<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app03</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 08:05:13 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Recording”</title>
    <link>https://www.bsdnow.tv/tags/recording</link>
    <pubDate>Wed, 06 Aug 2014 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>49: The PC-BSD Tour</title>
  <link>https://www.bsdnow.tv/49</link>
  <guid isPermaLink="false">ccc19842-ae62-43a9-8f82-44f3f281de42</guid>
  <pubDate>Wed, 06 Aug 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/ccc19842-ae62-43a9-8f82-44f3f281de42.mp3" length="59661652" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:22:51</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener"&gt;FreeBSD foundation semi-annual newsletter&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation&lt;/li&gt;
&lt;li&gt;"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"&lt;/li&gt;
&lt;li&gt;It talks about the &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;FreeBSD journal&lt;/a&gt; as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT&lt;/li&gt;
&lt;li&gt;The full list of funded projects is included, also with details in the financial reports&lt;/li&gt;
&lt;li&gt;There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, intel nuc, nuc, gui, ssl, tls, libressl, openssl, foundation, bafug, talk, presentation, recording, bhyve, libvirt, rss, netmap, opensmtpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation</li>
<li>"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"</li>
<li>It talks about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD journal</a> as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT</li>
<li>The full list of funded projects is included, also with details in the financial reports</li>
<li>There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>Coming up this week on the show, we've got something special for you! We'll be giving you an in-depth look at all of the graphical PC-BSD utilities. That's right, BSD doesn't have to be commandline-only anymore! There's also the usual round of answers to your emails and all the latest headlines, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.freebsdfoundation.org/press/2014jul-newsletter" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation published their semi-annual newsletter, complete with a letter from the president of the foundation</li>
<li>"In fact after reading [the president's] letter, I was motivated to come up with my own elevator pitch instead of the usual FreeBSD is like Linux, only better!"</li>
<li>It talks about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD journal</a> as being one of the most exciting things they've launched this year, conferences they funded and various bits of sponsored code that went into -CURRENT</li>
<li>The full list of funded projects is included, also with details in the financial reports</li>
<li>There are also a number of conference wrap-ups: NYCBSDCon, BSDCan, AsiaBSDCon and details about the upcoming EuroBSDCon</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>33: Certified Package Delivery</title>
  <link>https://www.bsdnow.tv/33</link>
  <guid isPermaLink="false">f0c15113-8ade-464b-a89f-3398734256dc</guid>
  <pubDate>Wed, 16 Apr 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/f0c15113-8ade-464b-a89f-3398734256dc.mp3" length="57837748" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:19</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener"&gt;BSDCan schedule, speakers and talks&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This year's BSDCan will kick off on May 14th in Ottawa&lt;/li&gt;
&lt;li&gt;The &lt;a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener"&gt;list of speakers&lt;/a&gt; is also out&lt;/li&gt;
&lt;li&gt;And finally &lt;a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener"&gt;the talks&lt;/a&gt; everyone's looking forward to&lt;/li&gt;
&lt;li&gt;Lots of great tutorials and talks, spanning a wide range of topics of interest&lt;/li&gt;
&lt;li&gt;Be sure to come by so you can and meet Allan and Kris in person &lt;a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener"&gt;and get BSDCan shirts&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener"&gt;NYCBSDCon talks uploaded&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon&lt;/li&gt;
&lt;li&gt;Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener"&gt;Dru Lavigne's talk&lt;/a&gt;, "ZFS Management Tools in FreeNAS and PC-BSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener"&gt;Scott Long's talk&lt;/a&gt;, "Serving one third of the Internet via FreeBSD"&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener"&gt;Michael W. Lucas' talk&lt;/a&gt;, "BSD Breaking Barriers"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener"&gt;FreeBSD Journal, issue 2&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The bi-monthly FreeBSD journal's second issue is out&lt;/li&gt;
&lt;li&gt;Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates&lt;/li&gt;
&lt;li&gt;In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc&lt;/li&gt;
&lt;li&gt;"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"&lt;/li&gt;
&lt;li&gt;Check &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;our interview with GNN&lt;/a&gt; for more information about the journal
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener"&gt;OpenSSL, more like OpenSS-Hell&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy&lt;/li&gt;
&lt;li&gt;There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so&lt;/li&gt;
