למה לא עוברים ל openbsd ?

eranb2

New member
תמיכה דווקא יש

"איזו חברה מסחרית אתה מכיר שמוכרת OpenBSD?"

http://www.openbsd.org/support.html

-----------------


רציתי להגיד שיוניקס מסחרי כמו יב"מ או hp או סולריס זה התשובה, לא יודע , sco unix זה רק דוגמא לא טובה.


בכל אופן, בארץ עובדים עם : linux , php , mysql joomla , drupal , שנחשבים ללא משהו באבטחה.
בחו"ל עובדים יותר עם דברים אחרים, עובדה שבנו אותם ויש להם אתרים וקהילה די רציניים.


http://plone.org/products/plone/security/overview



למה דביאן הכניסה את הקרנל של bsd ?

http://www.debian.org/ports/kfreebsd-gnu/
 

BravoMan

Active member
לא אמרתי "תמיכה".

החברות ברשימה הן חברות שנותנות שירותים שונים, רובן (אם לא כולן, לא בדקתי לעומק) עובדות גם עם לינוקס.

אבל לפי מה שראיתי, אף אחת מהן לא מוכרת מוצר מוגמר כמו ש-Red Hat עושה.

זה אולי טוב לעסקים קטנים או בינוניים, אבל אף תאגיד לא יביא מערכת בעצמו ואז ישכור חברה שתעזור לו לתפעל אותה. הם מחפשים מוצר "מ א' עד ת'" שיש לו אמא, אבא (ומשפחה שלמה), וזאת לאו דווקא כי זה מבטיח מוצר יותר איכותי, אלא כי ככה החברות האלה בנויות וככה מחלקות רכש שלהן מחונכות.

בחו"ל עובדים עם דברים אחרים?
https://en-gb.facebook.com/careers/teams/infrastructure
שים לב לרשימת הטכנולוגיות שהם משתמשים, זה בפסקה הראשונה.

http://en.wikipedia.org/wiki/Google_platform#Software
שים לב על מה השרתים שלהם רצים.

והנה עוד סתם חברה אמריקאית קטנה שאין להם מושג מהחיים שלהם:
http://www.zdnet.com/blog/open-sour...-of-almost-half-a-million-linux-servers/10620

בארץ דווקא אוהבים מוצרים של MS, שים לב באיזו טכנולוגיה האת הזה כתוב.

באשר ל-Debian, יש להם גם גרסה עם Hurd למרות שאף אחד לא משתמש בזה ל-production למיטב ידיעתי:
http://www.debian.org/ports/hurd

הסיבה לכך היא ש-Debian מתיימרת להיות "מערכת הפעלה אוניברסלית". זה אפילו כתוב מתחת לשם שלהם בעמוד הראשי של האתר.

הם לא רוצים להיות "סתם עוד הפצת לינוקס" הם רוצים לרוץ על כל מה שאפשר. הם כוללים תמיכה ב-ARM ו-MIPS וזאת לא רק ל-kernel אלא לכל (או לפחות רוב) החבילות שלהם.

בנוסף, הם מתגאים בכך שהם מספקים לא רק מערכת הפעלה בסיסית אלא עוד 29 אלף חבילות תוכנה - בקיצור "One stop shop".
 

eranb2

New member
===Privilege_separation===

http://en.wikipedia.org/wiki/Privilege_separation
---

הלינק שצירפתי בהתחלה:
http://allthatiswrong.wordpress.com/2010/01/20/the-insecurity-of-openbsd/

דווקא טוען במקור שהמערכת הזאת לא מאובטחת, כמה דוגמאות מהקישור :
In terms of OpenBSD, it’s really not a solid operating system for system administrators
---
I’ve run, configured and administered OpenBSD systems, and it was always a chore
---
The problems start when you start installing applications. And OpenBSD is the same in this regard.
But Linux has better second level defense.

---

“Why OpenBSD will never be as secure as Linux” – http://www.seifried.org/security/os/20011107-openbsd-linux.html
“Why Linux will never be as secure as OpenBSD” – http://www.seifried.org/security/os/20011107-linux-openbsd.html


===================================

הקטע הזה זה מה שאני לא מבין, זה סותר את הטענה המרכזית שלכם ושל כותב המאמר לאורך כל הדרך, הטענה של : openbsd אין יתרון על מערכות אחרות כי ההתקפה תהיה על : php , mysql ולא על המערכת הפעלה עצמה.

> Since the majority of attacks are not against the base system but against software operating at a higher level actively
> listening over the network, it is likely that if an OpenBSD machine were attacked, it would be through such software.
> This is where OpenBSD falls down, as it provides no means to protect from damage in the event of a successful attack.

What BS! You don’t seem to be aware that OpenBSD lead the charge years ago for “priv sep”, and to this day installs
every single ‘ports/packages’ daemon with a distinct, non-privileged userid – a good idea which not only proves that your
statement above is based on ignorance, but provides “secure by default” a strong measure of what the formal approaches claim to offer
but make complex to implement. And it’s also been copied into leading Linux distributions, e.g., Android does exactly the
same thing for every app you install.

