<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app01</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 08:10:43 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Static”</title>
    <link>https://www.bsdnow.tv/tags/static</link>
    <pubDate>Wed, 15 Apr 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>85: PIE in the Sky</title>
  <link>https://www.bsdnow.tv/85</link>
  <guid isPermaLink="false">7b947cd6-04e4-4210-a3a1-3f80d96ccc79</guid>
  <pubDate>Wed, 15 Apr 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/7b947cd6-04e4-4210-a3a1-3f80d96ccc79.mp3" length="58114516" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:20:42</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener"&gt;Solaris' networking future is with OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;A curious patch from someone with an Oracle email address was &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142822852613581&amp;amp;w=2" rel="nofollow noopener"&gt;recently sent in&lt;/a&gt; to one of the OpenBSD mailing lists&lt;/li&gt;
&lt;li&gt;It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the &lt;strong&gt;current&lt;/strong&gt; version of PF&lt;/li&gt;
&lt;li&gt;For anyone unfamiliar with the history of PF, it was actually made &lt;em&gt;as a replacement for&lt;/em&gt; IPFilter in OpenBSD, due to some licensing issues&lt;/li&gt;
&lt;li&gt;What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting&lt;/li&gt;
&lt;li&gt;This blog post goes through some of the backstory of the two firewalls&lt;/li&gt;
&lt;li&gt;PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too&lt;/li&gt;
&lt;li&gt;"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"&lt;/li&gt;
&lt;li&gt;You're welcome, Oracle
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener"&gt;BAFUG discussion videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Bay Area FreeBSD users group has been uploading some videos from their recent meetings&lt;/li&gt;
&lt;li&gt;Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)&lt;/li&gt;
&lt;li&gt;Craig Rodrigues also gave &lt;a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener"&gt;a talk&lt;/a&gt; about Kyua and the FreeBSD testing framework&lt;/li&gt;
&lt;li&gt;Lastly, Kip Macy gave &lt;a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener"&gt;a talk&lt;/a&gt; titled "network stack changes, user-level FreeBSD"&lt;/li&gt;
&lt;li&gt;The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics&lt;/li&gt;
&lt;li&gt;If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener"&gt;More than just a makefile&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux&lt;/li&gt;
&lt;li&gt;This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs&lt;/li&gt;
&lt;li&gt;As it turns out, the ports system really isn't that different from a binary package manager - they are what's &lt;em&gt;used&lt;/em&gt; to create binary packages, after all&lt;/li&gt;
&lt;li&gt;The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream&lt;/li&gt;
&lt;li&gt;After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community&lt;/li&gt;
&lt;li&gt;This post is very long and there's a lot more to it, so check it out (and more discussion &lt;a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener"&gt;on Hacker News&lt;/a&gt;)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener"&gt;Securing your home fences&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a &lt;a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener"&gt;bad&lt;/a&gt; &lt;a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener"&gt;idea&lt;/a&gt; by now&lt;/li&gt;
&lt;li&gt;We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now&lt;/li&gt;
&lt;li&gt;In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines &lt;a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener"&gt;APU board&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;He notes that you have a lot of options software-wise, including vanilla &lt;a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener"&gt;FreeBSD&lt;/a&gt;, &lt;a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener"&gt;OpenBSD&lt;/a&gt; or even Linux, but decided to go with OPNsense because of the easy interface and configuration&lt;/li&gt;
&lt;li&gt;The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process&lt;/li&gt;
&lt;li&gt;Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up&lt;/li&gt;
&lt;li&gt;If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)&lt;/li&gt;
&lt;li&gt;We love super-detailed guides like this, so everyone should write more and send them to us immediately
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Pascal Stumpf - &lt;a href="mailto:pascal@openbsd.org" rel="nofollow noopener"&gt;pascal@openbsd.org&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Static PIE in OpenBSD&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener"&gt;LLVM's new libFuzzer&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility&lt;/li&gt;
&lt;li&gt;It looks like LLVM is going to have their own fuzzing tool too now&lt;/li&gt;
&lt;li&gt;The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself&lt;/li&gt;
&lt;li&gt;With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener"&gt;HardenedBSD upgrades secadm&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support&lt;/li&gt;
&lt;li&gt;We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)&lt;/li&gt;
&lt;li&gt;Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142877132517229&amp;amp;w=2" rel="nofollow noopener"&gt;RAID5 returns to OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenBSD's &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener"&gt;softraid&lt;/a&gt; subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while&lt;/li&gt;
&lt;li&gt;However, it was exactly that - experimental - and required a recompile to enable&lt;/li&gt;
&lt;li&gt;With some work from recent hackathons, the &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142876943116907&amp;amp;w=2" rel="nofollow noopener"&gt;final piece&lt;/a&gt; was added to enable resuming partial array rebuilds&lt;/li&gt;
&lt;li&gt;Now it's &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877026917030&amp;amp;w=2" rel="nofollow noopener"&gt;on by default&lt;/a&gt;, and there's a call for testing being put out, so grab a snapshot and put the code through its paces&lt;/li&gt;
&lt;li&gt;The bioctl softraid command also &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=142877223817406&amp;amp;w=2" rel="nofollow noopener"&gt;now supports&lt;/a&gt; DUIDs during pseudo-device detachment, possibly paving the way for the installer to &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=142643313416298&amp;amp;w=2" rel="nofollow noopener"&gt;drop&lt;/a&gt; the "do you want to enable DUIDs?" question entirely
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener"&gt;pkgng 1.5.0 released&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Going back to what we &lt;a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener"&gt;talked about last week&lt;/a&gt;, the final version of pkgng 1.5.0 is out&lt;/li&gt;
&lt;li&gt;The "provides" and "requires" support is finally in a regular release&lt;/li&gt;
&lt;li&gt;A new "-r" switch will allow for direct installation to a chroot or alternate root directory&lt;/li&gt;
&lt;li&gt;Memory usage should be much better now, and some general code speed-ups were added&lt;/li&gt;
&lt;li&gt;This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that&lt;/li&gt;
&lt;li&gt;Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150411160247" rel="nofollow noopener"&gt;p2k15 hackathon reports&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work&lt;/li&gt;
&lt;li&gt;As usual, the developers sent in reports of some of the things they got done at the event&lt;/li&gt;
&lt;li&gt;Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit&lt;/li&gt;
&lt;li&gt;Stefan Sperling &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150414064710" rel="nofollow noopener"&gt;wrote in&lt;/a&gt;, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports&lt;/li&gt;
&lt;li&gt;Ken Westerback &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150413163333" rel="nofollow noopener"&gt;also sent in a report&lt;/a&gt;, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener"&gt;Shaun writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener"&gt;Hrishi writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener"&gt;Randy writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener"&gt;Zach writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener"&gt;Ben writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=142884995931428&amp;amp;w=2" rel="nofollow noopener"&gt;Gstreamer hates us&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener"&gt;At least he's honest&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener"&gt;I find myself in a situation&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, aslr, pie, position-independent executable, static, binary, dynamic, linking, security, llvm, fuzzing, clang, opnsense, pcengines, apu, alix, hammer2, zfs, oracle, solaris, pf</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This time on the show, we'll be talking with Pascal Stumpf about static PIE in the upcoming OpenBSD release. He'll tell us what types of attacks it prevents, and why it's such a big deal. We've also got answers to questions from you in the audience and all this week's news, on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://bsdly.blogspot.com/2015/04/solaris-admins-for-glimpse-of-your.html" rel="nofollow noopener">Solaris' networking future is with OpenBSD</a></h3>