&lt;li&gt;We finally have &lt;a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener"&gt;a timeline of events&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Reactions from &lt;a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener"&gt;ISC&lt;/a&gt;, &lt;a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener"&gt;PCBSD&lt;/a&gt;, &lt;a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener"&gt;Tarsnap&lt;/a&gt;, the &lt;a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener"&gt;Tor&lt;/a&gt; &lt;a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener"&gt;project&lt;/a&gt;, &lt;a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener"&gt;NetBSD&lt;/a&gt;, &lt;a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener"&gt;oss-sec&lt;/a&gt;, &lt;a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener"&gt;PHK&lt;/a&gt;, &lt;a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener"&gt;Varnish&lt;/a&gt; and &lt;a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener"&gt;Akamai&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener"&gt;pfSense&lt;/a&gt; released &lt;a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener"&gt;a new version to fix it&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;OpenBSD &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139715336230455&amp;amp;w=2" rel="nofollow noopener"&gt;disabled heartbeat entirely&lt;/a&gt; and is very &lt;a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener"&gt;unforgiving of the IETF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;Ted Unangst&lt;/a&gt; has two &lt;a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener"&gt;good&lt;/a&gt; &lt;a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener"&gt;write-ups&lt;/a&gt; about the issue and how horrible the OpenSSL codebase is&lt;/li&gt;
&lt;li&gt;A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"&lt;/li&gt;
&lt;li&gt;Sounds like &lt;a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener"&gt;someone else&lt;/a&gt; was having fun with the bug for a while too&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;There's also another OpenSSL bug&lt;/strong&gt; that &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139732441810737&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD patched&lt;/a&gt; - it allows an attacker to &lt;strong&gt;inject data from one connection into another&lt;/strong&gt; &lt;/li&gt;
&lt;li&gt;OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140415093252" rel="nofollow noopener"&gt;seeing a fork&lt;/a&gt; in real time
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Jim Brown - &lt;a href="mailto:info@bsdcertification.org" rel="nofollow noopener"&gt;info@bsdcertification.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;The &lt;a href="http://bsdcertification.org/" rel="nofollow noopener"&gt;BSD Certification&lt;/a&gt; exams&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener"&gt;Building OpenBSD binary packages in bulk&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/aperezdc/signify" rel="nofollow noopener"&gt;Portable signify&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Back in &lt;a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener"&gt;episode 23&lt;/a&gt; we talked with Ted Unangst about the new "signify" tool in OpenBSD&lt;/li&gt;
&lt;li&gt;Now there's a (completely unofficial) portable version of it on github&lt;/li&gt;
&lt;li&gt;If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it&lt;/li&gt;
&lt;li&gt;Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener"&gt;Foundation goals and updates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The OpenBSD foundation has reached their 2014 goal of $150,000&lt;/li&gt;
&lt;li&gt;You can check &lt;a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener"&gt;their activities and goals&lt;/a&gt; to see where the money is going&lt;/li&gt;
&lt;li&gt;Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data&lt;/li&gt;
&lt;li&gt;The FreeBSD foundation has kicked off their &lt;a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener"&gt;spring fundraising&lt;/a&gt; campaign&lt;/li&gt;
&lt;li&gt;There's also a list of their activities and goals available to read through&lt;/li&gt;
&lt;li&gt;Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;New PBI runtime that fixes stability issues and decreases load times&lt;/li&gt;
&lt;li&gt;"Update Center" is getting a lot of development and improvements&lt;/li&gt;
&lt;li&gt;Lots of misc. bug fixes and updates
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener"&gt;There's a reddit thread&lt;/a&gt; we wanted to highlight - a user wants to show his friend BSD and why it's great&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener"&gt;Brad writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener"&gt;Sha'ul writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener"&gt;iGibbs writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener"&gt;Matt writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, dpb, distributed ports builder, marc espie, poudriere, package builds, jim brown, bsdcertification, bsd certification, exam, test, openssl, heartbleed, exploit, ssl, tls, heartbeat, openssh, theo de raadt, hole, 0day, zero day, bsdcan, nycbsdcon, presentations, talks, conference, recording, netflix, tarsnap, mitigation, ixsystems, foundation, journal, cve</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week, we sit down with Jim Brown from the BSD Certification group to talk about the BSD exams. Following that, we'll be showing you how to build OpenBSD binary packages in bulk, a la poudriere. There's a boatload of news and we've got answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.bsdcan.org/2014/schedule/" rel="nofollow noopener">BSDCan schedule, speakers and talks</a></h3>

