🆕 Software Suggestion | LibertyBSD #929

Closed
opened 2019-05-14 01:42:01 +00:00 by gjhklfdsa · 12 comments
gjhklfdsa commented 2019-05-14 01:42:01 +00:00 (Migrated from github.com)

Description: Add LibertyBSD to OSes.
How?: I recommend changing the OpenBSD description to:

A project that produces a free, multi-platform 4.4BSD-based UNIX-like operating system. Emphasizes portability, standardization, correctness, proactive security and integrated cryptography. LibertyBSD is a completely free software version of OpenBSD.

This is very similar to the way Parabola is listed as a free'd version of Arch.

**Description**: Add LibertyBSD to OSes. **How?**: I recommend changing the OpenBSD description to: > A project that produces a free, multi-platform 4.4BSD-based UNIX-like operating system. Emphasizes portability, standardization, correctness, proactive security and integrated cryptography. [LibertyBSD](https://libertybsd.net) is a completely [free software](https://www.wikipedia.org/wiki/Free_software) version of [OpenBSD](https://openbsd.org). This is very similar to the way [Parabola](https://www.wikipedia.org/wiki/Parabola_GNU/Linux-libre) is listed as a free'd version of [Arch](https://www.wikipedia.org/wiki/Arch_Linux).
FrostKnight commented 2019-05-15 20:14:57 +00:00 (Migrated from github.com)

except, that LibertyBSD ditched libressl in favor of openssl. Which I have heard is not secure due to mulitiple vulnerabilities. Worth researching though!

except, that LibertyBSD ditched libressl in favor of openssl. Which I have heard is not secure due to mulitiple vulnerabilities. Worth researching though!
gjhklfdsa commented 2019-05-17 04:04:04 +00:00 (Migrated from github.com)

@FrostKnight I've never heard this. Can you please send link?
OpenSSL is still very popular. Not sure how bad the vulnerabilities are today.

@FrostKnight I've never heard this. Can you please send link? OpenSSL is still very popular. Not sure how bad the vulnerabilities are today.
FrostKnight commented 2019-05-17 06:38:57 +00:00 (Migrated from github.com)

@FrostKnight I've never heard this. Can you please send link?
OpenSSL is still very popular. Not sure how bad the vulnerabilities are today.

here is LibreSSL's vulnerability list over time: https://www.cvedetails.com/version/250810/Openbsd-Libressl-2.7.3.html
Here is OpenSSL's vulnerability list over time: https://www.cvedetails.com/product/383/Openssl-Openssl.html?vendor_id=217

Also, OpenBSD is known for focusing heavily on security, if they forked OpenSSL, it was for a reason. ;)

Also here is a more updated remote issue based list: https://www.cvedetails.com/vulnerability-list.php?vendor_id=97&product_id=30688&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=2018&cweid=0&order=1&trc=5&sha=ffdf9c4cd94a5fb3a7baf89619c702b7fc5a5cad

https://www.cvedetails.com/vulnerability-list.php?vendor_id=217&product_id=383&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=2018&cweid=0&order=1&trc=9&sha=746b2e6eab6dc4007d60ba0d6720cc8e028e1d7a

The bottom one is OpenSSL. The Top is LibreSSL.

https://www.cvedetails.com/product/383/Openssl-Openssl.html?vendor_id=217
OpenSSL

LibreSSL

https://www.cvedetails.com/product/30688/Openbsd-Libressl.html?vendor_id=97

Tell me if this helps, ps, my distro Hyperbola is planning to switch to Hyperbola due to LibreSSL's focus on security. I don't know if this is true btw, but some people think openssl could be used for the purpose of a backdoor. Dunno if true, but openssl's vulnerabilities from 2014-2019 is alot more than LibreSSL. ;/

But yeah, this might not be enough evidence, you may need to talk to openbsd devs or voidlinux devs to get a better idea as to why its better. Voidlinux was the first linux distro to use libressl instead of openssl. :)

I am not an expert on SSL/TLS, but I wouldn't be surprised if OpenBSD knows better, it is hailed as the most secure os on the planet from what I hear. :)