<ul>
<li>A curious patch from someone with an Oracle email address was <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142822852613581&amp;w=2" rel="nofollow noopener">recently sent in</a> to one of the OpenBSD mailing lists</li>
<li>It was revealed that future releases of Solaris are going to drop their IPFilter firewall entirely, in favor of a port of the <strong>current</strong> version of PF</li>
<li>For anyone unfamiliar with the history of PF, it was actually made <em>as a replacement for</em> IPFilter in OpenBSD, due to some licensing issues</li>
<li>What's more, Solaris was the original development platform for IPFilter, so the fact that it would be replaced in its own home is pretty interesting</li>
<li>This blog post goes through some of the backstory of the two firewalls</li>
<li>PF is in a lot of places - other BSDs, Mac OS X and iOS - but there are plenty of other OpenBSD-developed technologies end up ported to other projects too</li>
<li>"Many of the world's largest corporations and government agencies are heavy Solaris users, meaning that even if you're neither an OpenBSD user or a Solaris user, your kit is likely interacting intensely with both kinds, and with Solaris moving to OpenBSD's PF for their filtering needs, we will all be benefiting even more from the OpenBSD project's emphasis on correctness, quality and security"</li>
<li>You're welcome, Oracle
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=Cb--h-iOQEM#t=15" rel="nofollow noopener">BAFUG discussion videos</a></h3>

<ul>
<li>The Bay Area FreeBSD users group has been uploading some videos from their recent meetings</li>
<li>Sean Bruno gave a recap of his experiences at EuroBSDCon last year, including the devsummit and some proposed ideas from it (as well as their current status)</li>
<li>Craig Rodrigues also gave <a href="https://www.youtube.com/watch?v=kPs8Dni_g3M#t=15" rel="nofollow noopener">a talk</a> about Kyua and the FreeBSD testing framework</li>
<li>Lastly, Kip Macy gave <a href="https://www.youtube.com/watch?v=Q13WtuqbZ7E#t=15" rel="nofollow noopener">a talk</a> titled "network stack changes, user-level FreeBSD"</li>
<li>The main two subjects there are some network stack changes, and how to get more people contributing, but there's also open discussion about a variety of FreeBSD topics</li>
<li>If you're close to the Bay Area in California, be sure to check out their group and attend a meeting sometime
***</li>
</ul>

<h3><a href="http://homing-on-code.blogspot.com/2015/04/ports-are-more-than-just-makefile.html" rel="nofollow noopener">More than just a makefile</a></h3>

<ul>
<li>If you're not a BSD user just yet, you might be wondering how the various ports and pkgsrc systems compare to the binary way of doing things on Linux</li>
<li>This blog entry talks about the ports system in OpenBSD, but a lot of the concepts apply to all the ports systems across the BSDs</li>
<li>As it turns out, the ports system really isn't that different from a binary package manager - they are what's <em>used</em> to create binary packages, after all</li>
<li>The author goes through what makefiles do, customizing which options software is compiled with, patching source code to build and getting those patches back upstream</li>
<li>After that, he shows you how to get your new port tested, if you're interesting in doing some porting yourself, and getting involved with the rest of the community</li>
<li>This post is very long and there's a lot more to it, so check it out (and more discussion <a href="https://news.ycombinator.com/item?id=9360827" rel="nofollow noopener">on Hacker News</a>)
***</li>
</ul>