<ul>
<li>This year's BSDCan will kick off on May 14th in Ottawa</li>
<li>The <a href="https://www.bsdcan.org/2014/schedule/speakers.en.html" rel="nofollow noopener">list of speakers</a> is also out</li>
<li>And finally <a href="https://www.bsdcan.org/2014/schedule/events.en.html" rel="nofollow noopener">the talks</a> everyone's looking forward to</li>
<li>Lots of great tutorials and talks, spanning a wide range of topics of interest</li>
<li>Be sure to come by so you can and meet Allan and Kris in person <a href="https://twitter.com/bsdcan/status/454990067552247808" rel="nofollow noopener">and get BSDCan shirts</a>
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=4bPduH6O7lI" rel="nofollow noopener">NYCBSDCon talks uploaded</a></h3>

<ul>
<li>The BSD TV YouTube channel has been uploading recordings from the 2014 NYCBSDCon</li>
<li>Jeff Rizzo's talk, "Releasing NetBSD: So Many Targets, So Little Time"</li>
<li><a href="https://www.youtube.com/watch?v=DAmZ3cbfigA" rel="nofollow noopener">Dru Lavigne's talk</a>, "ZFS Management Tools in FreeNAS and PC-BSD"</li>
<li><a href="https://www.youtube.com/watch?v=FL5U4wr86L4" rel="nofollow noopener">Scott Long's talk</a>, "Serving one third of the Internet via FreeBSD"</li>
<li><a href="https://www.youtube.com/watch?v=buo5JlMnGPI" rel="nofollow noopener">Michael W. Lucas' talk</a>, "BSD Breaking Barriers"
***</li>
</ul>

<h3><a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-journal-issue-2-is-now-available.html" rel="nofollow noopener">FreeBSD Journal, issue 2</a></h3>

<ul>
<li>The bi-monthly FreeBSD journal's second issue is out</li>
<li>Topics in this issue include pkg, poudriere, the PBI format, hwpmc and journaled soft-updates</li>
<li>In less than two months, they've already gotten over 1000 subscribers! It's available on Google Play, iTunes, Amazon, etc</li>
<li>"We are also working on a dynamic version of the magazine that can be read in many web browsers, including those that run on FreeBSD"</li>
<li>Check <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">our interview with GNN</a> for more information about the journal
***</li>
</ul>

<h3><a href="http://bsd.slashdot.org/story/200567" rel="nofollow noopener">OpenSSL, more like OpenSS-Hell</a></h3>

<ul>
<li>We mentioned this huge OpenSSL bug last week during all the chaos, but the aftermath is just as messy</li>
<li>There's been a pretty vicious response from security experts all across the internet and in all of the BSD projects - and rightfully so</li>
<li>We finally have <a href="http://www.smh.com.au/it-pro/security-it/heartbleed-disclosure-timeline-who-knew-what-and-when-20140414-zqurk.html" rel="nofollow noopener">a timeline of events</a></li>
<li>Reactions from <a href="https://isc.sans.edu/diary/Testing+for+Heartbleed/17933" rel="nofollow noopener">ISC</a>, <a href="http://blog.pcbsd.org/2014/04/openssl-security-update/" rel="nofollow noopener">PCBSD</a>, <a href="http://www.daemonology.net/blog/2014-04-09-tarsnap-no-heartbleed-here.html" rel="nofollow noopener">Tarsnap</a>, the <a href="https://lists.torproject.org/pipermail/tor-talk/2014-April/thread.html" rel="nofollow noopener">Tor</a> <a href="https://lists.torproject.org/pipermail/tor-relays/2014-April/thread.html" rel="nofollow noopener">project</a>, <a href="https://lists.freebsd.org/pipermail/freebsd-security/2014-April/thread.html" rel="nofollow noopener">FreeBSD</a>, <a href="http://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2014-004.txt.asc" rel="nofollow noopener">NetBSD</a>, <a href="http://seclists.org/oss-sec/2014/q2/index.html" rel="nofollow noopener">oss-sec</a>, <a href="https://queue.acm.org/detail.cfm?id=2602816" rel="nofollow noopener">PHK</a>, <a href="https://www.varnish-cache.org/docs/trunk/phk/dough.html" rel="nofollow noopener">Varnish</a> and <a href="https://blogs.akamai.com/2014/04/heartbleed-update.html" rel="nofollow noopener">Akamai</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_19-a_sixth_pfsense" rel="nofollow noopener">pfSense</a> released <a href="https://blog.pfsense.org/?p=1253" rel="nofollow noopener">a new version to fix it</a></li>
<li>OpenBSD <a href="http://marc.info/?l=openbsd-cvs&amp;m=139715336230455&amp;w=2" rel="nofollow noopener">disabled heartbeat entirely</a> and is very <a href="https://news.ycombinator.com/item?id=7568921" rel="nofollow noopener">unforgiving of the IETF</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">Ted Unangst</a> has two <a href="http://www.tedunangst.com/flak/post/heartbleed-vs-mallocconf" rel="nofollow noopener">good</a> <a href="http://www.tedunangst.com/flak/post/analysis-of-openssl-freelist-reuse" rel="nofollow noopener">write-ups</a> about the issue and how horrible the OpenSSL codebase is</li>
<li>A nice quote from one of the OpenBSD lists: "Given how trivial one-liner fixes such as #2569 have remained unfixed for 2.5+ years, one can only assume that OpenSSL's bug tracker is only used to park bugs, not fix them"</li>
<li>Sounds like <a href="http://www.bloomberg.com/news/2014-04-11/nsa-said-to-have-used-heartbleed-bug-exposing-consumers.html" rel="nofollow noopener">someone else</a> was having fun with the bug for a while too</li>
<li><strong>There's also another OpenSSL bug</strong> that <a href="http://marc.info/?l=openbsd-cvs&amp;m=139732441810737&amp;w=2" rel="nofollow noopener">OpenBSD patched</a> - it allows an attacker to <strong>inject data from one connection into another</strong> </li>
<li>OpenBSD has also imported the most current version of OpenSSL and are ripping it apart from the inside out - we're <a href="http://undeadly.org/cgi?action=article&amp;sid=20140415093252" rel="nofollow noopener">seeing a fork</a> in real time
***</li>
</ul>