===

OpenBSD doesn’t need these controls because of proper priv seg. This is why whenever you hear about yet another X vuln it doesn’t affect OpenBSD because of how they’ve separated the running process from users. Linux doesn’t have this, no distro I know of does it.
===


ממה שאני מבין מכל הסיפור , הצוות של openbsd ביטל את כל אופציות ההגנה הכבדות שיש למערכות אחרות "שבאות מעל" והם בנו מערכת הפעלה שמגנה על עצמה ברמת השורש.




אני אישית לא מבין באבטחה ולא בתכנות אבל אני מאמין שהם כן מבינים בזה יותר מכל אחד אחר !
 

eranb2

New member
+

http://www.openbsd.org/papers/ven05-deraadt/


so the scope of the potential vulnerabilities is limited (since a crash in the less privileged part cannot be exploited to gain privileges, merely to cause a denial-of-service attack).


http://www.openbsd.org/papers/ven05-deraadt/mgp00034.html


http://www.openbsd.org/papers/ven05-deraadt/mgp00037.html


אני עדיין לא משוכנע שאין סיבה להתעסק עם המערכת הזאת כי ההתקפות יגיעו מעל מערכת ההפעלה ושם היא לא יעילה בלהגן.

הבעיה היא ש openbsd לא ממש מתאימה לתפקד כשרת רציני שיש עליו עומסים כבדים.


אולי אין ממש את דרך המלך באבטחה של שרתים, אבל ממה שראיתי plone זאת מערכת ניהול תוכן שיושבת על סביבה אחרת לגמרי מ LAMP ,
סביבה שכוללת בתוכה שרת אינטרנט ( לא אפאצי) , ובסיס נתונים אחר ( לא mysql ) .
סביבה הרבה יותר בטוחה מבחינת אבטחה לפי מה שהם טוענים.


אני מבין שאף מתכנת לא יזרוק לפח שנים של ניסיון בסביבה אחת ויתחיל מאפס בסביבת פיתוח אחרת.
 

BravoMan

Active member
אתה לא מבין, כי אתה לא יודע מה המבנה של

המערכת המוגמרת, ואתה עושה סלט מכל מיני דברים.

נתחיל מזה, שלא משנה איזו טענה תביא, תמיד תמצא באינטרנט אנשים שמביאים הוכחות בעד ונגד.
לא רק בקשר למערכות הפעלה, אלא בקשר לכל דבר תחת השמש ומעבר לה.

אז יהיו מי שיביאו טענות ש-OpenBSD יותר מאובטחת מ-Linux ויהיו כאלה שיביאו הוכחות הפוכות.

האמת, כרגיל, נמצאת באמצע:
להתקין כל יישום תחת משתמש משלו אפשר בדיוק באותה מידה על הפצת לינוקס, ועד כמה שאני יודע הפצות מכובדות נוהגות בדיוק כך.

אבטחה של שרת לא יכולה להתרכז רק בנקודה אחת כמו מערכת הפעלה או Framework מסוים, זה נושא עצום שכולל לא רק בחירת תוכנות אלא גם הגדרות ותחזוקה שותפת, פעילות ניתור ועוד.

בנקודות וויכוח שאתה מציג כאן, צד אחד זועק "המערכת שלנו בטוחה כי הקוד שלנו הכי טוב" בעוד שהצד השני זועק "לנו יש מערכת בקרה יותר חזקה אז אנחנו מאובטחים יותר".
בפועל, אם לוקחים כל נקודה בנפרד, שתיהן לא מספיקות כדי לספק מערכת מאובטחת, כי צריך הכל ביחד.

ואם אי אפשר, אז מוצאים את הפשרה הכי טובה שאפשר.

רק בגלל ש-plone לא משתמש ב-Apache, PHP ו-MySQL לא עושה אותו בטוח או מאובטח.

בסה"כ מדובר ביישום Python לניהול תוכן, ואף אחד לא הבטיח לך שאין פרצות אבטחה בקוד שלו, או במפרש Python.
מה גם, שלא לכל דבר מתאים NoSQL, ואם אתה אוהב וויכוחים, אז "המלחמה" בין מחנה של SQL למחנה של שיטות אחרות היא מקום לא פחות טוב לחפור בו מאשר מלחמת מערכות הפעלה.

וכאן אנחנו חוזרים למה שכבר נאמר כמה פעמים בשרשור הזה:
בסופו של יום, רמת האבטחה של כל שרת נקבעת נקודתית והיא פרטית לו.
אם מי שמקים את השרת ומתחזק אותו לא יודע מה הוא עושה, גם המערכת הכי מאובטחת בעולם תהיה פרוצה אצלו.
ומי שיודע מה הוא עושה, יכול להקשיח כל מערכת סבירה ברמה הנדרשת.