<h3><a href="http://www.scip.ch/en/?labs.20150409" rel="nofollow noopener">Securing your home fences</a></h3>

<ul>
<li>Hopefully all our listeners have realized that trusting your network(s) to a consumer router is a <a href="http://www.devttys0.com/2015/04/hacking-the-d-link-dir-890l/" rel="nofollow noopener">bad</a> <a href="https://threatpost.com/12-million-home-routers-vulnerable-to-takeover/109970" rel="nofollow noopener">idea</a> by now</li>
<li>We hear from a lot of users who want to set up some kind of BSD-based firewall, but don't hear back from them after they've done it.. until now</li>
<li>In this post, someone goes through the process of setting up a home firewall using OPNsense on a PCEngines <a href="http://www.pcengines.ch/apu1d4.htm" rel="nofollow noopener">APU board</a></li>
<li>He notes that you have a lot of options software-wise, including vanilla <a href="http://blog.pcbsd.org/2015/01/using-trueos-as-a-ipfw-based-home-router/" rel="nofollow noopener">FreeBSD</a>, <a href="http://www.bsdnow.tv/tutorials/openbsd-router" rel="nofollow noopener">OpenBSD</a> or even Linux, but decided to go with OPNsense because of the easy interface and configuration</li>
<li>The post covers all the hardware you'll need, getting the OS installed to a flash drive or SD card and going through the whole process</li>
<li>Finally, he goes through setting up the firewall with the graphical interface, applying updates and finishing everything up</li>
<li>If you don't have any experience using a serial console, this guide also has some good info for beginners about those (which also applies to regular FreeBSD)</li>
<li>We love super-detailed guides like this, so everyone should write more and send them to us immediately
***</li>
</ul>

<h2>Interview - Pascal Stumpf - <a href="mailto:pascal@openbsd.org" rel="nofollow noopener">pascal@openbsd.org</a></h2>

<p>Static PIE in OpenBSD</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://blog.llvm.org/2015/04/fuzz-all-clangs.html" rel="nofollow noopener">LLVM's new libFuzzer</a></h3>

<ul>
<li>We've discussed fuzzing on the show a number of times, albeit mostly with the American Fuzzy Lop utility</li>
<li>It looks like LLVM is going to have their own fuzzing tool too now</li>
<li>The Clang and LLVM guys are no strangers to this type of code testing, but decided to "close the loop" and start fuzzing parts of LLVM (including Clang) using LLVM itself</li>
<li>With Clang being the default in both FreeBSD and Bitrig, and with the other BSDs considering the switch, this could make for some good bug hunting across all the projects in the future
***</li>
</ul>

<h3><a href="http://hardenedbsd.org/article/shawn-webb/2015-04-14/introducing-secadm-02" rel="nofollow noopener">HardenedBSD upgrades secadm</a></h3>

<ul>
<li>The HardenedBSD guys have released a new version of their secadm tool, with the showcase feature being integriforce support</li>
<li>We covered both the secadm tool and integriforce in previous episodes, but the short version is that it's a way to prevent files from being altered (even as root)</li>
<li>Their integriforce feature itself has also gotten a couple improvements: shared objects are now checked too, instead of just binaries, and it uses more caching to speed up the whole process now
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=142877132517229&amp;w=2" rel="nofollow noopener">RAID5 returns to OpenBSD</a></h3>

<ul>
<li>OpenBSD's <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man4/softraid.4" rel="nofollow noopener">softraid</a> subsystem, somewhat similar to FreeBSD's GEOM, has had experimental RAID5 support for a while</li>
<li>However, it was exactly that - experimental - and required a recompile to enable</li>
<li>With some work from recent hackathons, the <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142876943116907&amp;w=2" rel="nofollow noopener">final piece</a> was added to enable resuming partial array rebuilds</li>
<li>Now it's <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877026917030&amp;w=2" rel="nofollow noopener">on by default</a>, and there's a call for testing being put out, so grab a snapshot and put the code through its paces</li>
<li>The bioctl softraid command also <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=142877223817406&amp;w=2" rel="nofollow noopener">now supports</a> DUIDs during pseudo-device detachment, possibly paving the way for the installer to <a href="https://www.marc.info/?l=openbsd-tech&amp;m=142643313416298&amp;w=2" rel="nofollow noopener">drop</a> the "do you want to enable DUIDs?" question entirely
***</li>
</ul>

<h3><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055463.html" rel="nofollow noopener">pkgng 1.5.0 released</a></h3>

<ul>
<li>Going back to what we <a href="http://www.bsdnow.tv/episodes/2015_04_08-pkg_remove_freebsd-update" rel="nofollow noopener">talked about last week</a>, the final version of pkgng 1.5.0 is out</li>
<li>The "provides" and "requires" support is finally in a regular release</li>
<li>A new "-r" switch will allow for direct installation to a chroot or alternate root directory</li>
<li>Memory usage should be much better now, and some general code speed-ups were added</li>
<li>This version also introduces support for Mac OS X, NetBSD and EdgeBSD - it'll be interesting to see if anything comes of that</li>
<li>Many more bugs were fixed, so check the mailing list announcement for the rest (and plenty new bugs were added, according to bapt)
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150411160247" rel="nofollow noopener">p2k15 hackathon reports</a></h3>