<h2>Interview - Jim Brown - <a href="mailto:info@bsdcertification.org" rel="nofollow noopener">info@bsdcertification.org</a></h2>

<p>The <a href="http://bsdcertification.org/" rel="nofollow noopener">BSD Certification</a> exams</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">Building OpenBSD binary packages in bulk</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/aperezdc/signify" rel="nofollow noopener">Portable signify</a></h3>

<ul>
<li>Back in <a href="http://www.bsdnow.tv/episodes/2014_02_05-time_signatures" rel="nofollow noopener">episode 23</a> we talked with Ted Unangst about the new "signify" tool in OpenBSD</li>
<li>Now there's a (completely unofficial) portable version of it on github</li>
<li>If you want to verify your OpenBSD sets ahead of time on another OS, this tool should let you do it</li>
<li>Maybe other BSD projects can adopt it as a replacement for gpg and incorporate it into their base systems
***</li>
</ul>

<h3><a href="https://www.mail-archive.com/misc@openbsd.org/msg128240.html" rel="nofollow noopener">Foundation goals and updates</a></h3>

<ul>
<li>The OpenBSD foundation has reached their 2014 goal of $150,000</li>
<li>You can check <a href="http://www.openbsdfoundation.org/activities.html" rel="nofollow noopener">their activities and goals</a> to see where the money is going</li>
<li>Remember that funding also goes to OpenSSH, which EVERY system uses and relies on everyday to protect their data</li>
<li>The FreeBSD foundation has kicked off their <a href="http://freebsdfoundation.blogspot.com/2014/04/freebsd-foundation-spring-fundraising.html" rel="nofollow noopener">spring fundraising</a> campaign</li>
<li>There's also a list of their activities and goals available to read through</li>
<li>Be sure to support your favorite BSD, whichever one, so they can continue to make and improve great software that powers the whole internet
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/04/pc-bsd-weekly-feature-digest-25/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>New PBI runtime that fixes stability issues and decreases load times</li>
<li>"Update Center" is getting a lot of development and improvements</li>
<li>Lots of misc. bug fixes and updates
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://www.reddit.com/r/BSD/comments/22y497/i_need_a_bit_of_help_showing_my_friends_bsd_and/" rel="nofollow noopener">There's a reddit thread</a> we wanted to highlight - a user wants to show his friend BSD and why it's great</li>
<li><a href="http://slexy.org/view/s20Tso9a6v" rel="nofollow noopener">Brad writes in</a></li>
<li><a href="http://slexy.org/view/s21DfdV9yt" rel="nofollow noopener">Sha'ul writes in</a></li>
<li><a href="http://slexy.org/view/s2di8XRt73" rel="nofollow noopener">iGibbs writes in</a></li>
<li><a href="http://slexy.org/view/s20m2g8UgV" rel="nofollow noopener">Matt writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>29: P.E.F.S.</title>
  <link>https://www.bsdnow.tv/29</link>
  <guid isPermaLink="false">4af36dea-3dd3-4ac1-9ee9-a2e34dd54e3a</guid>
  <pubDate>Wed, 19 Mar 2014 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/4af36dea-3dd3-4ac1-9ee9-a2e34dd54e3a.mp3" length="82610606" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>We're back from AsiaBSDCon! This week we'll be chatting with Gleb Kurtsou about some a filesystem-level encryption utility called PEFS. After that, we'll give you a step by step guide on how to actually use it. There's also the usual round of your questions and we've got a lot of news to catch up on, so stay tuned to BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:54:44</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;We're back from AsiaBSDCon! This week we'll be chatting with Gleb Kurtsou about some a filesystem-level encryption utility called PEFS. After that, we'll give you a step by step guide on how to actually use it. There's also the usual round of your questions and we've got a lot of news to catch up on, so stay tuned to BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://neocri.me/documentation/using-ssh-certificate-authentication/" rel="nofollow noopener"&gt;Using OpenSSH Certificate Authentication&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;SSH has a not-so-often-talked-about authentication option in addition to passwords and keys: certificates - you can add certificates to any current authentication method you're using&lt;/li&gt;
&lt;li&gt;They're not really that complex, there just isn't a lot of documentation on how to use them - this post tries to solve that&lt;/li&gt;
&lt;li&gt;There's the benefit of not needing a known_hosts file or authorized_users file anymore&lt;/li&gt;
&lt;li&gt;The post goes into a fair amount of detail about the differences, advantages and implications of using certificates for authentication
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.duckland.org/2014/03/back-to-freebsd-aka-day-1#more" rel="nofollow noopener"&gt;Back to FreeBSD, a new series&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Similar to the "FreeBSD Challenge" blog series, one of our listeners will be writing about his switching BACK to FreeBSD journey&lt;/li&gt;
&lt;li&gt;"So, a long time ago, I had a box which was running FreeBSD 4, running on a Pentium. 14 years later, I have decided to get back into FreeBSD, now at FreeBSD 10"&lt;/li&gt;
&lt;li&gt;He's starting off with PCBSD since it's easy to get working with dual graphics&lt;/li&gt;
&lt;li&gt;Should be a fun series to follow!
