<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" encoding="UTF-8" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/" xmlns:atom="http://www.w3.org/2005/Atom/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:fireside="http://fireside.fm/modules/rss/fireside">
  <channel>
    <fireside:hostname>app02</fireside:hostname>
    <fireside:genDate>Fri, 19 Jun 2026 08:04:31 +0000</fireside:genDate>
    <generator>Fireside (https://fireside.fm)</generator>
    <title>BSD Now - Episodes Tagged with “Verisign”</title>
    <link>https://www.bsdnow.tv/tags/verisign</link>
    <pubDate>Wed, 02 Sep 2015 08:00:00 -0400</pubDate>
    <description>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</description>
    <language>en-us</language>
    <itunes:type>episodic</itunes:type>
    <itunes:subtitle>A weekly podcast and the place to B...SD</itunes:subtitle>
    <itunes:author>JT Pennington</itunes:author>
    <itunes:summary>Created by three guys who love BSD, we cover the latest news and have an extensive series of tutorials, as well as interviews with various people from all areas of the BSD community. It also serves as a platform for support and questions. We love and advocate FreeBSD, OpenBSD, NetBSD, DragonFlyBSD and TrueOS. Our show aims to be helpful and informative for new users that want to learn about them, but still be entertaining for the people who are already pros. The show airs on Wednesdays at 2:00PM (US Eastern time) and the edited version is usually up the following day.</itunes:summary>
    <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
    <itunes:explicit>no</itunes:explicit>
    <itunes:keywords>berkeley,freebsd,openbsd,netbsd,dragonflybsd,trueos,trident,hardenedbsd,tutorial,howto,guide,bsd,interview</itunes:keywords>
    <itunes:owner>
      <itunes:name>JT Pennington</itunes:name>
      <itunes:email>feedback@bsdnow.tv</itunes:email>
    </itunes:owner>
<itunes:category text="News">
  <itunes:category text="Tech News"/>
</itunes:category>
<itunes:category text="Education">
  <itunes:category text="How To"/>
</itunes:category>
<item>
  <title>105: Virginia BSD Assembly</title>
  <link>https://www.bsdnow.tv/105</link>
  <guid isPermaLink="false">09c955b0-1ecf-440f-9aa9-80dc2fb05a49</guid>
  <pubDate>Wed, 02 Sep 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/09c955b0-1ecf-440f-9aa9-80dc2fb05a49.mp3" length="47635924" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</itunes:subtitle>
  <itunes:duration>1:06:09</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=144104398132541&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD hypervisor coming soon&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Our buddy Mike Larkin never rests, and he posted some very tight-lipped &lt;a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener"&gt;console output&lt;/a&gt; on Twitter recently&lt;/li&gt;
&lt;li&gt;From what little he revealed &lt;a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener"&gt;at the time&lt;/a&gt;, it appeared to be a new &lt;a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener"&gt;hypervisor&lt;/a&gt; (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"&lt;/li&gt;
&lt;li&gt;Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is&lt;/li&gt;
&lt;li&gt;Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation&lt;/li&gt;
&lt;li&gt;One thing to note: this &lt;strong&gt;isn't&lt;/strong&gt; just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route&lt;/li&gt;
&lt;li&gt;He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener"&gt;Why FreeBSD should not adopt launchd&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener"&gt;Last week&lt;/a&gt; we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD&lt;/li&gt;
&lt;li&gt;One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)&lt;/li&gt;
&lt;li&gt;In this article, the author talks about why he thinks this is a bad idea&lt;/li&gt;
&lt;li&gt;He doesn't oppose the integration into FreeBSD-&lt;em&gt;derived&lt;/em&gt; projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail&lt;/li&gt;
&lt;li&gt;The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities&lt;/li&gt;
&lt;li&gt;Reddit had &lt;a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener"&gt;quite a bit&lt;/a&gt; &lt;a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener"&gt;to say&lt;/a&gt; about this one, some in agreement and some not
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener"&gt;DragonFly graphics improvements&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack&lt;/li&gt;
&lt;li&gt;This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs&lt;/li&gt;
&lt;li&gt;You should also see some power management improvements, longer battery life and various other bug fixes&lt;/li&gt;
&lt;li&gt;If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-tech&amp;amp;m=144070638327053&amp;amp;w=2" rel="nofollow noopener"&gt;OpenBSD tames the userland&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are&lt;/li&gt;
&lt;li&gt;Theo posted a &lt;em&gt;mega diff&lt;/em&gt; of nearly 100 smaller diffs, adding tame support to many areas of the userland tools&lt;/li&gt;
&lt;li&gt;It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)&lt;/li&gt;
&lt;li&gt;Some classic utilities are even being reworked to make taming them easier - &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144103945031253&amp;amp;w=2" rel="nofollow noopener"&gt;the "w" command&lt;/a&gt;, for example&lt;/li&gt;
&lt;li&gt;The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)&lt;/li&gt;
&lt;li&gt;More discussion can be found &lt;a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener"&gt;on HN&lt;/a&gt;, as one might expect&lt;/li&gt;
&lt;li&gt;If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Scott Courtney - &lt;a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener"&gt;vbsdcon@verisign.com&lt;/a&gt; / &lt;a href="https://twitter.com/verisign" rel="nofollow noopener"&gt;@verisign&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://vbsdcon.com/" rel="nofollow noopener"&gt;vBSDCon&lt;/a&gt; 2015&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener"&gt;OPNsense, beyond the fork&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We first &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;heard about&lt;/a&gt; OPNsense back in January, and they've since released nearly &lt;strong&gt;40&lt;/strong&gt; versions, spanning over &lt;strong&gt;5,000&lt;/strong&gt; commits&lt;/li&gt;
&lt;li&gt;This is their first big status update, covering some of the things that've happened since the project was born&lt;/li&gt;
&lt;li&gt;There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150827112006" rel="nofollow noopener"&gt;LibreSSL nukes SSLv3&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;With their latest release, LibreSSL began to turn off &lt;a href="http://disablessl3.com" rel="nofollow noopener"&gt;SSLv3&lt;/a&gt; support, starting with the "openssl" command&lt;/li&gt;
&lt;li&gt;At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)&lt;/li&gt;
&lt;li&gt;They've now flipped the switch, and the process of complete removal has started&lt;/li&gt;
&lt;li&gt;From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"&lt;/li&gt;
&lt;li&gt;With this change and a few more to follow shortly, Libre*SSL* won't actually &lt;em&gt;support SSL&lt;/em&gt; anymore - time to rename it "LibreTLS"
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener"&gt;FreeBSD MPTCP updated&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;For anyone unaware, &lt;a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener"&gt;Multipath TCP&lt;/a&gt; is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."&lt;/li&gt;
&lt;li&gt;There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated&lt;/li&gt;
&lt;li&gt;Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements&lt;/li&gt;
&lt;li&gt;Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144092912907778&amp;amp;w=2" rel="nofollow noopener"&gt;UEFI and GPT in OpenBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently&lt;/li&gt;
&lt;li&gt;Some &lt;a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener"&gt;support&lt;/a&gt; for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review&lt;/li&gt;
&lt;li&gt;This comes along with a &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=143732984925140&amp;amp;w=2" rel="nofollow noopener"&gt;number&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144088136200753&amp;amp;w=2" rel="nofollow noopener"&gt;of&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144046793225230&amp;amp;w=2" rel="nofollow noopener"&gt;other&lt;/a&gt; &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144045760723039&amp;amp;w=2" rel="nofollow noopener"&gt;commits&lt;/a&gt; related to GPT, much of which is being refactored and slowly reintroduced&lt;/li&gt;
&lt;li&gt;Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)&lt;/li&gt;
&lt;li&gt;The UEFI bootloader support &lt;a href="https://www.marc.info/?l=openbsd-cvs&amp;amp;m=144115942223734&amp;amp;w=2" rel="nofollow noopener"&gt;has been committed&lt;/a&gt;, so stay tuned for &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150902074526&amp;amp;mode=flat" rel="nofollow noopener"&gt;more updates&lt;/a&gt; as &lt;a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener"&gt;further&lt;/a&gt; &lt;a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener"&gt;progress&lt;/a&gt; is made
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener"&gt;John writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener"&gt;Mason writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener"&gt;Earl writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, verisign, vbsdcon, conference, eurobsdcon, bsdcan, meetbsd, asiabsdcon, nextbsd, launchd, darwin, tame, mach, libressl, vmm, hypervisor, bhyve, multipath, tcp</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144104398132541&amp;w=2" rel="nofollow noopener">OpenBSD hypervisor coming soon</a></h3>