<ul>
<li>There was another OpenBSD hackathon that just finished up in the UK - this time it was mainly for ports work</li>
<li>As usual, the developers sent in reports of some of the things they got done at the event</li>
<li>Landry Breuil, both an upstream Mozilla developer and an OpenBSD developer, wrote in about the work he did on the Firefox port (specifically WebRTC) and some others, as well as reviewing lots of patches that were ready to commit</li>
<li>Stefan Sperling <a href="http://undeadly.org/cgi?action=article&amp;sid=20150414064710" rel="nofollow noopener">wrote in</a>, detailing his work with wireless chipsets, specifically when the vendor doesn't provide any hardware documentation, as well as updating some of the games in ports</li>
<li>Ken Westerback <a href="http://undeadly.org/cgi?action=article&amp;sid=20150413163333" rel="nofollow noopener">also sent in a report</a>, but decided to be a rebel and not work on ports at all - he got a lot of GPT-related work done, and also reviewed the RAID5 support we talked about earlier
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2iNBo2swq" rel="nofollow noopener">Shaun writes in</a></li>
<li><a href="http://slexy.org/view/s202BRLwrd" rel="nofollow noopener">Hrishi writes in</a></li>
<li><a href="http://slexy.org/view/s2KT7M35uY" rel="nofollow noopener">Randy writes in</a></li>
<li><a href="http://slexy.org/view/s2Q5lOoxzl" rel="nofollow noopener">Zach writes in</a></li>
<li><a href="http://slexy.org/view/s2ynDjuzVi" rel="nofollow noopener">Ben writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=142884995931428&amp;w=2" rel="nofollow noopener">Gstreamer hates us</a></li>
<li><a href="https://lists.torproject.org/pipermail/tor-relays/2015-April/006765.html" rel="nofollow noopener">At least he's honest</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-current/2015-April/055390.html" rel="nofollow noopener">I find myself in a situation</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>70: Daemons in the North</title>
  <link>https://www.bsdnow.tv/70</link>
  <guid isPermaLink="false">55684d1a-97da-439b-a037-b02c8d49de70</guid>
  <pubDate>Wed, 31 Dec 2014 08:00:00 -0500</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/55684d1a-97da-439b-a037-b02c8d49de70.mp3" length="60663316" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:24:15</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener"&gt;More conference presentation videos&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Some more of the presentation videos from AsiaBSDCon are appearing online&lt;/li&gt;
&lt;li&gt;Masanobu Saitoh, &lt;a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener"&gt;Developing CPE Routers Based on NetBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener"&gt;Reyk Floeter&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener"&gt;VXLAN and Cloud-based Networking with OpenBSD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Jos Jansen, &lt;a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener"&gt;Adapting OS X to the enterprise&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener"&gt;Pierre Pronchery&lt;/a&gt; &amp;amp; Guillaume Lasmayous, &lt;a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener"&gt;Carve your NetBSD&lt;/a&gt; &amp;lt;!-- skip to 5:06 for henning trolling --&amp;gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener"&gt;Colin Percival&lt;/a&gt;, &lt;a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener"&gt;Everything you need to know about cryptography in 1 hour&lt;/a&gt; (not from AsiaBSDCon)&lt;/li&gt;
&lt;li&gt;The "bsdconferences" YouTube channel has quite a lot of interesting &lt;a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;amp;view=0&amp;amp;flow=grid" rel="nofollow noopener"&gt;older BSD talks&lt;/a&gt; too - you may want to go back and watch them if you haven't already
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141922027318727&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD PIE enhancements&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener"&gt;ASLR&lt;/a&gt; and &lt;a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener"&gt;PIE&lt;/a&gt; are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem&lt;/li&gt;
&lt;li&gt;They only work with &lt;em&gt;dynamic&lt;/em&gt; libraries and binaries, so if you have any static binaries, they don't get the same treatment&lt;/li&gt;
&lt;li&gt;For example, the default shells (and many other things in /bin and /sbin) are statically linked&lt;/li&gt;
&lt;li&gt;In the case of the static ones, you can always predict the memory layout, which is very bad and sort of &lt;a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener"&gt;defeats the whole purpose&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;With this and a few &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141927571832106&amp;amp;w=2" rel="nofollow noopener"&gt;related commits&lt;/a&gt;, OpenBSD fixes this by introducing &lt;strong&gt;static self-relocation&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy&lt;/li&gt;
&lt;li&gt;It'll be available in 5.7 in May, or you can use a &lt;a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener"&gt;-current snapshot&lt;/a&gt; if you want to get a &lt;em&gt;slice&lt;/em&gt; of the action now
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener"&gt;FreeBSD foundation semi-annual newsletter&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities&lt;/li&gt;
&lt;li&gt;As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved&lt;/li&gt;
&lt;li&gt;The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)&lt;/li&gt;
&lt;li&gt;You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too&lt;/li&gt;
&lt;li&gt;There are also sections about the &lt;a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener"&gt;FreeBSD Journal&lt;/a&gt;'s progress, a new staff member and a testimonial from NetApp&lt;/li&gt;
&lt;li&gt;It's a very long report, so dedicate some time to read all the way through it&lt;/li&gt;
&lt;li&gt;This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too&lt;/li&gt;
&lt;li&gt;As we go into 2015, consider donating to &lt;a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener"&gt;whichever&lt;/a&gt; &lt;a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener"&gt;BSD&lt;/a&gt; &lt;a href="https://www.netbsd.org/donations/" rel="nofollow noopener"&gt;you&lt;/a&gt; &lt;a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener"&gt;use&lt;/a&gt;, it really can make a difference
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141920089614758&amp;amp;w=4" rel="nofollow noopener"&gt;Modernizing OpenSSH fingerprints&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to&lt;/li&gt;
&lt;li&gt;Up until now, the key fingerprints have been an MD5 hash, displayed as hex&lt;/li&gt;
&lt;li&gt;This &lt;a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener"&gt;can be problematic&lt;/a&gt;, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to&lt;/li&gt;
&lt;li&gt;This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint&lt;/li&gt;
&lt;li&gt;You can add a "FingerprintHash" line in your ssh_config to force using only the new type&lt;/li&gt;
&lt;li&gt;There's also a &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=141923470520906&amp;amp;w=2" rel="nofollow noopener"&gt;new option&lt;/a&gt; to require users to authenticate with &lt;strong&gt;more than one&lt;/strong&gt; public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type&lt;/li&gt;
&lt;li&gt;The new options should be in the upcoming 6.8 release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Dan Langille - &lt;a href="mailto:info@bsdcan.org" rel="nofollow noopener"&gt;info@bsdcan.org&lt;/a&gt; / &lt;a href="https://twitter.com/bsdcan" rel="nofollow noopener"&gt;@bsdcan&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Plans for the BSDCan 2015 conference&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener"&gt;Introducing ntimed, a new NTP daemon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;As we've mentioned before in &lt;a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener"&gt;our tutorials&lt;/a&gt;, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD&lt;/li&gt;
&lt;li&gt;With all the recent security problems with ISC's NTPd, &lt;a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener"&gt;Poul-Henning Kamp&lt;/a&gt; has been working on a third NTP daemon&lt;/li&gt;
&lt;li&gt;It's called "ntimed" and you can try out a preview version of it right now - it's &lt;a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener"&gt;in FreeBSD ports&lt;/a&gt; or on Github&lt;/li&gt;
&lt;li&gt;PHK also has a few &lt;a href="http://phk.freebsd.dk/time/" rel="nofollow noopener"&gt;blog entries&lt;/a&gt; about the project, including status updates
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener"&gt;OpenBSD-maintained projects list&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There was recently a read on the &lt;a href="https://www.marc.info/?t=141961588200003&amp;amp;r=1&amp;amp;w=2" rel="nofollow noopener"&gt;misc mailing list&lt;/a&gt; asking about different projects started by OpenBSD developers&lt;/li&gt;
&lt;li&gt;The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)&lt;/li&gt;
&lt;li&gt;A developer compiled a new list from all of the replies to that thread into a nice organized webpage&lt;/li&gt;
&lt;li&gt;Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more&lt;/li&gt;
&lt;li&gt;This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener"&gt;Monitoring network traffic with FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you&lt;/li&gt;
&lt;li&gt;It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)&lt;/li&gt;
&lt;li&gt;This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener"&gt;Trapping spammers with spamd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;This is a blog post about OpenBSD's &lt;a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener"&gt;spamd&lt;/a&gt; - a spam email deferral daemon - and how to use it for your mail&lt;/li&gt;
&lt;li&gt;It gives some background on the greylisting approach to spam, rather than just a typical host blacklist&lt;/li&gt;
&lt;li&gt;"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."&lt;/li&gt;
&lt;li&gt;The post also shows how to combine it with PF and other tools for a pretty fancy mail setup&lt;/li&gt;
&lt;li&gt;You can find spamd in the OpenBSD &lt;a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener"&gt;base system&lt;/a&gt;, or use it &lt;a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener"&gt;with FreeBSD&lt;/a&gt; &lt;a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener"&gt;or NetBSD&lt;/a&gt; via ports and pkgsrc&lt;/li&gt;
&lt;li&gt;You might also want to go back and listen to &lt;a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener"&gt;BSDTalk episode 68&lt;/a&gt;, where Will talks to Bob Beck about spamd
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener"&gt;Brandon writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener"&gt;Anders writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener"&gt;David writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener"&gt;Kyle writes in&lt;/a&gt;
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Mailing List Gold&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141903858708123&amp;amp;w=2" rel="nofollow noopener"&gt;NTP code comparison&lt;/a&gt; - &lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=141905854411370&amp;amp;w=2" rel="nofollow noopener"&gt;192870 vs. 2898&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener"&gt;NICs have feelings too&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.marc.info/?l=openbsd-ports&amp;amp;m=141998130824977&amp;amp;w=2" rel="nofollow noopener"&gt;Just think about it&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, bsdcan, call for papers, conference, talk, presentation, vxlan, static, pie, openssh, ntimed, ntp, openntpd</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener">More conference presentation videos</a></h3>