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140307130554" rel="nofollow noopener"&gt;OpenBSD's recent experiments in package building&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you'll remember back to our &lt;a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener"&gt;poudriere tutorial&lt;/a&gt;, it lets you build FreeBSD binary packages in bulk - OpenBSD's version is called &lt;a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener"&gt;dpb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Marc Espie recently got some monster machines in russia to play with to help improve scaling of dpb on high end hardware&lt;/li&gt;
&lt;li&gt;This article goes through some of his findings and plans for future versions that increase performance&lt;/li&gt;
&lt;li&gt;We'll be showing a tutorial of dpb on the show in a few weeks
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://jafdip.com/securing-freebsd-2fa-two-factor-authentication/" rel="nofollow noopener"&gt;Securing FreeBSD with 2FA&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;So maybe you've set up two-factor authentication with gmail or twitter, but have you done it with your BSD box?&lt;/li&gt;
&lt;li&gt;This post walks us through the process of locking down an &lt;a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener"&gt;ssh server&lt;/a&gt; with 2FA&lt;/li&gt;
&lt;li&gt;With just a mobile phone and a few extra tools, you can enable two-factor auth on your BSD box and have just that little extra bit of protections
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Gleb Kurtsou - &lt;a href="mailto:gleb.kurtsou@gmail.com" rel="nofollow noopener"&gt;gleb.kurtsou@gmail.com&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;PEFS (security audit results &lt;a href="https://defuse.ca/audits/pefs.htm" rel="nofollow noopener"&gt;here&lt;/a&gt;)&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Tutorial&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.bsdnow.tv/tutorials/pefs" rel="nofollow noopener"&gt;Filesystem-based encryption with PEFS&lt;/a&gt;&lt;/h3&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.bsdcan.org/2014/registration.php" rel="nofollow noopener"&gt;BSDCan 2014 registration&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Registration is finally open!&lt;/li&gt;
&lt;li&gt;The prices are available along with a full list of presentations&lt;/li&gt;
&lt;li&gt;Tutorial sessions for various topics as well&lt;/li&gt;
&lt;li&gt;You have to go
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140314080734" rel="nofollow noopener"&gt;Big changes for OpenBSD 5.6&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Although 5.5 was just frozen and the release process has started, 5.6 is already looking promising&lt;/li&gt;
&lt;li&gt;OpenBSD has, for a long time, included a heavily-patched version of Apache based on 1.3&lt;/li&gt;
&lt;li&gt;They've also imported nginx into base a few years ago, but now have finally removed Apache&lt;/li&gt;
&lt;li&gt;Sendmail is also no longer the default MTA, OpenSMTPD &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20140313052817" rel="nofollow noopener"&gt;is the new default&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Will BIND be removed next? &lt;a href="http://marc.info/?l=openbsd-cvs&amp;amp;m=139492163427518&amp;amp;w=2" rel="nofollow noopener"&gt;Maybe so&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;They've also discontinued the hp300, mvme68k and mvme88k ports
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blogs.freebsdish.org/portmgr/2014/03/11/getting-to-know-your-portmgr-lurker-alexy-dokuchaev/" rel="nofollow noopener"&gt;Getting to know your portmgr lurkers&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The "getting to know your portmgr" series makes its return&lt;/li&gt;
&lt;li&gt;This time we get to talk with danfe@ (probably most known for being the nVidia driver maintainer, but he does a lot with ports)&lt;/li&gt;
&lt;li&gt;How he got into FreeBSD? He "wanted a unix system that I could understand and that would not get bloated as time goes by"&lt;/li&gt;
&lt;li&gt;Mentions why he's still heavily involved with the project and lots more
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-20/" rel="nofollow noopener"&gt;PCBSD weekly digest&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Work has started to port Pulseaudio to PCBSD 10.0.1&lt;/li&gt;
&lt;li&gt;There's a new "pc-mixer" utility being worked on for sound management as well&lt;/li&gt;
&lt;li&gt;New PBIs, GNOME/Mate updates, Life Preserver fixes and a lot more&lt;/li&gt;
&lt;li&gt;PCBSD 10.0.1 &lt;a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-21-pcbsd-10-0-1-released/" rel="nofollow noopener"&gt;was released&lt;/a&gt; too
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QwjHkL2n" rel="nofollow noopener"&gt;Alex writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2wLGlHF15" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s21JsgRjMU" rel="nofollow noopener"&gt;Nick writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2UX4sYdHy" rel="nofollow noopener"&gt;Sami writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s26z60Qd6z" rel="nofollow noopener"&gt;Christopher writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, encryption, pefs, fde, disk, asiabsdcon, 2014, asiabsdcon2014, presentation, talk, video, recording, openssh, certificate, authentication, dpb, two factor, 2fa, yubikey</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>We're back from AsiaBSDCon! This week we'll be chatting with Gleb Kurtsou about some a filesystem-level encryption utility called PEFS. After that, we'll give you a step by step guide on how to actually use it. There's also the usual round of your questions and we've got a lot of news to catch up on, so stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://neocri.me/documentation/using-ssh-certificate-authentication/" rel="nofollow noopener">Using OpenSSH Certificate Authentication</a></h3>