<ul>
<li>Our buddy Mike Larkin never rests, and he posted some very tight-lipped <a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener">console output</a> on Twitter recently</li>
<li>From what little he revealed <a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener">at the time</a>, it appeared to be a new <a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener">hypervisor</a> (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"</li>
<li>Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is</li>
<li>Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation</li>
<li>One thing to note: this <strong>isn't</strong> just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route</li>
<li>He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***</li>
</ul>

<h3><a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener">Why FreeBSD should not adopt launchd</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener">Last week</a> we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD</li>
<li>One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)</li>
<li>In this article, the author talks about why he thinks this is a bad idea</li>
<li>He doesn't oppose the integration into FreeBSD-<em>derived</em> projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail</li>
<li>The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities</li>
<li>Reddit had <a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener">quite a bit</a> <a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener">to say</a> about this one, some in agreement and some not
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener">DragonFly graphics improvements</a></h3>

<ul>
<li>The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack</li>
<li>This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs</li>
<li>You should also see some power management improvements, longer battery life and various other bug fixes</li>
<li>If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144070638327053&amp;w=2" rel="nofollow noopener">OpenBSD tames the userland</a></h3>

<ul>
<li>Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are</li>
<li>Theo posted a <em>mega diff</em> of nearly 100 smaller diffs, adding tame support to many areas of the userland tools</li>
<li>It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)</li>
<li>Some classic utilities are even being reworked to make taming them easier - <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144103945031253&amp;w=2" rel="nofollow noopener">the "w" command</a>, for example</li>
<li>The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener">on HN</a>, as one might expect</li>
<li>If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***</li>
</ul>

<h2>Interview - Scott Courtney - <a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener">vbsdcon@verisign.com</a> / <a href="https://twitter.com/verisign" rel="nofollow noopener">@verisign</a></h2>

<p><a href="http://vbsdcon.com/" rel="nofollow noopener">vBSDCon</a> 2015</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener">OPNsense, beyond the fork</a></h3>

<ul>
<li>We first <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">heard about</a> OPNsense back in January, and they've since released nearly <strong>40</strong> versions, spanning over <strong>5,000</strong> commits</li>
<li>This is their first big status update, covering some of the things that've happened since the project was born</li>
<li>There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150827112006" rel="nofollow noopener">LibreSSL nukes SSLv3</a></h3>

<ul>
<li>With their latest release, LibreSSL began to turn off <a href="http://disablessl3.com" rel="nofollow noopener">SSLv3</a> support, starting with the "openssl" command</li>
<li>At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)</li>
<li>They've now flipped the switch, and the process of complete removal has started</li>
<li>From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"</li>
<li>With this change and a few more to follow shortly, Libre*SSL* won't actually <em>support SSL</em> anymore - time to rename it "LibreTLS"
***</li>
</ul>

<h3><a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener">FreeBSD MPTCP updated</a></h3>

<ul>
<li>For anyone unaware, <a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener">Multipath TCP</a> is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."</li>
<li>There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated</li>
<li>Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements</li>
<li>Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144092912907778&amp;w=2" rel="nofollow noopener">UEFI and GPT in OpenBSD</a></h3>