<ul>
<li>Some more of the presentation videos from AsiaBSDCon are appearing online</li>
<li>Masanobu Saitoh, <a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener">Developing CPE Routers Based on NetBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">VXLAN and Cloud-based Networking with OpenBSD</a></li>
<li>Jos Jansen, <a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener">Adapting OS X to the enterprise</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener">Pierre Pronchery</a> &amp; Guillaume Lasmayous, <a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener">Carve your NetBSD</a> &lt;!-- skip to 5:06 for henning trolling --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener">Colin Percival</a>, <a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener">Everything you need to know about cryptography in 1 hour</a> (not from AsiaBSDCon)</li>
<li>The "bsdconferences" YouTube channel has quite a lot of interesting <a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;view=0&amp;flow=grid" rel="nofollow noopener">older BSD talks</a> too - you may want to go back and watch them if you haven't already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141922027318727&amp;w=2" rel="nofollow noopener">OpenBSD PIE enhancements</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a> and <a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener">PIE</a> are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem</li>
<li>They only work with <em>dynamic</em> libraries and binaries, so if you have any static binaries, they don't get the same treatment</li>
<li>For example, the default shells (and many other things in /bin and /sbin) are statically linked</li>
<li>In the case of the static ones, you can always predict the memory layout, which is very bad and sort of <a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener">defeats the whole purpose</a></li>
<li>With this and a few <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141927571832106&amp;w=2" rel="nofollow noopener">related commits</a>, OpenBSD fixes this by introducing <strong>static self-relocation</strong></li>
<li>More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy</li>
<li>It'll be available in 5.7 in May, or you can use a <a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener">-current snapshot</a> if you want to get a <em>slice</em> of the action now
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities</li>
<li>As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved</li>
<li>The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)</li>
<li>You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too</li>
<li>There are also sections about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD Journal</a>'s progress, a new staff member and a testimonial from NetApp</li>
<li>It's a very long report, so dedicate some time to read all the way through it</li>
<li>This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too</li>
<li>As we go into 2015, consider donating to <a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">whichever</a> <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">BSD</a> <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">you</a> <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">use</a>, it really can make a difference
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141920089614758&amp;w=4" rel="nofollow noopener">Modernizing OpenSSH fingerprints</a></h3>

