href="https://github.com/jduck/asus-cmd" rel="nofollow noopener">disappointing</a> consumer router with something BSD-based</li>
<li>In this blog post, Kris details his experience building and configuring a new router for his home, using IPFW as the firewall</li>
<li>He covers in-kernel NAT and NATD, installing a DHCP server from packages and even touches on NAT reflection a bit</li>
<li>If you're an IPFW fan and are thinking about putting together a new router, give this post a read
***</li>
</ul>

<h2>Interview - Jos Schellevis - <a href="mailto:project@opnsense.org" rel="nofollow noopener">project@opnsense.org</a> / <a href="https://twitter.com/opnsense" rel="nofollow noopener">@opnsense</a></h2>

<p>The birth of <a href="http://opnsense.org" rel="nofollow noopener">OPNsense</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://adrianchadd.blogspot.com/2015/01/on-profiling-http-or-god-damnit-people.html" rel="nofollow noopener">On profiling HTTP</a></h3>

<ul>
<li>Adrian Chadd, who <a href="http://www.bsdnow.tv/episodes/2014_09_17-the_promised_wlan" rel="nofollow noopener">we've had on the show before</a>, has been doing some more ultra-high performance testing</li>
<li>Faced with the problem of how to generate a massive amount of HTTP traffic, he looked into the current state of benchmarking tools</li>
<li>According to him, it's "not very pretty"</li>
<li>He decided to work on a new tool to benchmark huge amounts of web traffic, and the rest of this post describes the whole process</li>
<li>You can check out his new code <a href="https://github.com/erikarn/libevhtp-http/" rel="nofollow noopener">on Github</a> right now
***</li>
</ul>

<h3><a href="http://daemonforums.org/showthread.php?s=db0dd79ca26eb645eadd2d8abd267cae&amp;t=8846" rel="nofollow noopener">Using divert(4) to reduce attacks</a></h3>

<ul>
<li>We talked about using <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/divert.4" rel="nofollow noopener">divert(4)</a> with PF last week, and this post is a good follow-up to that introduction (though unrelated to that series)</li>
<li>It talks about how you can use divert, combined with some blacklists, to reduce attacks on whatever public services you're running</li>
<li>PF has good built-in rate limiting for abusive IPs that hit rapidly, but when they attack slowly over a longer period of time, that won't work</li>
<li>The Composite Blocking List is a public DNS blocklist, operated alongside Spamhaus, that contains many IPs known to be malicious</li>
<li>Consider setting this up to reduce the attack spam in your logs if you run public services
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046814.html" rel="nofollow noopener">ChaCha20 patchset for GELI</a></h3>

<ul>
<li>A user has posted a patch to the freebsd-hackers list that adds ChaCha support to GELI, the <a href="http://www.bsdnow.tv/tutorials/fde" rel="nofollow noopener">disk encryption</a> system</li>
<li>There are also some benchmarks that look pretty good in terms of performance</li>
<li>Currently, GELI defaults to AES <a href="https://en.wikipedia.org/wiki/Disk_encryption_theory#XEX-based_tweaked-codebook_mode_with_ciphertext_stealing_.28XTS.29" rel="nofollow noopener">in XTS mode</a> with a few tweakable options (but also supports Blowfish, Camellia and Triple DES)</li>
<li>There's <a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046824.html" rel="nofollow noopener">some discussion</a> going on about whether a <a href="https://en.wikipedia.org/wiki/Stream_cipher" rel="nofollow noopener">stream cipher</a> is <a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2015-January/046834.html" rel="nofollow noopener">suitable or not</a> for disk encryption though, so this might not be a match made in heaven just yet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2015/01/new-update-gui-for-pc-bsd-automatic-updates/" rel="nofollow noopener">PCBSD update system enhancements</a></h3>