<ul>
<li>There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently</li>
<li>Some <a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener">support</a> for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review</li>
<li>This comes along with a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143732984925140&amp;w=2" rel="nofollow noopener">number</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144088136200753&amp;w=2" rel="nofollow noopener">of</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144046793225230&amp;w=2" rel="nofollow noopener">other</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144045760723039&amp;w=2" rel="nofollow noopener">commits</a> related to GPT, much of which is being refactored and slowly reintroduced</li>
<li>Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)</li>
<li>The UEFI bootloader support <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144115942223734&amp;w=2" rel="nofollow noopener">has been committed</a>, so stay tuned for <a href="http://undeadly.org/cgi?action=article&amp;sid=20150902074526&amp;mode=flat" rel="nofollow noopener">more updates</a> as <a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener">further</a> <a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener">progress</a> is made
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener">Earl writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>It's already our two-year anniversary! This time on the show, we'll be chatting with Scott Courtney, vice president of infrastructure engineering at Verisign, about this year's vBSDCon. What's it have to offer in an already-crowded BSD conference space? We'll find out.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144104398132541&amp;w=2" rel="nofollow noopener">OpenBSD hypervisor coming soon</a></h3>

<ul>
<li>Our buddy Mike Larkin never rests, and he posted some very tight-lipped <a href="http://pastebin.com/raw.php?i=F2Qbgdde" rel="nofollow noopener">console output</a> on Twitter recently</li>
<li>From what little he revealed <a href="https://twitter.com/mlarkin2012/status/638265767864070144" rel="nofollow noopener">at the time</a>, it appeared to be a new <a href="https://en.wikipedia.org/wiki/Hypervisor" rel="nofollow noopener">hypervisor</a> (that is, X86 hardware virtualization) running on OpenBSD -current, tentatively titled "vmm"</li>
<li>Later on, he provided a much longer explanation on the mailing list, detailing a bit about what the overall plan for the code is</li>
<li>Originally started around the time of the Australia hackathon, the work has since picked up more steam, and has gotten a funding boost from the OpenBSD foundation</li>
<li>One thing to note: this <strong>isn't</strong> just a port of something like Xen or Bhyve; it's all-new code, and Mike explains why he chose to go that route</li>
<li>He also answered some basic questions about the requirements, when it'll be available, what OSes it can run, what's left to do, how to get involved and so on
***</li>
</ul>

<h3><a href="http://blog.darknedgy.net/technology/2015/08/26/0/" rel="nofollow noopener">Why FreeBSD should not adopt launchd</a></h3>

<ul>
<li><a href="http://www.bsdnow.tv/episodes/2015_08_26-beverly_hills_25519" rel="nofollow noopener">Last week</a> we mentioned a talk Jordan Hubbard gave about integrating various parts of Mac OS X into FreeBSD</li>
<li>One of the changes, perhaps the most controversial item on the list, was the adoption of launchd to replace the init system (replacing init systems seems to cause backlash, we've learned)</li>
<li>In this article, the author talks about why he thinks this is a bad idea</li>
<li>He doesn't oppose the integration into FreeBSD-<em>derived</em> projects, like FreeNAS and PC-BSD, only vanilla FreeBSD itself - this is also explained in more detail</li>
<li>The post includes both high-level descriptions and low-level technical details, and provides an interesting outlook on the situation and possibilities</li>
<li>Reddit had <a href="https://www.reddit.com/r/BSD/comments/3ilhpk" rel="nofollow noopener">quite a bit</a> <a href="https://www.reddit.com/r/freebsd/comments/3ilj4i" rel="nofollow noopener">to say</a> about this one, some in agreement and some not
***</li>
</ul>

<h3><a href="http://lists.dragonflybsd.org/pipermail/commits/2015-August/458108.html" rel="nofollow noopener">DragonFly graphics improvements</a></h3>

<ul>
<li>The DragonFlyBSD guys are at it again, merging newer support and fixes into their i915 (Intel) graphics stack</li>
<li>This latest update brings them in sync with Linux 3.17, and includes Haswell fixes, DisplayPort fixes, improvements for Broadwell and even Cherryview GPUs</li>
<li>You should also see some power management improvements, longer battery life and various other bug fixes</li>
<li>If you're running DragonFly, especially on a laptop, you'll want to get this stuff on your machine quick - big improvements all around
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-tech&amp;m=144070638327053&amp;w=2" rel="nofollow noopener">OpenBSD tames the userland</a></h3>

<ul>
<li>Last week we mentioned OpenBSD's tame framework getting support for file whitelists, and said that the userland integration was next - well, now here we are</li>
<li>Theo posted a <em>mega diff</em> of nearly 100 smaller diffs, adding tame support to many areas of the userland tools</li>
<li>It's still a work-in-progress version; there's still more to be added (including the file path whitelist stuff)</li>
<li>Some classic utilities are even being reworked to make taming them easier - <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144103945031253&amp;w=2" rel="nofollow noopener">the "w" command</a>, for example</li>
<li>The diff provides some good insight on exactly how to restrict different types of utilities, as well as how easy it is to actually do so (and en masse)</li>
<li>More discussion can be found <a href="https://news.ycombinator.com/item?id=10135901" rel="nofollow noopener">on HN</a>, as one might expect</li>
<li>If you're a software developer, and especially if your software is in ports already, consider adding some more fine-grained tame support in your next release
***</li>
</ul>

<h2>Interview - Scott Courtney - <a href="mailto:vbsdcon@verisign.com" rel="nofollow noopener">vbsdcon@verisign.com</a> / <a href="https://twitter.com/verisign" rel="nofollow noopener">@verisign</a></h2>

<p><a href="http://vbsdcon.com/" rel="nofollow noopener">vBSDCon</a> 2015</p>

<hr>

<h2>News Roundup</h2>

<h3><a href="https://opnsense.org/opnsense-beyond-the-fork" rel="nofollow noopener">OPNsense, beyond the fork</a></h3>

<ul>
<li>We first <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">heard about</a> OPNsense back in January, and they've since released nearly <strong>40</strong> versions, spanning over <strong>5,000</strong> commits</li>
<li>This is their first big status update, covering some of the things that've happened since the project was born</li>
<li>There's been a lot of community growth and participation, mass bug fixing, new features added, experimental builds with ASLR and much more - the report touches on a little of everything
***</li>
</ul>