<ul>
<li>When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to</li>
<li>Up until now, the key fingerprints have been an MD5 hash, displayed as hex</li>
<li>This <a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener">can be problematic</a>, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to</li>
<li>This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint</li>
<li>You can add a "FingerprintHash" line in your ssh_config to force using only the new type</li>
<li>There's also a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141923470520906&amp;w=2" rel="nofollow noopener">new option</a> to require users to authenticate with <strong>more than one</strong> public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type</li>
<li>The new options should be in the upcoming 6.8 release
***</li>
</ul>

<h2>Interview - Dan Langille - <a href="mailto:info@bsdcan.org" rel="nofollow noopener">info@bsdcan.org</a> / <a href="https://twitter.com/bsdcan" rel="nofollow noopener">@bsdcan</a></h2>

<p>Plans for the BSDCan 2015 conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener">Introducing ntimed, a new NTP daemon</a></h3>

<ul>
<li>As we've mentioned before in <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">our tutorials</a>, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD</li>
<li>With all the recent security problems with ISC's NTPd, <a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">Poul-Henning Kamp</a> has been working on a third NTP daemon</li>
<li>It's called "ntimed" and you can try out a preview version of it right now - it's <a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener">in FreeBSD ports</a> or on Github</li>
<li>PHK also has a few <a href="http://phk.freebsd.dk/time/" rel="nofollow noopener">blog entries</a> about the project, including status updates
***</li>
</ul>

<h3><a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener">OpenBSD-maintained projects list</a></h3>

<ul>
<li>There was recently a read on the <a href="https://www.marc.info/?t=141961588200003&amp;r=1&amp;w=2" rel="nofollow noopener">misc mailing list</a> asking about different projects started by OpenBSD developers</li>
<li>The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)</li>
<li>A developer compiled a new list from all of the replies to that thread into a nice organized webpage</li>
<li>Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more</li>
<li>This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener">Monitoring network traffic with FreeBSD</a></h3>

<ul>
<li>If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you</li>
<li>It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)</li>
<li>This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener">Trapping spammers with spamd</a></h3>

<ul>
<li>This is a blog post about OpenBSD's <a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener">spamd</a> - a spam email deferral daemon - and how to use it for your mail</li>
<li>It gives some background on the greylisting approach to spam, rather than just a typical host blacklist</li>
<li>"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."</li>
<li>The post also shows how to combine it with PF and other tools for a pretty fancy mail setup</li>
<li>You can find spamd in the OpenBSD <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener">base system</a>, or use it <a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener">with FreeBSD</a> <a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener">or NetBSD</a> via ports and pkgsrc</li>
<li>You might also want to go back and listen to <a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener">BSDTalk episode 68</a>, where Will talks to Bob Beck about spamd
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener">Brandon writes in</a></li>
<li><a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener">Anders writes in</a></li>
<li><a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener">Kyle writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141903858708123&amp;w=2" rel="nofollow noopener">NTP code comparison</a> - <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141905854411370&amp;w=2" rel="nofollow noopener">192870 vs. 2898</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener">NICs have feelings too</a></li>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=141998130824977&amp;w=2" rel="nofollow noopener">Just think about it</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's our last episode of 2014, and we'll be chatting with Dan Langille about the upcoming BSDCan conference. We'll find out what's planned and what sorts of presentations they're looking for. As usual, answers to viewer-submitted questions and all the week's news, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/iXlogo2.png" alt="iXsystems - Enterprise servers and storage for open source"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/tarsnap1.png" alt="Tarsnap - online backups for the truly paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://2014.asiabsdcon.org/timetable.html.en" rel="nofollow noopener">More conference presentation videos</a></h3>

