Although many readers think I'm a Windows-only zealot, one of my other favorite OSes is OpenBSD. I run a few flavors of Linux as well, but I use OpenBSD as my honeynet (a network of honeypots) firewall and to explore the criminal side of the Net. There is no better secure, popular OS than OpenBSD.
Project founder Theo de Raadt created OpenBSD in 1995 as a more secure and open alternative to NetBSD and Linux. De Raadt and his project team are legendary in their pursuit of openness and security. They worked hard to scrub every proprietary and non-open piece of source code out of the kernel. The name OpenBSD comes from the fact that its source code can easily be examined on the Web or by using other tools. Open also means that it supports many platforms, including i386, Alpha, HP, Mac (both Motorola and iMac chipsets), Vax, Sparc, and SGI.
The founders and maintainers of OpenBSD are the kings of security. Nothing goes into OpenBSD before a gauntlet of security reviews, and the source code is constantly examined, re-examined, extended, and updated in developer-focused hack-a-thons.
Crypto is baked-in and turned on by default. Kerberos V is built-in. In 1997, OpenBSD was the first OS with IPSec support. It has native support for many cryptographic hardware accelerator cards. You want to use remote admin? Then you’re going to use an encrypted channel (e.g., OpenSSH). FTP supports HTTPS. Passwords are protected by Blowfish encryption (called bcrypt hashes), which are considered the strongest password hashes available.
The overarching goal is to be the most secure operating system. To date, only one remote vulnerability has been found in the OpenBSD kernel. Critics often counter -- and rightly so -- that no one runs just the kernel, and that other common add-ons (again, OpenSSH) have been found with bugs. That may be right, but few other OSes can say that in 10 years of existence, outsiders found only one kernel bug. It’s quite the record.
OpenBSD is especially known for its Packet Filter (PF) firewall software, considered one of the most protective and straightforward firewalls available. You need a chrooted service? Nobody does it better than OpenBSD. In fact, think of any generally available security feature, and it's highly likely that it’s available or installable on OpenBSD, albeit in a more secure form.
Security comes at the price of decreased user friendliness and difficult installs from a lack of supported drivers. OpenBSD earned its reputation for being difficult to configure after the install, because what does get installed is minimalist in nature by default. For example, PF is a strong firewall, but it doesn’t include all the cute little features that are available in today’s massively bloated firewalls. It does what you tell it to do, no more and no less -- and without holes.
OpenBSD is shipped secure-by-default, with all non-essential services disabled. You won’t find NFS, Mountd, or Apache enabled by default. The \bin and \sbin folders will be emptier than other Linux or BSD distros. Install OpenBSD and you can be assured that it doesn’t default to an insecure state.
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »