Aaron wrote:Thanks to everyone for answering/explaining what i know is in no way an easy question to answer with really an infinite number of answers depending on the skill set of the person answering and also the level of the person asking. Like I said originally I'm fairly new to Openbsd, and to be honest, when i read that securelevels was able to be defeated and to move to systrace, i was a little overwhelmed reading up on it and looking at the examples. The types of machines I will be running (when i feel comfortable enough with openbsd)(and am concerned about protecting, should i be more concerned about protecting my OBSD workstation too? I run pf and only allow pass out w/return traffic allowed, no services at all) will be single or dual purpose servers.. i.e. http, smtp, imap etc, not machines that are running X and all my fav ports like amule (not that i would ever download anything from there anyway, that's just not safe :-)) I don't allow remote logins even via ssh except for the local networks, I always have a firewall in front of my public servers with rate limits (overload for pf fans) and I had decided a while back i was going to forgo the new bells and whistles in the latest and greatest versions of software, due to simplicity/security's sake. and only run packages for the services I need, even though often times i get frustrated that things don't get brought current with every new release (i.e. hylafax or dspam). _NOT COMPLAINING_, just giving an example. Maybe it's good that these things came up with securelevels and systrace because to be honest , I'm not sure I would have been up for upgrading like I should with securelevels and i _know_ I would had a fit trying to get systrace policies set up, if not worse thinking i had them set up right and figuring out later they weren't and i had in fact lessened the security by putting all my trust in that system, at least at this point in my experience. From what I have comprehended both of the security mechanisms that have been "broken" still need to have someone that has gained root on the box (not that my understanding might not be flawed), which is one of the things that OpenBSD strives to disallow. For now I think I'll stick with the minimalistic type install, choosing software with a good security history, doing my best to configure things as safe (chrooting, using login.conf, running things as non-privileged users, etc...) as possible, as people have suggested, sticking with the openbsd package system and keeping a close eye on the systems via some of the suggestions made in this thread and in others on this list. Perhaps by the time systrace is fixed or the next mechanism for securing beyond default install and common sense, if the teams decides to go the fixing systrace route, I'll be better prepared to utilize those tools. Thanks to the OpenBSD team for all the work and help. Aaron
| Bart Van Assche | Integration of SCST in the mainstream Linux kernel |
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| Linus Torvalds | Linux 2.6.27 |
| Eric Paris | [RFC 0/5] [TALPA] Intro to a linux interface for on access scanning |
git: | |
| Denis Bueno | Recovering from repository corruption |
| Linus Torvalds | I'm a total push-over.. |
| J. Bruce Fields | "failed to read delta base object at..." |
| Robin Rosenberg | Re: [wishlist] graphical diff |
| GVG GVG | ssh_exchange_identification: Connection closed by remote host |
| Richard Stallman | Real men don't attack straw men |
| Marcos Laufer | dmesg IBM x3650 OpenBSD 4.3 |
| Paolo Supino | order |
| Simon Horman | Possible regression in HTB |
| Corey Hickey | SFQ: backport some features from ESFQ (try 4) |
| KOSAKI Motohiro | [bug?] tg3: Failed to load firmware "tigon/tg3_tso.bin" |
| Ingo Molnar | Re: [crash] kernel BUG at net/core/dev.c:1328! |
| usb mic not detected | 58 minutes ago | Applications and Utilities |
| Problem in Inserting a module | 1 hour ago | Linux kernel |
| Treason Uncloaked | 7 hours ago | Linux kernel |
| Shared swap partition | 18 hours ago | Linux general |
| high memory | 2 days ago | Linux kernel |
| semaphore access speed | 2 days ago | Applications and Utilities |
| the kernel how to power off the machine | 2 days ago | Linux kernel |
| Easter Eggs in windows XP | 2 days ago | Windows |
| Root password | 2 days ago | Linux general |
| Where/when DNOTIFY is used? | 2 days ago | Linux kernel |
