Re: Hardening browser

2020-03-04 Thread Tomasz Rola
On Thu, Mar 05, 2020 at 04:18:00AM +0100, Tomasz Rola wrote: [...] > As a side note, I sometimes get a bit obsessed upon seeing a program > which "sits idle" but scratches my disk every n seconds (and/or loads > my cpu with empty loops). A daemon can be hunted down and nailed. No > big deal. But a

Re: Hardening browser

2020-03-04 Thread Tomasz Rola
On Wed, Mar 04, 2020 at 02:06:40AM +0100, whistlez...@riseup.net wrote: > Hi, > in the following message: > https://marc.info/?l=openbsd-misc=158110613210895=2 > Theo discourages to use unveil instead of chroot. > I asked if he suggests the same for the browser but he asked that chroot > is onlye

Re: Hardening browser

2020-03-04 Thread Luke A. Call
On 03-04 12:03, Luke A. Call wrote: > Partly as a possible approach, and partly for feedback/suggestions on > it: [] > multiple user logins and their corresponding X sessions running > at the same time, among which I would switch with Ctrl-Alt-F* keys, > hoping that if one account (where I

Re: Hardening browser

2020-03-04 Thread Luke A. Call
On 03-04 02:06, whistlez...@riseup.net wrote: > in the following message: > https://marc.info/?l=openbsd-misc=158110613210895=2 > Theo discourages to use unveil instead of chroot. > I asked if he suggests the same for the browser but he asked that chroot > is onlye for *root*. > Then what should I

Re: man to render pure text? (or a pipe in vi macros ?)

2020-03-04 Thread Marc Chantreux
hello Ingo, > Heck, piping to sort, or wc + undo are two of the most common used > commands. no need to pipe and undo: just write to a pipe :%w !wc > Under vi, !}fmt is also a favorite > though vim does have better integrated commands... AFAIK, ! work exactly the same between vim and

Re: 6.6 pflow IPFIX removed?

2020-03-04 Thread Florian Obser
The ifconfig option parser is... special. You must set flowdst as well as pflowproto. On 4 March 2020 14:02:18 CET, Kapetanakis Giannis wrote: >Hi, > >Is IPFIX removed  from pflow in 6.6? > ># ifconfig pflow0 pflowproto 10 >ifconfig: SIOCSETPFLOW: Can't assign requested address > >pflow(4)

Re: Having PF enabled breaks up rsync (and scp) over ssh connections

2020-03-04 Thread Stuart Henderson
On 2020-03-03, Chris Cappuccio wrote: > Jyri Hovila [Turvamies.fi] [jyri.hov...@turvamies.fi] wrote: >> Hello everyone! >> >> Now here's a mysterious one -- I've been working on this for weeks and still >> have no clue what's causing it. >> >> "client_loop: send disconnect: Broken pipe >> >>

Re: Hardening browser

2020-03-04 Thread Kevin Chadwick
On 2020-03-04 11:38, Ottavio Caruso wrote: > Probably not what you were looking for but, back in the days when I > was ultra paranoid about my web browsing, I used to use stripped down > live usb installations of Linux distros (DSL was one of them that I > remember). I ignore if OpenBSD comes with

Re: Pledge Policy for Tset Binary

2020-03-04 Thread Theo de Raadt
shankarapailoor . wrote: > I was looking at the pledge policy for the tset binary and I was wondering > why wpath is necessary. I removed the group from the pledge and did some > basic tests with the utility and there was no error. Removing any of the > other groups produces an error so they

Re: man to render pure text? (or a pipe in vi macros ?)

2020-03-04 Thread Marc Espie
On Wed, Mar 04, 2020 at 03:42:47PM +0100, Marc Espie wrote: > On Mon, Mar 02, 2020 at 06:25:47PM +0100, Ingo Schwarze wrote: > > Yikes. I had no idea what either of these are doing and had to > > try them out. vi(1) contains so much bloat that is never really > > needed and doesn't belong in a

Re: man to render pure text? (or a pipe in vi macros ?)

2020-03-04 Thread Marc Espie
On Mon, Mar 02, 2020 at 06:25:47PM +0100, Ingo Schwarze wrote: > Yikes. I had no idea what either of these are doing and had to > try them out. vi(1) contains so much bloat that is never really > needed and doesn't belong in a text editor at all. No, all of this does belong in a text editor. I

6.6 pflow IPFIX removed?

2020-03-04 Thread Kapetanakis Giannis
Hi, Is IPFIX removed  from pflow in 6.6? # ifconfig pflow0 pflowproto 10 ifconfig: SIOCSETPFLOW: Can't assign requested address pflow(4) still mentions it. regards, Giannis

Re: Web documentation available offline by default?

2020-03-04 Thread Vincenzo Nicosia
On Wed, Mar 04, 2020 at 01:49:01PM +0100, Peter N. M. Hansteen wrote: > On Tue, Mar 03, 2020 at 10:15:31AM -, Stuart Henderson wrote: > > On 2020-03-02, Peter N. M. Hansteen wrote: > > > I was thinking of the probably quite unlikely event that somebody who > > > wants this > > > comes up

Re: Web documentation available offline by default?

2020-03-04 Thread Peter N. M. Hansteen
On Tue, Mar 03, 2020 at 10:15:31AM -, Stuart Henderson wrote: > On 2020-03-02, Peter N. M. Hansteen wrote: > > I was thinking of the probably quite unlikely event that somebody who wants > > this > > comes up with an actually reproducible way that could be turned into an > > otherwise > >

Compiler warning in ctype.h

2020-03-04 Thread Thomas de Grivel
With latest OpenBSD snapshot on amd64 In file included from /usr/include/readline/chardefs.h:26, from /usr/include/readline/keymaps.h:36, from /usr/include/readline/readline.h:38, from cli.c:21: /usr/include/ctype.h:216: warning: unused parameter

Re: Web documentation available offline by default?

2020-03-04 Thread Frank Beuth
On Tue, Mar 03, 2020 at 10:15:31AM -, Stuart Henderson wrote: On 2020-03-02, Peter N. M. Hansteen wrote: I was thinking of the probably quite unlikely event that somebody who wants this comes up with an actually reproducible way that could be turned into an otherwise unremarkable make

Re: Hardening browser

2020-03-04 Thread Ottavio Caruso
On Wed, 4 Mar 2020 at 01:06, wrote: > > Hi, > in the following message: > https://marc.info/?l=openbsd-misc=158110613210895=2 > Theo discourages to use unveil instead of chroot. > I asked if he suggests the same for the browser but he asked that chroot > is onlye for *root*. > Then what should I

Re: Hardening browser

2020-03-04 Thread Kevin Chadwick
On 2020-03-04 01:06, whistlez...@riseup.net wrote: > in the following message: > https://marc.info/?l=openbsd-misc=158110613210895=2 > Theo discourages to use unveil instead of chroot. > I asked if he suggests the same for the browser but he asked that chroot > is onlye for *root*. I thought that

Re: USB Printer Prebloms

2020-03-04 Thread 陈贤文
Dear Ducan, I just set up a Brother HL-5450DN Series on OpenBSD 6.6 amd64. > 1. ulpt must be disabled: > # config -ef /bsd > ukc> disable ulpt > ukc> quit I studied tutorials on-line and previous discussions on @misc. I found out that for 6.6 amd64, if I disabled ulpt(4), I would not get the