> @FrostKnight I've never heard this. Can you please send link? > OpenSSL is still very popular. Not sure how bad the vulnerabilities are today. here is LibreSSL's vulnerability list over time: https://www.cvedetails.com/version/250810/Openbsd-Libressl-2.7.3.html Here is OpenSSL's vulnerability list over time: https://www.cvedetails.com/product/383/Openssl-Openssl.html?vendor_id=217 Also, OpenBSD is known for focusing heavily on security, if they forked OpenSSL, it was for a reason. ;) Also here is a more updated remote issue based list: https://www.cvedetails.com/vulnerability-list.php?vendor_id=97&product_id=30688&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=2018&cweid=0&order=1&trc=5&sha=ffdf9c4cd94a5fb3a7baf89619c702b7fc5a5cad https://www.cvedetails.com/vulnerability-list.php?vendor_id=217&product_id=383&version_id=0&page=1&hasexp=0&opdos=0&opec=0&opov=0&opcsrf=0&opgpriv=0&opsqli=0&opxss=0&opdirt=0&opmemc=0&ophttprs=0&opbyp=0&opfileinc=0&opginf=0&cvssscoremin=0&cvssscoremax=0&year=2018&cweid=0&order=1&trc=9&sha=746b2e6eab6dc4007d60ba0d6720cc8e028e1d7a The bottom one is OpenSSL. The Top is LibreSSL. https://www.cvedetails.com/product/383/Openssl-Openssl.html?vendor_id=217 OpenSSL LibreSSL https://www.cvedetails.com/product/30688/Openbsd-Libressl.html?vendor_id=97 Tell me if this helps, ps, my distro Hyperbola is planning to switch to Hyperbola due to LibreSSL's focus on security. I don't know if this is true btw, but some people think openssl could be used for the purpose of a backdoor. Dunno if true, but openssl's vulnerabilities from 2014-2019 is alot more than LibreSSL. ;/ But yeah, this might not be enough evidence, you may need to talk to openbsd devs or voidlinux devs to get a better idea as to why its better. Voidlinux was the first linux distro to use libressl instead of openssl. :) I am not an expert on SSL/TLS, but I wouldn't be surprised if OpenBSD knows better, it is hailed as the most secure os on the planet from what I hear. :)
gjhklfdsa commented 2019-05-18 18:52:13 +00:00 (Migrated from github.com)

@FrostKnight I meant, where did you see that LibertyBSD doesn't use or work with LibreSSL.

@FrostKnight I meant, where did you see that LibertyBSD doesn't use or work with LibreSSL.
FrostKnight commented 2019-05-18 21:12:46 +00:00 (Migrated from github.com)

@FrostKnight I meant, where did you see that LibertyBSD doesn't use or work with LibreSSL.

https://pub.allbsd.org/LibertyBSD/6.1/packages/amd64/

For example, search openssl and then search libressl. Tell me what you see. I see only openssl. ;)

> @FrostKnight I meant, where did you see that LibertyBSD doesn't use or work with LibreSSL. https://pub.allbsd.org/LibertyBSD/6.1/packages/amd64/ For example, search openssl and then search libressl. Tell me what you see. I see only openssl. ;)
blacklight447 commented 2019-05-28 11:15:41 +00:00 (Migrated from github.com)

As this is a fork, Would anyone be able to tell whether libertybsd gets their updates at the same time as openbsd? or is there any delay?

As this is a fork, Would anyone be able to tell whether libertybsd gets their updates at the same time as openbsd? or is there any delay?
dawidpotocki commented 2019-05-28 11:38:32 +00:00 (Migrated from github.com)

LibertyBSD from what I see is now on 6.1 (April 11, 2017) while OpenBSD is on 6.5 (May 1, 2019) release. Also their git links on the page are giving 404.

LibertyBSD from what I see is now on 6.1 (April 11, 2017) while OpenBSD is on 6.5 (May 1, 2019) release. Also their git links on the page are giving 404.
blacklight447 commented 2019-06-02 06:57:01 +00:00 (Migrated from github.com)

My vote goes to adding it as worth mentioning for software freedom purists.

My vote goes to adding it as worth mentioning for software freedom purists.
gjhklfdsa commented 2019-06-25 02:34:13 +00:00 (Migrated from github.com)

@blacklight447-ptio Aye, I created a PR about this:
https://github.com/privacytoolsIO/privacytools.io/pull/939
My original thought was that the discussion wasn't active anymore and wanted to take further steps.

However, noticing your comment I wanted to clarify.
My PR (not the issue) is about listing LibertyBSD as an alternative to OpenBSD.

Are you proposing LibertyBSD be listed separately? :)

Thanks,
@gjhklfdsa

@blacklight447-ptio Aye, I created a PR about this: https://github.com/privacytoolsIO/privacytools.io/pull/939 My original thought was that the discussion wasn't active anymore and wanted to take further steps. However, noticing your comment I wanted to clarify. My PR (not the issue) is about listing LibertyBSD as an alternative to OpenBSD. Are you proposing LibertyBSD be listed separately? :) Thanks, @gjhklfdsa
blacklight447 commented 2019-08-09 21:58:31 +00:00 (Migrated from github.com)

Yes and we could make it clear that its an foss alternative for foss extremists.

Yes and we could make it clear that its an foss alternative for foss extremists.
dawidpotocki commented 2019-09-03 13:17:09 +00:00 (Migrated from github.com)

LibertyBSD seems to not be maintained.
It is stuck on old 6.1 OpenBSD release from 2017.
Git repository is giving 404 and installing packages comes with an error.

screenshot

LibertyBSD seems to not be maintained. It is stuck on old 6.1 OpenBSD release from 2017. Git repository is giving 404 and installing packages comes with an error. ![screenshot](https://user-images.githubusercontent.com/38681822/64176392-e5380180-ce4c-11e9-831e-d9863710ab11.png)
FrostKnight commented 2019-09-03 21:02:49 +00:00 (Migrated from github.com)

Yes... that's another good reason I suppose.

Yes... that's another good reason I suppose.
This repo is archived. You cannot comment on issues.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#929
No description provided.