<h3><a href="http://undeadly.org/cgi?action=article&amp;sid=20150827112006" rel="nofollow noopener">LibreSSL nukes SSLv3</a></h3>

<ul>
<li>With their latest release, LibreSSL began to turn off <a href="http://disablessl3.com" rel="nofollow noopener">SSLv3</a> support, starting with the "openssl" command</li>
<li>At the time, SSLv3 wasn't disabled entirely because of some things in the OpenBSD ports tree requiring it (apache being one odd example)</li>
<li>They've now flipped the switch, and the process of complete removal has started</li>
<li>From the Undeadly summary, "This is an important step for the security of the LibreSSL library and, by extension, the ports tree. It does, however, require lots of testing of the resulting packages, as some of the fallout may be at runtime (so not detected during the build). That is part of why this is committed at this point during the release cycle: it gives the community more time to test packages and report issues so that these can be fixed. When these fixes are then pushed upstream, the entire software ecosystem will benefit. In short: you know what to do!"</li>
<li>With this change and a few more to follow shortly, Libre*SSL* won't actually <em>support SSL</em> anymore - time to rename it "LibreTLS"
***</li>
</ul>

<h3><a href="http://caia.swin.edu.au/urp/newtcp/mptcp/tools/v05/mptcp-readme-v0.5.txt" rel="nofollow noopener">FreeBSD MPTCP updated</a></h3>

<ul>
<li>For anyone unaware, <a href="https://en.wikipedia.org/wiki/Multipath_TCP" rel="nofollow noopener">Multipath TCP</a> is "an ongoing effort of the Internet Engineering Task Force's (IETF) Multipath TCP working group, that aims at allowing a Transmission Control Protocol (TCP) connection to use multiple paths to maximize resource usage and increase redundancy."</li>
<li>There's been work out of an Australian university to add support for it to the FreeBSD kernel, and the patchset was recently updated</li>
<li>Including in this latest version is an overview of the protocol, how to get it compiled in, current features and limitations and some info about the routing requirements</li>
<li>Some big performance gains can be had with MPTCP, but only if both the client and server systems support it - getting it into the FreeBSD kernel would be a good start
***</li>
</ul>

<h3><a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144092912907778&amp;w=2" rel="nofollow noopener">UEFI and GPT in OpenBSD</a></h3>

<ul>
<li>There hasn't been much fanfare about it yet, but some initial UEFI and GPT-related commits have been creeping into OpenBSD recently</li>
<li>Some <a href="https://github.com/yasuoka/openbsd-uefi" rel="nofollow noopener">support</a> for UEFI booting has landed in the kernel, and more bits are being slowly enabled after review</li>
<li>This comes along with a <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=143732984925140&amp;w=2" rel="nofollow noopener">number</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144088136200753&amp;w=2" rel="nofollow noopener">of</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144046793225230&amp;w=2" rel="nofollow noopener">other</a> <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144045760723039&amp;w=2" rel="nofollow noopener">commits</a> related to GPT, much of which is being refactored and slowly reintroduced</li>
<li>Currently, you have to do some disklabel wizardry to bypass the MBR limit and access more than 2TB of space on a single drive, but it should "just work" with GPT (once everything's in)</li>
<li>The UEFI bootloader support <a href="https://www.marc.info/?l=openbsd-cvs&amp;m=144115942223734&amp;w=2" rel="nofollow noopener">has been committed</a>, so stay tuned for <a href="http://undeadly.org/cgi?action=article&amp;sid=20150902074526&amp;mode=flat" rel="nofollow noopener">more updates</a> as <a href="https://twitter.com/kotatsu_mi/status/638909417761562624" rel="nofollow noopener">further</a> <a href="https://twitter.com/yojiro/status/638189353601097728" rel="nofollow noopener">progress</a> is made
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2sIWfb3Qh" rel="nofollow noopener">John writes in</a></li>
<li><a href="http://slexy.org/view/s2Ybrx00KI" rel="nofollow noopener">Mason writes in</a></li>
<li><a href="http://slexy.org/view/s20FpmR7ZW" rel="nofollow noopener">Earl writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
<item>
  <title>89: Exclusive Disjunction</title>
  <link>https://www.bsdnow.tv/89</link>
  <guid isPermaLink="false">e47f088b-2b32-4187-92cd-0f4be4f1426e</guid>
  <pubDate>Wed, 13 May 2015 08:00:00 -0400</pubDate>
  <author>JT Pennington</author>
  <enclosure url="https://aphid.fireside.fm/d/1437767933/c91b88f1-e824-4815-bcb8-5227818d6010/e47f088b-2b32-4187-92cd-0f4be4f1426e.mp3" length="45530932" type="audio/mpeg"/>
  <itunes:episodeType>full</itunes:episodeType>
  <itunes:author>JT Pennington</itunes:author>
  <itunes:subtitle>This week on the show, we'll be talking to Mike Larkin about various memory protections in OpenBSD. We'll cover recent W^X improvements, SSP, ASLR, PIE and all kinds of acronyms! We've also got a bunch of news and answers to your questions, coming up on BSD Now - the place to B.. SD.</itunes:subtitle>
  <itunes:duration>1:03:14</itunes:duration>
  <itunes:explicit>no</itunes:explicit>
  <itunes:image href="https://media24.fireside.fm/file/fireside-images-2024/podcasts/images/c/c91b88f1-e824-4815-bcb8-5227818d6010/cover.jpg?v=4"/>
  <description>&lt;p&gt;This week on the show, we'll be talking to Mike Larkin about various memory protections in OpenBSD. We'll cover recent W&lt;sup&gt;X&lt;/sup&gt; improvements, SSP, ASLR, PIE and all kinds of acronyms! We've also got a bunch of news and answers to your questions, coming up on BSD Now - the place to B.. SD.&lt;/p&gt;

&lt;h2&gt;This episode was brought to you by&lt;/h2&gt;