התקפות יהיו תמיד על המקום שבו יתגלו חולשות:
כשבאים לתקוף שרת, לא מחליטים מראש לתקוף את מערכת ההפעלה, אלא מחפשים איפה יש חור.
אם יש חור באתר עצמו (שוב, קרא על "נט המשפט", זה יפתח לך את העניים!), אז נכנסים משם, אם מזהים חור בתשתית הולכים עליו, ואם יש על מה להתנפל במערכת הפעלה אז מה רע.
 

eranb2

New member
השוואות - http://www.cvedetails.com

השוואה בין מערכות ניהול תוכן :

http://www.cvedetails.com/vendor/1367/Drupal.html
http://www.cvedetails.com/vendor/4313/Plone.html
http://www.cvedetails.com/vendor/3496/Joomla.html
http://www.cvedetails.com/vendor/2337/Wordpress.html


plone - 21
drupal - 235
joomla - 289


השוואה בין מערכות הפעלה :

http://www.cvedetails.com/vendor/97/Openbsd.html --- בשנים האחרונות יש הרבה פחות
http://www.cvedetails.com/vendor/33/Linux.html --- בשנים האחרונות יש הרבה יותר - סימן שבאמת הגרעין הופך להיות יותר ויותר בעייתי.
http://www.cvedetails.com/vendor/23/Debian.html
http://www.cvedetails.com/vendor/6/Freebsd.html



המספרים מדברים :

openbsd 197
linux 1000




השוואה בין סביבות פיתוח :

http://www.cvedetails.com/product/128/PHP-PHP.html?vendor_id=74
http://www.cvedetails.com/product/18230/Python-Python.html?vendor_id=10210


php - 338
python - 15
 

eranb2

New member
העתיד של לינוקס לא ברור

http://www.satirewire.com/news/0101/linux_quit.shtml


The executive, Microsoft group product manager Doug Miller, told a reporter for Wired "Linux is not leading anything, it is simply providing a 'free' operating system," adding that, ""Free does not sustain a business," and, "the recent security problems with Linux ... really call into question whether Linux should be used at all."


Reached at his office, Microsoft's Miller said he didn't enjoy delivering the sobering news, and prayed his opponents would be able to find peace. "Revealing that Linux is full of errors, shouldn't be used, and has no place in the software world was one of the hardest things I've ever had to do," confessed Miller, who appeared to be holding back tears. "I can only hope that one day, they will see I was doing this to save them years of wasted effort."


לינוקס טובה ב : embedded devices ולמחשבי desktop , אבל ממה שאני רואה לשרתים עדיף bsd כמערכת שהפיתוח שלה הוא הרבה יותר רציני ויציב.


http://forums.freebsd.org/showthread.php?t=29495



=======================================


אני מצרף תגובות של אנשי תמיכה מאחת החברות הגדולות והרציניות בעולם לאחסון אתרים - ממוקמים בארצות הברית.


There are many metrics of performance. Disk I/O, filesystem, memory management, multitasking. Each of these categories could also be benchmarked for scalability from 1 to tens of thousands of processes/threads. The relevant metrics for you depend on your particular workload.

And regarding security, there is a famous adage: Security is a process. Yes, different operating systems have a different level of focus on security *out of the box*. But the relative security of any particular host over the long term is most affected by the policies, enforcement, and ongoing vigilance of its administrators.

Also of potential importance for you... We have noticed that OpenBSD tends to become unstable and crash when it is stressed with a heavy workload. (OpenBSD's focus on security seems to have been to the detriment of a focus on stability.) If you anticipate that your site may someday receive a lot of traffic, you may want to choose something other than OpenBSD.




While OpenBSD is well known for being secure, the security is for the software included in OpenBSD... not for all the applications you might add on top of it. Also, FreeBSD is very secure. Just like OpenBSD however, the security of a new server with nothing installed is very secure. But, when you install software on the server, you add possible vulnerabilities that are not part of the OpenBSD or FreeBSD audited code.
FreeBSD performs *much* better than OpenBSD and has better hardware support. If given the choice of either OpenBSD or FreeBSD as the platform to use for a new site that I hoped to grow to a large number of users, there is no doubt in my mind; I would definitely use FreeBSD.
Let me say that I am a fan of OpenBSD, but for a production web site that will have many users I would prefer to use FreeBSD.





-----------------------




openbsd זאת לא המערכת לשרתים כבדים , זה ברור לי ממחקר ארוך שעשיתי ( המון שעות בכל פורום אפשרי ) .

הם גם אמרו לי שזה נכון שלינוקס היתה מערכת עם ביצועים הרבה יותר טובים ( מדגיש "הרבה" ) מ freebsd עד הגרסא 9 .

בגרסא 9 עניין הביצועים מאוד השתפר יחסית ללינוקס.

אני אוהב את זה שכלום לא מוכן שם ( זה כמו לינוקס לפני 12 שנה ).
זה הרבה יותר יוניקס אמיתי ולא דומה לווינדוס.
 

Dניאל Mור

New member
הערה "כללית" - לכולנו

להביע דעה, להתווכח, לא להסכים ועוד זה מצויין, מקובל ואנושי. עם זאת, בוא ננסה להקפיד על שפה נאותה וכבוד הדדי אחד לשני.

תודה מראש לכולנו.

+דניאל.
 
למעלה