<ul>
<li>SSH has a not-so-often-talked-about authentication option in addition to passwords and keys: certificates - you can add certificates to any current authentication method you're using</li>
<li>They're not really that complex, there just isn't a lot of documentation on how to use them - this post tries to solve that</li>
<li>There's the benefit of not needing a known_hosts file or authorized_users file anymore</li>
<li>The post goes into a fair amount of detail about the differences, advantages and implications of using certificates for authentication
***</li>
</ul>

<h3><a href="http://www.duckland.org/2014/03/back-to-freebsd-aka-day-1#more" rel="nofollow noopener">Back to FreeBSD, a new series</a></h3>

<ul>
<li>Similar to the "FreeBSD Challenge" blog series, one of our listeners will be writing about his switching BACK to FreeBSD journey</li>
<li>"So, a long time ago, I had a box which was running FreeBSD 4, running on a Pentium. 14 years later, I have decided to get back into FreeBSD, now at FreeBSD 10"</li>
<li>He's starting off with PCBSD since it's easy to get working with dual graphics</li>
<li>Should be a fun series to follow!
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140307130554" rel="nofollow noopener">OpenBSD's recent experiments in package building</a></h3>

<ul>
<li>If you'll remember back to our <a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener">poudriere tutorial</a>, it lets you build FreeBSD binary packages in bulk - OpenBSD's version is called <a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">dpb</a></li>
<li>Marc Espie recently got some monster machines in russia to play with to help improve scaling of dpb on high end hardware</li>
<li>This article goes through some of his findings and plans for future versions that increase performance</li>
<li>We'll be showing a tutorial of dpb on the show in a few weeks
***</li>
</ul>

<h3><a href="http://jafdip.com/securing-freebsd-2fa-two-factor-authentication/" rel="nofollow noopener">Securing FreeBSD with 2FA</a></h3>

<ul>
<li>So maybe you've set up two-factor authentication with gmail or twitter, but have you done it with your BSD box?</li>
<li>This post walks us through the process of locking down an <a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener">ssh server</a> with 2FA</li>
<li>With just a mobile phone and a few extra tools, you can enable two-factor auth on your BSD box and have just that little extra bit of protections
***</li>
</ul>