&lt;p&gt;&lt;a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"&gt;&lt;img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"&gt;&lt;/a&gt;&lt;a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"&gt;&lt;img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"&gt;&lt;/a&gt;&lt;a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"&gt;&lt;img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;Headlines&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://homing-on-code.blogspot.com/2015/05/accept-from-any-for-any-relay-via.html" rel="nofollow noopener"&gt;OpenSMTPD for the whole family&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Setting up a BSD mail server is something a lot of us are probably familiar with doing, at least for our own accounts&lt;/li&gt;
&lt;li&gt;This article talks about configuring a home mail server too, but even for the other people you live with&lt;/li&gt;
&lt;li&gt;After convincing his wife to use their BSD-based Owncloud server for backups, the author talks about moving her over to his brand new OpenSMTPD server too&lt;/li&gt;
&lt;li&gt;If you've ever run a mail server and had to deal with greylisting, you'll appreciate the struggle he went through&lt;/li&gt;
&lt;li&gt;In the end, BGP-based list distribution saved the day, and his family is being served well by a BSD box
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://blog.netbsd.org/tnf/entry/hands_on_experience_with_edgerouter" rel="nofollow noopener"&gt;NetBSD on the Edgerouter Lite&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've talked a lot about building your own BSD-based router on the show, but not many of the devices we mention are in the same price range as consumer devices&lt;/li&gt;
&lt;li&gt;The EdgeRouter Lite, a small MIPS-powered machine, is starting to become popular (and is a bit cheaper)&lt;/li&gt;
&lt;li&gt;A NetBSD developer has been hacking on it, and documents the steps to get a working install in this blog post&lt;/li&gt;
&lt;li&gt;The process is fairly simple, and you can &lt;a href="http://www.bsdnow.tv/tutorials/current-nbsd" rel="nofollow noopener"&gt;cross-compile&lt;/a&gt; your own installation image on any CPU architecture (even from another BSD!)&lt;/li&gt;
&lt;li&gt;OpenBSD and FreeBSD also have &lt;a href="http://www.openbsd.org/octeon.html" rel="nofollow noopener"&gt;some&lt;/a&gt; &lt;a href="http://rtfm.net/FreeBSD/ERL/" rel="nofollow noopener"&gt;support&lt;/a&gt; for these devices
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://www.youtube.com/watch?v=h4FhgBdYSUU" rel="nofollow noopener"&gt;Bitrig at NYC*BUG&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The New York City BSD users group has semi-regular meetings with presentations, and this time the speaker was John Vernaleo&lt;/li&gt;
&lt;li&gt;John discussed &lt;a href="http://www.bsdnow.tv/episodes/2014_12_10-must_be_rigged" rel="nofollow noopener"&gt;Bitrig&lt;/a&gt;, an OpenBSD fork that we've talked about a couple times on the show&lt;/li&gt;
&lt;li&gt;He talks about what they've been up to lately, why they're doing what they're doing, difference in supported platforms&lt;/li&gt;
&lt;li&gt;Ports and packages between the two projects are almost exactly the same, but he covers the differences in the base systems, how (some) patches get shared between the two and finally some development model differences
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener"&gt;OPNsense, meet HardenedBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Speaking of forks, two FreeBSD-based forked projects we've mentioned on the show, &lt;a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener"&gt;HardenedBSD&lt;/a&gt; and &lt;a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener"&gt;OPNsense&lt;/a&gt;, have decided to join forces&lt;/li&gt;
&lt;li&gt;Backporting their changes to the 10-STABLE branch, HardenedBSD hopes to introduce some of their security additions to the OPNsense codebase&lt;/li&gt;
&lt;li&gt;Paired up with LibreSSL, this combination should offer a good solution for anyone wanting a BSD-based firewall with an easy web interface&lt;/li&gt;
&lt;li&gt;We'll cover more news on the collaboration as it comes out
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Interview - Mike Larkin - &lt;a href="mailto:mlarkin@openbsd.org" rel="nofollow noopener"&gt;mlarkin@openbsd.org&lt;/a&gt; / &lt;a href="https://twitter.com/mlarkin2012" rel="nofollow noopener"&gt;@mlarkin2012&lt;/a&gt;&lt;/h2&gt;

&lt;p&gt;Memory protections in OpenBSD: &lt;a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener"&gt;W&lt;sup&gt;X&lt;/sup&gt;&lt;/a&gt;, &lt;a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener"&gt;ASLR&lt;/a&gt;, &lt;a href="https://en.wikipedia.org/wiki/Position-independent_code" rel="nofollow noopener"&gt;PIE&lt;/a&gt;, &lt;a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener"&gt;SSP&lt;/a&gt;&lt;/p&gt;

&lt;hr&gt;

&lt;h2&gt;News Roundup&lt;/h2&gt;

