OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
eWeeks article/review of OpenBSD 3.3 (Advocacy)

From: Steven Lacroix (stevenlnexxustelecom.com)
Date: Mon Jun 02 2003 - 13:53:11 CDT


I didn't see it mentioned earlier in this mailing list; I found a fairly positive review of OBSD 3.3. Some of you may be interested in the eWEEK article on page 58 of the June 2, 2003 issue.

OpenBSD gets harder to crack
REVIEW: VERSION 3.3's ATTACK DEFENSES ARE EVEN STRONGER

Snippet: "Executive Summary"

OpenBSD 3.3: Organizations deploying firewalls or virtual private networks - and preferring to do so on servers rather than dedicated appliances-should consider the highly secure and easy-to-configure OpenBSD (www.openbsd.org). The operating system's security track record embarrasses all others, and this release continues to advance the state of the art in attack defense. The product is free to download, or a CD set can be ordered for $40.

+ (Pros) Unmatched security track record; secure-out-of-the-box deployment; packet filter provides complete traffic filtering features, along with traffic shaping and load balancing; the latest in buffer overflow prevention technology with ProPolice and page-level memory permissions.

- (Cons) Update mechanisms are labor-intensive for system administrators; memory protection features not currently available on x86 CPUs; no mandatory access control features to limit the power of root-level exploits; not well-supported by commercial server software vendors.

Steven