<ul>
<li>The PCBSD update utility has gotten an update itself, now supporting automatic upgrades</li>
<li>You can choose what parts of your system you want to let it automatically handle (packages, security updates)</li>
<li>The update system uses ZFS and Boot Environments for safe updating and bypasses some dubious pkgng functionality</li>
<li>There's also a new graphical frontend available for it
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2XJhAsffU" rel="nofollow noopener">Mat writes in</a></li>
<li><a href="http://slexy.org/view/s20qnSHujZ" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s21O0MShqi" rel="nofollow noopener">Andy writes in</a></li>
<li><a href="http://slexy.org/view/s2LutVQOXN" rel="nofollow noopener">Beau writes in</a> </li>
<li><a href="http://slexy.org/view/s21Esexdrc" rel="nofollow noopener">Kutay writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.mail-archive.com/advocacy@openbsd.org/msg02249.html" rel="nofollow noopener">Wait, a real one?</a></li>
<li><a href="https://www.marc.info/?l=openbsd-misc&amp;m=142125454022458&amp;w=2" rel="nofollow noopener">What's that glowing...</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>66: Conference Connoisseur</title>
  <link>https://www.bsdnow.tv/66</link>
  <guid isPermaLink="false">e76cf015-25d3-4a75-89c3-629d1f6d9a87</guid>
  <pubDate>Wed, 03 Dec 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e76cf015-25d3-4a75-89c3-629d1f6d9a87.mp3" length="59426068" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:22:32</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.meetbsd.com/" rel="nofollow noopener"&gt;More BSD presentation videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch&lt;/li&gt;
&lt;li&gt;Corey Vixie, &lt;a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener"&gt;Web Apps in Embedded BSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Allan Jude, &lt;a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener"&gt;UCL config&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Kip Macy, &lt;a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener"&gt;iflib&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;While we're on the topic of conferences, AsiaBSDCon's CFP was &lt;a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener"&gt;extended&lt;/a&gt; by one week&lt;/li&gt;
&lt;li&gt;This year's &lt;a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener"&gt;ruBSD&lt;/a&gt; will be on December 13th in Moscow&lt;/li&gt;
&lt;li&gt;Also, the &lt;a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener"&gt;BSDCan call for papers&lt;/a&gt; is out, and the event will be in June next year&lt;/li&gt;
&lt;li&gt;Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener"&gt;BSD-powered digital library in Africa&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access&lt;/li&gt;
&lt;li&gt;With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school&lt;/li&gt;
&lt;li&gt;They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)&lt;/li&gt;
&lt;li&gt;The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener"&gt;pfSense 2.2 status update&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update&lt;/li&gt;
&lt;li&gt;2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc&lt;/li&gt;
&lt;li&gt;All these things have taken more time than previously expected&lt;/li&gt;
&lt;li&gt;The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener"&gt;Recommended hardware threads&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A few threads on caught our attention this week, all about hardware recommendations for BSD setups&lt;/li&gt;
&lt;li&gt;In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS&lt;/li&gt;
&lt;li&gt;Everyone gave some good recommendations for low power, Atom-based systems&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.marc.info/?t=141694918800006&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;second thread&lt;/a&gt; started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread&lt;/li&gt;
&lt;li&gt;For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the &lt;a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener"&gt;third&lt;/a&gt; and &lt;a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener"&gt;fourth&lt;/a&gt; threads confirming this&lt;/li&gt;
&lt;li&gt;If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Paul Schenkeveld - &lt;a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener"&gt;freebsd@psconsult.nl&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Running a BSD conference&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener"&gt;From Linux to FreeBSD - for reals&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)&lt;/li&gt;
&lt;li&gt;After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition&lt;/li&gt;
&lt;li&gt;In the comments, a lot of new switchers offer some advice and reading material&lt;/li&gt;
&lt;li&gt;If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener"&gt;Running FreeBSD as a Xen Dom0&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor&lt;/li&gt;
&lt;li&gt;This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it&lt;/li&gt;
&lt;li&gt;Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)&lt;/li&gt;
&lt;li&gt;The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener"&gt;HardenedBSD updates and changes&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;a.out is the old executable format for Unix&lt;/li&gt;
&lt;li&gt;The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968&lt;/li&gt;
&lt;li&gt;FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0&lt;/li&gt;
&lt;li&gt;A restriction against NULL mapping was introduced in &lt;a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener"&gt;FreeBSD 7&lt;/a&gt; and enabled by default in FreeBSD 8&lt;/li&gt;
&lt;li&gt;However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited&lt;/li&gt;
&lt;li&gt;HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’&lt;/li&gt;
&lt;li&gt;Package building update: &lt;a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener"&gt;more consistent repo, no more i386 packages &lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener"&gt;Boris writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt; (&lt;b&gt;edit:&lt;/b&gt; adding "tinker panic 0" to the ntp.conf will disable the sanity check)&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener"&gt;Chris writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener"&gt;Robert writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener"&gt;Jake writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?t=141711266800001&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;Real world authpf use&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;amp;r2=373563&amp;amp;pathrev=373564" rel="nofollow noopener"&gt;The&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener"&gt;great&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener"&gt;perl&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener"&gt;event&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener"&gt;of&lt;/a&gt; &lt;a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener"&gt;2014&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, eurobsdcon, meetbsd, bsdcan, asiabsdcon, conference, community, organization, foundation, pfsense, soekris, router, alix, apu, netgate, pcengines</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">More BSD presentation videos</a></h3>