<h2>Interview - Gleb Kurtsou - <a href="mailto:gleb.kurtsou@gmail.com" rel="nofollow noopener">gleb.kurtsou@gmail.com</a></h2>

<p>PEFS (security audit results <a href="https://defuse.ca/audits/pefs.htm" rel="nofollow noopener">here</a>)</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pefs" rel="nofollow noopener">Filesystem-based encryption with PEFS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.bsdcan.org/2014/registration.php" rel="nofollow noopener">BSDCan 2014 registration</a></h3>

<ul>
<li>Registration is finally open!</li>
<li>The prices are available along with a full list of presentations</li>
<li>Tutorial sessions for various topics as well</li>
<li>You have to go
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140314080734" rel="nofollow noopener">Big changes for OpenBSD 5.6</a></h3>

<ul>
<li>Although 5.5 was just frozen and the release process has started, 5.6 is already looking promising</li>
<li>OpenBSD has, for a long time, included a heavily-patched version of Apache based on 1.3</li>
<li>They've also imported nginx into base a few years ago, but now have finally removed Apache</li>
<li>Sendmail is also no longer the default MTA, OpenSMTPD <a href="http://undeadly.org/cgi?action=article&amp;sid=20140313052817" rel="nofollow noopener">is the new default</a></li>
<li>Will BIND be removed next? <a href="http://marc.info/?l=openbsd-cvs&amp;m=139492163427518&amp;w=2" rel="nofollow noopener">Maybe so</a></li>
<li>They've also discontinued the hp300, mvme68k and mvme88k ports
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/03/11/getting-to-know-your-portmgr-lurker-alexy-dokuchaev/" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The "getting to know your portmgr" series makes its return</li>
<li>This time we get to talk with danfe@ (probably most known for being the nVidia driver maintainer, but he does a lot with ports)</li>
<li>How he got into FreeBSD? He "wanted a unix system that I could understand and that would not get bloated as time goes by"</li>
<li>Mentions why he's still heavily involved with the project and lots more
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-20/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Work has started to port Pulseaudio to PCBSD 10.0.1</li>
<li>There's a new "pc-mixer" utility being worked on for sound management as well</li>
<li>New PBIs, GNOME/Mate updates, Life Preserver fixes and a lot more</li>
<li>PCBSD 10.0.1 <a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-21-pcbsd-10-0-1-released/" rel="nofollow noopener">was released</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2QwjHkL2n" rel="nofollow noopener">Alex writes in</a></li>
<li><a href="http://slexy.org/view/s2wLGlHF15" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s21JsgRjMU" rel="nofollow noopener">Nick writes in</a></li>
<li><a href="http://slexy.org/view/s2UX4sYdHy" rel="nofollow noopener">Sami writes in</a></li>
<li><a href="http://slexy.org/view/s26z60Qd6z" rel="nofollow noopener">Christopher writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>We're back from AsiaBSDCon! This week we'll be chatting with Gleb Kurtsou about some a filesystem-level encryption utility called PEFS. After that, we'll give you a step by step guide on how to actually use it. There's also the usual round of your questions and we've got a lot of news to catch up on, so stay tuned to BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise Servers and Storage For Open Source"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://neocri.me/documentation/using-ssh-certificate-authentication/" rel="nofollow noopener">Using OpenSSH Certificate Authentication</a></h3>

<ul>
<li>SSH has a not-so-often-talked-about authentication option in addition to passwords and keys: certificates - you can add certificates to any current authentication method you're using</li>
<li>They're not really that complex, there just isn't a lot of documentation on how to use them - this post tries to solve that</li>
<li>There's the benefit of not needing a known_hosts file or authorized_users file anymore</li>
<li>The post goes into a fair amount of detail about the differences, advantages and implications of using certificates for authentication
***</li>
</ul>

<h3><a href="http://www.duckland.org/2014/03/back-to-freebsd-aka-day-1#more" rel="nofollow noopener">Back to FreeBSD, a new series</a></h3>

<ul>
<li>Similar to the "FreeBSD Challenge" blog series, one of our listeners will be writing about his switching BACK to FreeBSD journey</li>
<li>"So, a long time ago, I had a box which was running FreeBSD 4, running on a Pentium. 14 years later, I have decided to get back into FreeBSD, now at FreeBSD 10"</li>
<li>He's starting off with PCBSD since it's easy to get working with dual graphics</li>
<li>Should be a fun series to follow!
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140307130554" rel="nofollow noopener">OpenBSD's recent experiments in package building</a></h3>