&lt;h3&gt;&lt;a href="http://www.techopedia.com/2/31035/software/a-closer-look-at-freebsd" rel="nofollow noopener"&gt;A closer look at FreeBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The week wouldn't be complete without at least one BSD article making it to a mainstream tech site&lt;/li&gt;
&lt;li&gt;This time, it's a high-level overview of FreeBSD, some of its features and where it's used&lt;/li&gt;
&lt;li&gt;Being that it's an overview article on a more mainstream site, you won't find anything too technical - it covers some BSD history, stability, ZFS, LLVM and Clang, ports and packages, jails and the licensing&lt;/li&gt;
&lt;li&gt;If you have any BSD-curious Linux friends, this might be a good one to send to them
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://ramblingfoo.blogspot.com/2015/05/linksys-nslu2-adventures-into-netbsd.html" rel="nofollow noopener"&gt;Linksys NSLU2 and NetBSD&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The Linksys NSLU2 is a proprietary network-attached storage device introduced back in 2004&lt;/li&gt;
&lt;li&gt;"About 2 months ago I set a goal to run some kind of BSD on the spare Linksys NSLU2 I had. This was driven mostly by curiosity, after listening to a few BSDNow episodes and becoming a regular listener [...]"&lt;/li&gt;
&lt;li&gt;After doing some research, the author of this post discovered that he could cross-compile NetBSD for the device straight from his Linux box&lt;/li&gt;
&lt;li&gt;If you've got one of these old devices kicking around, check out this write-up and get some BSD action on there
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="http://blog.jeffreyforman.net/2015/05/09/from-0-to-an-openbsd-install-with-no-hands-and-a-custom-disk-layou" rel="nofollow noopener"&gt;OpenBSD disklabel templates&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;We've covered OpenBSD's "autoinstall" feature for unattended installations in the past, but one area where it didn't offer a lot of customization was with the disk layout&lt;/li&gt;
&lt;li&gt;With a few &lt;a href="http://undeadly.org/cgi?action=article&amp;amp;sid=20150505123418" rel="nofollow noopener"&gt;recent changes&lt;/a&gt;, there are now a series of templates you can use for a completely customized partition scheme&lt;/li&gt;
&lt;li&gt;This article takes you through the process of configuring an autoinstall answer file and adding the new section for disklabel&lt;/li&gt;
&lt;li&gt;Combine this new feature with our &lt;a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener"&gt;-stable iso tutorial&lt;/a&gt;, and you could deploy completely patched and customized images en masse pretty easily
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;&lt;a href="https://svnweb.freebsd.org/base?view=revision&amp;amp;revision=282693" rel="nofollow noopener"&gt;FreeBSD native ARM builds&lt;/a&gt;&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;FreeBSD -CURRENT builds for the ARM CPU architecture can now be built natively, without utilities that aren't part of base&lt;/li&gt;
&lt;li&gt;Some of the older board-specific kernel configuration files have been replaced, and now the "IMC6" target is used&lt;/li&gt;
&lt;li&gt;This goes along with what we read in the most recent quarterly status report - ARM is starting to get treated as a first class citizen
***&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;Feedback/Questions&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2088U2OjO" rel="nofollow noopener"&gt;Sean writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s29ZKhQKOz" rel="nofollow noopener"&gt;Ron writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2NCVHEKt1" rel="nofollow noopener"&gt;Charles writes in&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://slexy.org/view/s2mGRoKo5G" rel="nofollow noopener"&gt;Bostjan writes in&lt;/a&gt;
*** &lt;/li&gt;
&lt;/ul&gt;
</description>
  <itunes:keywords>freebsd, openbsd, netbsd, dragonflybsd, pcbsd, tutorial, howto, guide, bsd, interview, verisign, vbsdcon, 2015, presentations, talks, w^x, aslr, pie, ssp, stack smashing, gcc, exploit mitigation, security, edgerouter lite, opnsense, hardenedbsd, bitrig</itunes:keywords>
  <content:encoded>
    <![CDATA[<p>This week on the show, we'll be talking to Mike Larkin about various memory protections in OpenBSD. We'll cover recent W<sup>X</sup> improvements, SSP, ASLR, PIE and all kinds of acronyms! We've also got a bunch of news and answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://homing-on-code.blogspot.com/2015/05/accept-from-any-for-any-relay-via.html" rel="nofollow noopener">OpenSMTPD for the whole family</a></h3>

<ul>
<li>Setting up a BSD mail server is something a lot of us are probably familiar with doing, at least for our own accounts</li>
<li>This article talks about configuring a home mail server too, but even for the other people you live with</li>
<li>After convincing his wife to use their BSD-based Owncloud server for backups, the author talks about moving her over to his brand new OpenSMTPD server too</li>
<li>If you've ever run a mail server and had to deal with greylisting, you'll appreciate the struggle he went through</li>
<li>In the end, BGP-based list distribution saved the day, and his family is being served well by a BSD box
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/hands_on_experience_with_edgerouter" rel="nofollow noopener">NetBSD on the Edgerouter Lite</a></h3>

<ul>
<li>We've talked a lot about building your own BSD-based router on the show, but not many of the devices we mention are in the same price range as consumer devices</li>
<li>The EdgeRouter Lite, a small MIPS-powered machine, is starting to become popular (and is a bit cheaper)</li>
<li>A NetBSD developer has been hacking on it, and documents the steps to get a working install in this blog post</li>
<li>The process is fairly simple, and you can <a href="http://www.bsdnow.tv/tutorials/current-nbsd" rel="nofollow noopener">cross-compile</a> your own installation image on any CPU architecture (even from another BSD!)</li>
<li>OpenBSD and FreeBSD also have <a href="http://www.openbsd.org/octeon.html" rel="nofollow noopener">some</a> <a href="http://rtfm.net/FreeBSD/ERL/" rel="nofollow noopener">support</a> for these devices
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=h4FhgBdYSUU" rel="nofollow noopener">Bitrig at NYC*BUG</a></h3>

<ul>
<li>The New York City BSD users group has semi-regular meetings with presentations, and this time the speaker was John Vernaleo</li>
<li>John discussed <a href="http://www.bsdnow.tv/episodes/2014_12_10-must_be_rigged" rel="nofollow noopener">Bitrig</a>, an OpenBSD fork that we've talked about a couple times on the show</li>
<li>He talks about what they've been up to lately, why they're doing what they're doing, difference in supported platforms</li>
<li>Ports and packages between the two projects are almost exactly the same, but he covers the differences in the base systems, how (some) patches get shared between the two and finally some development model differences
***</li>
</ul>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener">OPNsense, meet HardenedBSD</a></h3>

<ul>
<li>Speaking of forks, two FreeBSD-based forked projects we've mentioned on the show, <a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener">HardenedBSD</a> and <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a>, have decided to join forces</li>
<li>Backporting their changes to the 10-STABLE branch, HardenedBSD hopes to introduce some of their security additions to the OPNsense codebase</li>
<li>Paired up with LibreSSL, this combination should offer a good solution for anyone wanting a BSD-based firewall with an easy web interface</li>
<li>We'll cover more news on the collaboration as it comes out
***</li>
</ul>

<h2>Interview - Mike Larkin - <a href="mailto:mlarkin@openbsd.org" rel="nofollow noopener">mlarkin@openbsd.org</a> / <a href="https://twitter.com/mlarkin2012" rel="nofollow noopener">@mlarkin2012</a></h2>