<ul>
<li>Some more of the presentation videos from AsiaBSDCon are appearing online</li>
<li>Masanobu Saitoh, <a href="https://www.youtube.com/watch?v=ApruZrU5fVs" rel="nofollow noopener">Developing CPE Routers Based on NetBSD</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_09_03-its_hammer_time" rel="nofollow noopener">Reyk Floeter</a>, <a href="https://www.youtube.com/watch?v=ufeEP_hzFN0" rel="nofollow noopener">VXLAN and Cloud-based Networking with OpenBSD</a></li>
<li>Jos Jansen, <a href="https://www.youtube.com/watch?v=gOPfRQgTjNo" rel="nofollow noopener">Adapting OS X to the enterprise</a></li>
<li><a href="http://www.bsdnow.tv/episodes/2014_04_01-edgy_bsd_users" rel="nofollow noopener">Pierre Pronchery</a> &amp; Guillaume Lasmayous, <a href="https://www.youtube.com/watch?v=vh-TjLUj6os" rel="nofollow noopener">Carve your NetBSD</a> &lt;!-- skip to 5:06 for henning trolling --&gt;</li>
<li><a href="http://www.bsdnow.tv/episodes/2014_01_22-tendresse_for_ten" rel="nofollow noopener">Colin Percival</a>, <a href="https://www.youtube.com/watch?v=jzY3m5Kv7Y8" rel="nofollow noopener">Everything you need to know about cryptography in 1 hour</a> (not from AsiaBSDCon)</li>
<li>The "bsdconferences" YouTube channel has quite a lot of interesting <a href="https://www.youtube.com/user/bsdconferences/videos?sort=da&amp;view=0&amp;flow=grid" rel="nofollow noopener">older BSD talks</a> too - you may want to go back and watch them if you haven't already
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141922027318727&amp;w=2" rel="nofollow noopener">OpenBSD PIE enhancements</a></h3>

<ul>
<li><a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a> and <a href="https://en.wikipedia.org/wiki/Position-independent_executable" rel="nofollow noopener">PIE</a> are great security features that OpenBSD has had enabled by default for a long time, in both the base system and ports, but they have one inherent problem</li>
<li>They only work with <em>dynamic</em> libraries and binaries, so if you have any static binaries, they don't get the same treatment</li>
<li>For example, the default shells (and many other things in /bin and /sbin) are statically linked</li>
<li>In the case of the static ones, you can always predict the memory layout, which is very bad and sort of <a href="https://en.wikipedia.org/wiki/Return-oriented_programming" rel="nofollow noopener">defeats the whole purpose</a></li>
<li>With this and a few <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141927571832106&amp;w=2" rel="nofollow noopener">related commits</a>, OpenBSD fixes this by introducing <strong>static self-relocation</strong></li>
<li>More and more CPU architectures are being tested and getting support too; this isn't just for amd64 and i386 - VAX users can rest easy</li>
<li>It'll be available in 5.7 in May, or you can use a <a href="http://www.openbsd.org/faq/faq5.html#BldBinary" rel="nofollow noopener">-current snapshot</a> if you want to get a <em>slice</em> of the action now
***</li>
</ul>

<h3><a href="https://www.freebsdfoundation.org/press/2014dec-newsletter.html" rel="nofollow noopener">FreeBSD foundation semi-annual newsletter</a></h3>

<ul>
<li>The FreeBSD foundation publishes a huge newsletter twice a year, detailing their funded projects and some community activities</li>
<li>As always, it starts with a letter from the president of the foundation - this time it's about encouraging students and new developers to get involved</li>
<li>The article also has a fundraising update with a list of sponsored projects, and they note that the donations meter has changed from dollars to number of donors (since they exceeded the goal already)</li>
<li>You can read summaries of all the BSD conferences of 2014 and see a list of upcoming ones next year too</li>
<li>There are also sections about the <a href="http://www.bsdnow.tv/episodes/2014_01_29-journaled_news_updates" rel="nofollow noopener">FreeBSD Journal</a>'s progress, a new staff member and a testimonial from NetApp</li>
<li>It's a very long report, so dedicate some time to read all the way through it</li>
<li>This year was pretty great for BSD: both the FreeBSD and OpenBSD foundations exceeded their goals and the NetBSD foundation came really close too</li>
<li>As we go into 2015, consider donating to <a href="https://www.freebsdfoundation.org/donate" rel="nofollow noopener">whichever</a> <a href="http://www.openbsdfoundation.org/donations.html" rel="nofollow noopener">BSD</a> <a href="https://www.netbsd.org/donations/" rel="nofollow noopener">you</a> <a href="http://www.dragonflybsd.org/donations/" rel="nofollow noopener">use</a>, it really can make a difference
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141920089614758&amp;w=4" rel="nofollow noopener">Modernizing OpenSSH fingerprints</a></h3>

<ul>
<li>When you connect to a server for the first time, you'll get what's called a fingerprint of the host's public key - this is used to verify that you're actually talking to the same server you intended to</li>
<li>Up until now, the key fingerprints have been an MD5 hash, displayed as hex</li>
<li>This <a href="https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-November/033117.html" rel="nofollow noopener">can be problematic</a>, especially for larger key types like RSA that give lots of wiggle room for collisions, as an attacker could generate a fake host key that gives the same MD5 string as the one you wanted to connect to</li>
<li>This new change replaces the default MD5 and hex with a base64-encoded SHA256 fingerprint</li>
<li>You can add a "FingerprintHash" line in your ssh_config to force using only the new type</li>
<li>There's also a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=141923470520906&amp;w=2" rel="nofollow noopener">new option</a> to require users to authenticate with <strong>more than one</strong> public key, so you can really lock down login access to your servers - also useful if you're not 100% confident in any single key type</li>
<li>The new options should be in the upcoming 6.8 release
***</li>
</ul>

<h2>Interview - Dan Langille - <a href="mailto:info@bsdcan.org" rel="nofollow noopener">info@bsdcan.org</a> / <a href="https://twitter.com/bsdcan" rel="nofollow noopener">@bsdcan</a></h2>