<ul>
<li>The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch</li>
<li>Corey Vixie, <a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener">Web Apps in Embedded BSD</a></li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener">UCL config</a></li>
<li>Kip Macy, <a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener">iflib</a></li>
<li>While we're on the topic of conferences, AsiaBSDCon's CFP was <a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener">extended</a> by one week</li>
<li>This year's <a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener">ruBSD</a> will be on December 13th in Moscow</li>
<li>Also, the <a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener">BSDCan call for papers</a> is out, and the event will be in June next year</li>
<li>Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***</li>
</ul>

<h3><a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener">BSD-powered digital library in Africa</a></h3>

<ul>
<li>You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access</li>
<li>With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school</li>
<li>They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)</li>
<li>The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener">pfSense 2.2 status update</a></h3>

<ul>
<li>With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update</li>
<li>2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc</li>
<li>All these things have taken more time than previously expected</li>
<li>The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener">Recommended hardware threads</a></h3>

<ul>
<li>A few threads on caught our attention this week, all about hardware recommendations for BSD setups</li>
<li>In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS</li>
<li>Everyone gave some good recommendations for low power, Atom-based systems</li>
<li>The <a href="https://www.marc.info/?t=141694918800006&amp;r=1&amp;w=2" rel="nofollow noopener">second thread</a> started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread</li>
<li>For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the <a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener">third</a> and <a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener">fourth</a> threads confirming this</li>
<li>If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***</li>
</ul>

<h2>Interview - Paul Schenkeveld - <a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener">freebsd@psconsult.nl</a></h2>

<p>Running a BSD conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener">From Linux to FreeBSD - for reals</a></h3>

<ul>
<li>Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)</li>
<li>After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition</li>
<li>In the comments, a lot of new switchers offer some advice and reading material</li>
<li>If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***</li>
</ul>

<h3><a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener">Running FreeBSD as a Xen Dom0</a></h3>

<ul>
<li>Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor</li>
<li>This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it</li>
<li>Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)</li>
<li>The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener">HardenedBSD updates and changes</a></h3>

<ul>
<li>a.out is the old executable format for Unix</li>
<li>The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968</li>
<li>FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0</li>
<li>A restriction against NULL mapping was introduced in <a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener">FreeBSD 7</a> and enabled by default in FreeBSD 8</li>
<li>However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited</li>
<li>HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’</li>
<li>Package building update: <a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener">more consistent repo, no more i386 packages </a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener">Boris writes in</a></li>
<li><a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener">Alex writes in</a> (<b>edit:</b> adding "tinker panic 0" to the ntp.conf will disable the sanity check)</li>
<li><a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener">Jake writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141711266800001&amp;r=1&amp;w=2" rel="nofollow noopener">Real world authpf use</a></li>
<li><a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;r2=373563&amp;pathrev=373564" rel="nofollow noopener">The</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener">great</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener">perl</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener">event</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener">of</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener">2014</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be talking with Paul Schenkeveld, chairman of the EuroBSDCon foundation. He tells us about his experiences running BSD conferences and how regular users can get involved too. We've also got answers to all your emails and the latest news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.meetbsd.com/" rel="nofollow noopener">More BSD presentation videos</a></h3>