<p>Memory protections in OpenBSD: <a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener">W<sup>X</sup></a>, <a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a>, <a href="https://en.wikipedia.org/wiki/Position-independent_code" rel="nofollow noopener">PIE</a>, <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener">SSP</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.techopedia.com/2/31035/software/a-closer-look-at-freebsd" rel="nofollow noopener">A closer look at FreeBSD</a></h3>

<ul>
<li>The week wouldn't be complete without at least one BSD article making it to a mainstream tech site</li>
<li>This time, it's a high-level overview of FreeBSD, some of its features and where it's used</li>
<li>Being that it's an overview article on a more mainstream site, you won't find anything too technical - it covers some BSD history, stability, ZFS, LLVM and Clang, ports and packages, jails and the licensing</li>
<li>If you have any BSD-curious Linux friends, this might be a good one to send to them
***</li>
</ul>

<h3><a href="http://ramblingfoo.blogspot.com/2015/05/linksys-nslu2-adventures-into-netbsd.html" rel="nofollow noopener">Linksys NSLU2 and NetBSD</a></h3>

<ul>
<li>The Linksys NSLU2 is a proprietary network-attached storage device introduced back in 2004</li>
<li>"About 2 months ago I set a goal to run some kind of BSD on the spare Linksys NSLU2 I had. This was driven mostly by curiosity, after listening to a few BSDNow episodes and becoming a regular listener [...]"</li>
<li>After doing some research, the author of this post discovered that he could cross-compile NetBSD for the device straight from his Linux box</li>
<li>If you've got one of these old devices kicking around, check out this write-up and get some BSD action on there
***</li>
</ul>

<h3><a href="http://blog.jeffreyforman.net/2015/05/09/from-0-to-an-openbsd-install-with-no-hands-and-a-custom-disk-layou" rel="nofollow noopener">OpenBSD disklabel templates</a></h3>

<ul>
<li>We've covered OpenBSD's "autoinstall" feature for unattended installations in the past, but one area where it didn't offer a lot of customization was with the disk layout</li>
<li>With a few <a href="http://undeadly.org/cgi?action=article&amp;sid=20150505123418" rel="nofollow noopener">recent changes</a>, there are now a series of templates you can use for a completely customized partition scheme</li>
<li>This article takes you through the process of configuring an autoinstall answer file and adding the new section for disklabel</li>
<li>Combine this new feature with our <a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener">-stable iso tutorial</a>, and you could deploy completely patched and customized images en masse pretty easily
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=282693" rel="nofollow noopener">FreeBSD native ARM builds</a></h3>

<ul>
<li>FreeBSD -CURRENT builds for the ARM CPU architecture can now be built natively, without utilities that aren't part of base</li>
<li>Some of the older board-specific kernel configuration files have been replaced, and now the "IMC6" target is used</li>
<li>This goes along with what we read in the most recent quarterly status report - ARM is starting to get treated as a first class citizen
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2088U2OjO" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s29ZKhQKOz" rel="nofollow noopener">Ron writes in</a></li>
<li><a href="http://slexy.org/view/s2NCVHEKt1" rel="nofollow noopener">Charles writes in</a></li>
<li><a href="http://slexy.org/view/s2mGRoKo5G" rel="nofollow noopener">Bostjan writes in</a>
***</li>
</ul>]]>
  </content:encoded>
  <itunes:summary>
    <![CDATA[<p>This week on the show, we'll be talking to Mike Larkin about various memory protections in OpenBSD. We'll cover recent W<sup>X</sup> improvements, SSP, ASLR, PIE and all kinds of acronyms! We've also got a bunch of news and answers to your questions, coming up on BSD Now - the place to B.. SD.</p>

<h2>This episode was brought to you by</h2>

<p><a href="http://www.ixsystems.com/bsdnow" title="iXsystems" rel="nofollow noopener"><img src="/images/1.png" alt="iXsystems - Enterprise Servers and Storage for Open Source"></a><a href="http://www.digitalocean.com/" title="DigitalOcean" rel="nofollow noopener"><img src="/images/2.png" alt="DigitalOcean - Simple Cloud Hosting, Built for Developers"></a><a href="http://www.tarsnap.com/bsdnow" title="Tarsnap" rel="nofollow noopener"><img src="/images/3.png" alt="Tarsnap - Online Backups for the Truly Paranoid"></a></p>

<hr>

<h2>Headlines</h2>

<h3><a href="http://homing-on-code.blogspot.com/2015/05/accept-from-any-for-any-relay-via.html" rel="nofollow noopener">OpenSMTPD for the whole family</a></h3>

<ul>
<li>Setting up a BSD mail server is something a lot of us are probably familiar with doing, at least for our own accounts</li>
<li>This article talks about configuring a home mail server too, but even for the other people you live with</li>
<li>After convincing his wife to use their BSD-based Owncloud server for backups, the author talks about moving her over to his brand new OpenSMTPD server too</li>
<li>If you've ever run a mail server and had to deal with greylisting, you'll appreciate the struggle he went through</li>
<li>In the end, BGP-based list distribution saved the day, and his family is being served well by a BSD box
***</li>
</ul>

<h3><a href="https://blog.netbsd.org/tnf/entry/hands_on_experience_with_edgerouter" rel="nofollow noopener">NetBSD on the Edgerouter Lite</a></h3>

<ul>
<li>We've talked a lot about building your own BSD-based router on the show, but not many of the devices we mention are in the same price range as consumer devices</li>
<li>The EdgeRouter Lite, a small MIPS-powered machine, is starting to become popular (and is a bit cheaper)</li>
<li>A NetBSD developer has been hacking on it, and documents the steps to get a working install in this blog post</li>
<li>The process is fairly simple, and you can <a href="http://www.bsdnow.tv/tutorials/current-nbsd" rel="nofollow noopener">cross-compile</a> your own installation image on any CPU architecture (even from another BSD!)</li>
<li>OpenBSD and FreeBSD also have <a href="http://www.openbsd.org/octeon.html" rel="nofollow noopener">some</a> <a href="http://rtfm.net/FreeBSD/ERL/" rel="nofollow noopener">support</a> for these devices
***</li>
</ul>