<p>Plans for the BSDCan 2015 conference</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://github.com/bsdphk/Ntimed" rel="nofollow noopener">Introducing ntimed, a new NTP daemon</a></h3>

<ul>
<li>As we've mentioned before in <a href="http://www.bsdnow.tv/tutorials/ntpd" rel="nofollow noopener">our tutorials</a>, there are two main daemons for the Network Time Protocol - ISC's NTPd and OpenBSD's OpenNTPD</li>
<li>With all the recent security problems with ISC's NTPd, <a href="http://www.bsdnow.tv/episodes/2013_10_16-go_directly_to_jail" rel="nofollow noopener">Poul-Henning Kamp</a> has been working on a third NTP daemon</li>
<li>It's called "ntimed" and you can try out a preview version of it right now - it's <a href="https://www.freshports.org/net/ntimed/" rel="nofollow noopener">in FreeBSD ports</a> or on Github</li>
<li>PHK also has a few <a href="http://phk.freebsd.dk/time/" rel="nofollow noopener">blog entries</a> about the project, including status updates
***</li>
</ul>

<h3><a href="http://mdocml.bsd.lv/openbsd_projects.html" rel="nofollow noopener">OpenBSD-maintained projects list</a></h3>

<ul>
<li>There was recently a read on the <a href="https://www.marc.info/?t=141961588200003&amp;r=1&amp;w=2" rel="nofollow noopener">misc mailing list</a> asking about different projects started by OpenBSD developers</li>
<li>The initial list had marks for which software had portable versions to other operating systems (OpenSSH being the most popular example)</li>
<li>A developer compiled a new list from all of the replies to that thread into a nice organized webpage</li>
<li>Most people are only familiar with things like OpenSSH, OpenSMTPD, OpenNTPD and more recently LibreSSL, but there are quite a lot more</li>
<li>This page also serves as a good history lesson for BSD in general: FreeBSD and others have ported some things over, while a couple OpenBSD tools were born from forks of FreeBSD tools (mergemaster, pkg tools, portscout)
***</li>
</ul>

<h3><a href="https://forums.freebsd.org/threads/howto-monitor-network-traffic-with-netflow-nfdump-nfsen-on-freebsd.49724/" rel="nofollow noopener">Monitoring network traffic with FreeBSD</a></h3>

<ul>
<li>If you've ever been curious about monitoring network traffic on your FreeBSD boxes, this forum post may be exactly the thing for you</li>
<li>It'll show you how to combine the Netflow, NfDump and NfSen suite of tools to get some pretty detailed network stats (and of course put them into a fancy webpage)</li>
<li>This is especially useful for finding out what was going on at a certain point in time, for example if you had a traffic spike
***</li>
</ul>

<h3><a href="http://www.protoc.org/blog/2014/12/22/trapping-spammers-with-the-openbsd-spam-deferral-daemon" rel="nofollow noopener">Trapping spammers with spamd</a></h3>

<ul>
<li>This is a blog post about OpenBSD's <a href="https://en.wikipedia.org/wiki/Spamd" rel="nofollow noopener">spamd</a> - a spam email deferral daemon - and how to use it for your mail</li>
<li>It gives some background on the greylisting approach to spam, rather than just a typical host blacklist</li>
<li>"Greylisting is a method of defending e-mail users against spam. A mail transfer agent (MTA) using greylisting will "temporarily reject" any email from a sender it does not recognize. If the sender re-attempts mail delivery at a later time, the sender may be allowed to continue the mail delivery conversation."</li>
<li>The post also shows how to combine it with PF and other tools for a pretty fancy mail setup</li>
<li>You can find spamd in the OpenBSD <a href="http://www.openbsd.org/cgi-bin/man.cgi/OpenBSD-current/man8/spamd.8" rel="nofollow noopener">base system</a>, or use it <a href="https://www.freshports.org/mail/spamd" rel="nofollow noopener">with FreeBSD</a> <a href="http://pkgsrc.se/mail/spamd" rel="nofollow noopener">or NetBSD</a> via ports and pkgsrc</li>
<li>You might also want to go back and listen to <a href="https://archive.org/details/bsdtalk068" rel="nofollow noopener">BSDTalk episode 68</a>, where Will talks to Bob Beck about spamd
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s20rUK9XVJ" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s20nfzIuT2" rel="nofollow noopener">Brandon writes in</a></li>
<li><a href="http://slexy.org/view/s20wCBhFLO" rel="nofollow noopener">Anders writes in</a></li>
<li><a href="http://slexy.org/view/s20xGrBIyl" rel="nofollow noopener">David writes in</a></li>
<li><a href="http://slexy.org/view/s2QHRaiZJW" rel="nofollow noopener">Kyle writes in</a>
***</li>
</ul>

<h2>Mailing List Gold</h2>

<ul>
<li><a href="https://www.marc.info/?l=openbsd-tech&amp;m=141903858708123&amp;w=2" rel="nofollow noopener">NTP code comparison</a> - <a href="https://www.marc.info/?l=openbsd-tech&amp;m=141905854411370&amp;w=2" rel="nofollow noopener">192870 vs. 2898</a></li>
<li><a href="https://lists.freebsd.org/pipermail/freebsd-hackers/2014-December/046741.html" rel="nofollow noopener">NICs have feelings too</a></li>
<li><a href="https://www.marc.info/?l=openbsd-ports&amp;m=141998130824977&amp;w=2" rel="nofollow noopener">Just think about it</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