<ul>
<li>The MeetBSD video uploading spree continues with a few more talks, maybe this'll be the last batch</li>
<li>Corey Vixie, <a href="https://www.youtube.com/watch?v=Pbks12Mqpp8" rel="nofollow noopener">Web Apps in Embedded BSD</a></li>
<li>Allan Jude, <a href="https://www.youtube.com/watch?v=TjP86iWsEzQ" rel="nofollow noopener">UCL config</a></li>
<li>Kip Macy, <a href="https://www.youtube.com/watch?v=P4FRPKj7F80" rel="nofollow noopener">iflib</a></li>
<li>While we're on the topic of conferences, AsiaBSDCon's CFP was <a href="https://twitter.com/asiabsdcon/status/538352055245492226" rel="nofollow noopener">extended</a> by one week</li>
<li>This year's <a href="https://events.yandex.ru/events/yagosti/rubsd14/" rel="nofollow noopener">ruBSD</a> will be on December 13th in Moscow</li>
<li>Also, the <a href="http://lists.bsdcan.org/pipermail/bsdcan-announce/2014-December/000135.html" rel="nofollow noopener">BSDCan call for papers</a> is out, and the event will be in June next year</li>
<li>Lastly, according to Rick Miller, "A potential vBSDcon 2015 event is being explored though a decision has yet to be made."
***</li>
</ul>

<h3><a href="http://peercorpsglobal.org/nzegas-digital-library-becomes-a-reality/" rel="nofollow noopener">BSD-powered digital library in Africa</a></h3>

<ul>
<li>You probably haven't heard much about Nzega, Tanzania, but it's an East African country without much internet access</li>
<li>With physical schoolbooks being a rarity there, a few companies helped out to bring some BSD-powered reading material to a local school</li>
<li>They now have a pair of FreeNAS Minis at the center of their local network, with over 80,000 books and accompanying video content stored on them (~5TB of data currently)</li>
<li>The school's workstations also got wiped and reloaded with FreeBSD, and everyone there seems to really enjoy using it
***</li>
</ul>

<h3><a href="https://blog.pfsense.org/?p=1486" rel="nofollow noopener">pfSense 2.2 status update</a></h3>

<ul>
<li>With lots of people asking when the 2.2 release will be done, some pfSense developers decided to provide a status update</li>
<li>2.2 will have a lot of changes: being based on FreeBSD 10.1, Unbound instead of BIND, updating PHP to something recent, including the new(ish) IPSEC stack updates, etc</li>
<li>All these things have taken more time than previously expected</li>
<li>The post also has some interesting graphs showing the ratio of opened and close bugs for the upcoming release
***</li>
</ul>

<h3><a href="https://www.reddit.com/r/BSD/comments/2n8wrg/bsd_on_mini_itx/" rel="nofollow noopener">Recommended hardware threads</a></h3>

<ul>
<li>A few threads on caught our attention this week, all about hardware recommendations for BSD setups</li>
<li>In the first one, the OP asks about mini-ITX hardware to run a FreeBSD server and NAS</li>
<li>Everyone gave some good recommendations for low power, Atom-based systems</li>
<li>The <a href="https://www.marc.info/?t=141694918800006&amp;r=1&amp;w=2" rel="nofollow noopener">second thread</a> started off asking about which CPU architecture is best for PF on an OpenBSD router, but ended up being another hardware thread</li>
<li>For a router, the ALIX, APU and Soekris boards still seem to be the most popular choices, with the <a href="https://www.reddit.com/r/homelab/comments/24m6tj/" rel="nofollow noopener">third</a> and <a href="https://www.reddit.com/r/PFSENSE/comments/2nblgp/" rel="nofollow noopener">fourth</a> threads confirming this</li>
<li>If you're thinking about building your first BSD box - server, router, NAS, whatever - these might be some good links to read
***</li>
</ul>