<h3><a href="https://www.youtube.com/watch?v=h4FhgBdYSUU" rel="nofollow noopener">Bitrig at NYC*BUG</a></h3>

<ul>
<li>The New York City BSD users group has semi-regular meetings with presentations, and this time the speaker was John Vernaleo</li>
<li>John discussed <a href="http://www.bsdnow.tv/episodes/2014_12_10-must_be_rigged" rel="nofollow noopener">Bitrig</a>, an OpenBSD fork that we've talked about a couple times on the show</li>
<li>He talks about what they've been up to lately, why they're doing what they're doing, difference in supported platforms</li>
<li>Ports and packages between the two projects are almost exactly the same, but he covers the differences in the base systems, how (some) patches get shared between the two and finally some development model differences
***</li>
</ul>

<h3><a href="https://hardenedbsd.org/article/shawn-webb/2015-05-08/hardenedbsd-teams-opnsense" rel="nofollow noopener">OPNsense, meet HardenedBSD</a></h3>

<ul>
<li>Speaking of forks, two FreeBSD-based forked projects we've mentioned on the show, <a href="http://www.bsdnow.tv/episodes/2014_08_27-reverse_takeover" rel="nofollow noopener">HardenedBSD</a> and <a href="http://www.bsdnow.tv/episodes/2015_01_14-common_sense_approach" rel="nofollow noopener">OPNsense</a>, have decided to join forces</li>
<li>Backporting their changes to the 10-STABLE branch, HardenedBSD hopes to introduce some of their security additions to the OPNsense codebase</li>
<li>Paired up with LibreSSL, this combination should offer a good solution for anyone wanting a BSD-based firewall with an easy web interface</li>
<li>We'll cover more news on the collaboration as it comes out
***</li>
</ul>

<h2>Interview - Mike Larkin - <a href="mailto:mlarkin@openbsd.org" rel="nofollow noopener">mlarkin@openbsd.org</a> / <a href="https://twitter.com/mlarkin2012" rel="nofollow noopener">@mlarkin2012</a></h2>

<p>Memory protections in OpenBSD: <a href="https://en.wikipedia.org/wiki/W%5EX" rel="nofollow noopener">W<sup>X</sup></a>, <a href="https://en.wikipedia.org/wiki/Address_space_layout_randomization" rel="nofollow noopener">ASLR</a>, <a href="https://en.wikipedia.org/wiki/Position-independent_code" rel="nofollow noopener">PIE</a>, <a href="https://en.wikipedia.org/wiki/Buffer_overflow_protection" rel="nofollow noopener">SSP</a></p>

<hr>

<h2>News Roundup</h2>

<h3><a href="http://www.techopedia.com/2/31035/software/a-closer-look-at-freebsd" rel="nofollow noopener">A closer look at FreeBSD</a></h3>

<ul>
<li>The week wouldn't be complete without at least one BSD article making it to a mainstream tech site</li>
<li>This time, it's a high-level overview of FreeBSD, some of its features and where it's used</li>
<li>Being that it's an overview article on a more mainstream site, you won't find anything too technical - it covers some BSD history, stability, ZFS, LLVM and Clang, ports and packages, jails and the licensing</li>
<li>If you have any BSD-curious Linux friends, this might be a good one to send to them
***</li>
</ul>

<h3><a href="http://ramblingfoo.blogspot.com/2015/05/linksys-nslu2-adventures-into-netbsd.html" rel="nofollow noopener">Linksys NSLU2 and NetBSD</a></h3>

<ul>
<li>The Linksys NSLU2 is a proprietary network-attached storage device introduced back in 2004</li>
<li>"About 2 months ago I set a goal to run some kind of BSD on the spare Linksys NSLU2 I had. This was driven mostly by curiosity, after listening to a few BSDNow episodes and becoming a regular listener [...]"</li>
<li>After doing some research, the author of this post discovered that he could cross-compile NetBSD for the device straight from his Linux box</li>
<li>If you've got one of these old devices kicking around, check out this write-up and get some BSD action on there
***</li>
</ul>

<h3><a href="http://blog.jeffreyforman.net/2015/05/09/from-0-to-an-openbsd-install-with-no-hands-and-a-custom-disk-layou" rel="nofollow noopener">OpenBSD disklabel templates</a></h3>

<ul>
<li>We've covered OpenBSD's "autoinstall" feature for unattended installations in the past, but one area where it didn't offer a lot of customization was with the disk layout</li>
<li>With a few <a href="http://undeadly.org/cgi?action=article&amp;sid=20150505123418" rel="nofollow noopener">recent changes</a>, there are now a series of templates you can use for a completely customized partition scheme</li>
<li>This article takes you through the process of configuring an autoinstall answer file and adding the new section for disklabel</li>
<li>Combine this new feature with our <a href="http://www.bsdnow.tv/tutorials/stable-iso" rel="nofollow noopener">-stable iso tutorial</a>, and you could deploy completely patched and customized images en masse pretty easily
***</li>
</ul>

<h3><a href="https://svnweb.freebsd.org/base?view=revision&amp;revision=282693" rel="nofollow noopener">FreeBSD native ARM builds</a></h3>

<ul>
<li>FreeBSD -CURRENT builds for the ARM CPU architecture can now be built natively, without utilities that aren't part of base</li>
<li>Some of the older board-specific kernel configuration files have been replaced, and now the "IMC6" target is used</li>
<li>This goes along with what we read in the most recent quarterly status report - ARM is starting to get treated as a first class citizen
***</li>
</ul>

<h2>Feedback/Questions</h2>

<ul>
<li><a href="http://slexy.org/view/s2088U2OjO" rel="nofollow noopener">Sean writes in</a></li>
<li><a href="http://slexy.org/view/s29ZKhQKOz" rel="nofollow noopener">Ron writes in</a></li>
<li><a href="http://slexy.org/view/s2NCVHEKt1" rel="nofollow noopener">Charles writes in</a></li>
<li><a href="http://slexy.org/view/s2mGRoKo5G" rel="nofollow noopener">Bostjan writes in</a>
***</li>
</ul>]]>
  </itunes:summary>
</item>
  </channel>
</rss>