<ul>
<li>If you'll remember back to our <a href="http://www.bsdnow.tv/tutorials/poudriere" rel="nofollow noopener">poudriere tutorial</a>, it lets you build FreeBSD binary packages in bulk - OpenBSD's version is called <a href="http://www.bsdnow.tv/tutorials/dpb" rel="nofollow noopener">dpb</a></li>
<li>Marc Espie recently got some monster machines in russia to play with to help improve scaling of dpb on high end hardware</li>
<li>This article goes through some of his findings and plans for future versions that increase performance</li>
<li>We'll be showing a tutorial of dpb on the show in a few weeks
***</li>
</ul>

<h3><a href="http://jafdip.com/securing-freebsd-2fa-two-factor-authentication/" rel="nofollow noopener">Securing FreeBSD with 2FA</a></h3>

<ul>
<li>So maybe you've set up two-factor authentication with gmail or twitter, but have you done it with your BSD box?</li>
<li>This post walks us through the process of locking down an <a href="http://www.bsdnow.tv/tutorials/ssh-tmux" rel="nofollow noopener">ssh server</a> with 2FA</li>
<li>With just a mobile phone and a few extra tools, you can enable two-factor auth on your BSD box and have just that little extra bit of protections
***</li>
</ul>

<h2>Interview - Gleb Kurtsou - <a href="mailto:gleb.kurtsou@gmail.com" rel="nofollow noopener">gleb.kurtsou@gmail.com</a></h2>

<p>PEFS (security audit results <a href="https://defuse.ca/audits/pefs.htm" rel="nofollow noopener">here</a>)</p>

<hr>

<h2>Tutorial</h2>

<h3><a href="http://www.bsdnow.tv/tutorials/pefs" rel="nofollow noopener">Filesystem-based encryption with PEFS</a></h3>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://www.bsdcan.org/2014/registration.php" rel="nofollow noopener">BSDCan 2014 registration</a></h3>

<ul>
<li>Registration is finally open!</li>
<li>The prices are available along with a full list of presentations</li>
<li>Tutorial sessions for various topics as well</li>
<li>You have to go
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20140314080734" rel="nofollow noopener">Big changes for OpenBSD 5.6</a></h3>

<ul>
<li>Although 5.5 was just frozen and the release process has started, 5.6 is already looking promising</li>
<li>OpenBSD has, for a long time, included a heavily-patched version of Apache based on 1.3</li>
<li>They've also imported nginx into base a few years ago, but now have finally removed Apache</li>
<li>Sendmail is also no longer the default MTA, OpenSMTPD <a href="http://undeadly.org/cgi?action=article&amp;sid=20140313052817" rel="nofollow noopener">is the new default</a></li>
<li>Will BIND be removed next? <a href="http://marc.info/?l=openbsd-cvs&amp;m=139492163427518&amp;w=2" rel="nofollow noopener">Maybe so</a></li>
<li>They've also discontinued the hp300, mvme68k and mvme88k ports
***</li>
</ul>

<h3><a href="http://blogs.freebsdish.org/portmgr/2014/03/11/getting-to-know-your-portmgr-lurker-alexy-dokuchaev/" rel="nofollow noopener">Getting to know your portmgr lurkers</a></h3>

<ul>
<li>The "getting to know your portmgr" series makes its return</li>
<li>This time we get to talk with danfe@ (probably most known for being the nVidia driver maintainer, but he does a lot with ports)</li>
<li>How he got into FreeBSD? He "wanted a unix system that I could understand and that would not get bloated as time goes by"</li>
<li>Mentions why he's still heavily involved with the project and lots more
***</li>
</ul>

<h3><a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-20/" rel="nofollow noopener">PCBSD weekly digest</a></h3>

<ul>
<li>Work has started to port Pulseaudio to PCBSD 10.0.1</li>
<li>There's a new "pc-mixer" utility being worked on for sound management as well</li>
<li>New PBIs, GNOME/Mate updates, Life Preserver fixes and a lot more</li>
<li>PCBSD 10.0.1 <a href="http://blog.pcbsd.org/2014/03/pc-bsd-weekly-feature-digest-21-pcbsd-10-0-1-released/" rel="nofollow noopener">was released</a> too
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2QwjHkL2n" rel="nofollow noopener">Alex writes in</a></li>
<li><a href="http://slexy.org/view/s2wLGlHF15" rel="nofollow noopener">Ben writes in</a></li>
<li><a href="http://slexy.org/view/s21JsgRjMU" rel="nofollow noopener">Nick writes in</a></li>
<li><a href="http://slexy.org/view/s2UX4sYdHy" rel="nofollow noopener">Sami writes in</a></li>
<li><a href="http://slexy.org/view/s26z60Qd6z" rel="nofollow noopener">Christopher writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