<h2>Interview - Paul Schenkeveld - <a href="mailto:freebsd@psconsult.nl" rel="nofollow noopener">freebsd@psconsult.nl</a></h2>

<p>Running a BSD conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.reddit.com/r/freebsd/comments/2nqa60/" rel="nofollow noopener">From Linux to FreeBSD - for reals</a></h3>

<ul>
<li>Another Linux user is ready to switch to BSD, and takes to Reddit for some community encouragement (seems to be a common thing now)</li>
<li>After being a Linux guy for 20(!) years, he's ready to switch his systems over, and is looking for some helpful guides to transition</li>
<li>In the comments, a lot of new switchers offer some advice and reading material</li>
<li>If any of the listeners have some things that were helpful along your switching journey, maybe send 'em this guy's way
***</li>
</ul>

<h3><a href="http://wiki.xenproject.org/wiki/FreeBSD_Dom0" rel="nofollow noopener">Running FreeBSD as a Xen Dom0</a></h3>

<ul>
<li>Continuing progress has been made to allow FreeBSD to be a host for the Xen hypervisor</li>
<li>This wiki article explains how to run the Xen branch of FreeBSD and host virtual machines on it</li>
<li>Xen on FreeBSD currently supports PV guests (modified kernels) and HVM (unmodified kernels, uses hardware virtualization features)</li>
<li>The wiki provides instructions for running Debian (PV) and FreeBSD (HVM), and discusses the features that are not finished yet
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2014-11-18/aout-and-null-mapping-support-removal" rel="nofollow noopener">HardenedBSD updates and changes</a></h3>

<ul>
<li>a.out is the old executable format for Unix</li>
<li>The name stands for assembler output, and was coined by Ken Thompson as the fixed name for output of his PDP-7 assembler in 1968</li>
<li>FreeBSD, on which HardenedBSD is based, switched away from a.out in version 3.0</li>
<li>A restriction against NULL mapping was introduced in <a href="https://www.freebsd.org/security/advisories/FreeBSD-EN-09:05.null.asc" rel="nofollow noopener">FreeBSD 7</a> and enabled by default in FreeBSD 8</li>
<li>However, for reasons of compatibility, it could be switched off, allowing buggy applications to continue to run, at the risk of allowing a kernel bug to be exploited</li>
<li>HardenedBSD has removed the sysctl, making it impossible to run in ‘insecure mode’</li>
<li>Package building update: <a href="http://hardenedbsd.org/article/shawn-webb/2014-11-30/package-building-infrastructure-maintenance" rel="nofollow noopener">more consistent repo, no more i386 packages </a>
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2kVPKICqj" rel="nofollow noopener">Boris writes in</a></li>
<li><a href="http://slexy.org/view/s21Fic4dZC" rel="nofollow noopener">Alex writes in</a> (<b>edit:</b> adding "tinker panic 0" to the ntp.conf will disable the sanity check)</li>
<li><a href="http://slexy.org/view/s2zk1Tvfe9" rel="nofollow noopener">Chris writes in</a></li>
<li><a href="http://slexy.org/view/s22alvJ4mu" rel="nofollow noopener">Robert writes in</a></li>
<li><a href="http://slexy.org/view/s203YMc2zL" rel="nofollow noopener">Jake writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?t=141711266800001&amp;r=1&amp;w=2" rel="nofollow noopener">Real world authpf use</a></li>
<li><a href="https://svnweb.freebsd.org/ports/head/UPDATING?r1=373564&amp;r2=373563&amp;pathrev=373564" rel="nofollow noopener">The</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096788.html" rel="nofollow noopener">great</a> <a href="https://lists.freebsd.org/pipermail/freebsd-ports/2014-November/096799.html" rel="nofollow noopener">perl</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010146.html" rel="nofollow noopener">event</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010149.html" rel="nofollow noopener">of</a> <a href="https://lists.freebsd.org/pipermail/freebsd-perl/2014-November/010167.html" rel="nofollow noopener">2014</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
