Add KDE Plasma to 75.html

2024-03-22 Thread Kevin Williams
This patch adds KDE Plasma to the list of packages on the 7.5 page. Index: 75.html === RCS file: /cvs/www/75.html,v retrieving revision 1.10 diff -u -p -r1.10 75.html --- 75.html 22 Mar 2024 11:08:09 -  1.10 +++ 75.html 

Re: Automatic OS updates

2024-02-16 Thread Kevin Williams
The main use case I see for this is to manage a fleet of more than 10 or so machines/VMs/instances. rdist or a package such as Ansible could manage the crontab and possibly search announce@ on marc.info for keywords to hold off on the upgrade. On 2/16/24 08:09, Jan Stary wrote: On

Re: Adaptec 8405 SGL drivers these days?

2024-01-26 Thread Kevin
On Fri, Jan 26, 2024 at 6:02 AM Nick Holland wrote: > > On 1/26/24 00:37, Kevin wrote: > > Hey gang, > > > > Looking at a server whose only option for storage comes via an Adaptec 8405 > > SGL. > > > > Given the battles between OpenBSD and Adaptec for

Adaptec 8405 SGL drivers these days?

2024-01-25 Thread Kevin
and storage and is an offensively reasonable price. Thanks, Kevin

Appimage

2023-12-19 Thread Kevin Chadwick
I'm not sure if this is a pipe dream but atleast I imagine the filesystem API and /proc avoidance is likely possible. "https://github.com/AppImage/AppImageKit/issues/98;

Re: Using wayland on OpenBSD

2023-11-25 Thread Kevin Williams
, if you're developing any app for or with OpenBSD, web-based or native, I recommend you do so on -current, because it will give you the best chance of the app functioning well on the next few OpenBSD releases when your app might be in production. Good luck on your project! Kevin On Sat, Nov 25, 2023

Re: xenodm blank screen

2023-10-18 Thread Kevin Williams
Hi Ryan, Yes, please paste the output of: $ dmesg | less $ less /var/log/Xorg.0.log I see you already sent part of the Xorg log. Please send the entire output of the commands above. The information those provide will help us better assist you. Usually when you create your own ~/.xsession

Re: OT: Paid Email Provider Options

2023-10-10 Thread Kevin Williams
Hi Jan, This one I accidentally replied all. Several people had really good suggestions. I replied individually to the others. On Tue, Oct 10, 2023, at 00:44, Kevin Williams wrote: > Hi Kevin, > > Thank you for the suggestion. I will check out hostinger.com. >

Re: OT: Paid Email Provider Options

2023-10-10 Thread Kevin Williams
Hi Kevin, Thank you for the suggestion. I will check out hostinger.com.

Re: OT: Paid Email Provider Options

2023-10-09 Thread Kevin
hostinger.com has hosting plans that include email. Just forego the hosting part and use their system for email. Super inexpensive AFAIK they meet the rest of your requirements. On Mon, Oct 9, 2023 at 11:24 AM Kevin Williams wrote: > > I registered a new domain and I am l

OT: Paid Email Provider Options

2023-10-09 Thread Kevin Williams
I registered a new domain and I am looking for an email provider for it. I am happy with k9w.org hosted at fastmail.com and am not looking to change for that domain at this time. I heard good things about pobox.com, gandi.net, and protonmail. But I want something else. pobox.com is owned by

Re: man.openbsd.org is down?

2023-09-23 Thread Kevin Williams
Nick thank you for hosting this part of the OpenBSD project. Much appreciated! On Sat, Sep 23, 2023, at 14:17, Nick Holland wrote: > On 9/23/23 13:42, S V wrote: > > Any info on man.openbsd.org state? It is down for me and web checkers. > > It is back up now. > Seems my monitor's alert to text

Re: man.openbsd.org is down?

2023-09-23 Thread Kevin Williams
On Sat, Sep 23, 2023, at 10:42, S V wrote: > Any info on man.openbsd.org state? It is down for me and web checkers. It is down for me as well.

Re: ddb panic on 7.3 after applying 2023-07-24 zenbleed patches

2023-07-25 Thread Kevin
> > > Just applied the fix to the first affected AMD machine and all is well > > again. > > > > Would this be worth putting a ticket into Vultr to get them to make > > appropriate updates on their side? > > Yes (but I see you already did) > Here's the reply I got from Vultr about this: Thank

Re: ddb panic on 7.3 after applying 2023-07-24 zenbleed patches

2023-07-25 Thread Kevin
On Tue, Jul 25, 2023 at 7:42 AM Theo de Raadt wrote: > It seems some of the smaller hypervisor companies didn't get the memo, > and they are blocking the msr write to to set the chicken bit. > > They block it by raising an exception. > They should IGNORE that bit if they allow setting it. > > I

Update groups

2023-06-24 Thread Kevin Williams
> 0 > C USA > P Oregon > T Portland > F 3rd Thursday, 7pm > O BSD Pizza Night (group) > U https://bsd.pizza > N *BSD

New groups

2023-06-24 Thread Kevin Williams
0 C USA P Oregon T Portland F 3rd Thursday, 7pm O BSD Pizza Night (group) U https://bsd.pizza N *BSD

BSD meetup event

2023-06-24 Thread Kevin Williams
Not sure if we need to be listed as an official BSD User Group on openbsd.org before posting this. If you're in or visiting Portland Oregon (United States) on Thursday June 29th, come join a handful of us for BSD Pizza Night at 7pm at the location linked here.

Re: OpenBSD 7.3 released

2023-04-11 Thread Kevin Williams
Thank you to all the developers for such a great release! Sysupgrade went flawlessly on my cloud instances, router, and laptop host. Keep up the great work! On Mon, Apr 10, 2023, at 6:52 AM, Theo de Raadt wrote: > > > -

Re: dual boot with full disk encryption for OpenBSD

2022-12-05 Thread Kevin Williams
but it > might be helpful for someone. > > https://astro-gr.org/openbsd-full-encryption-with-dual-boot/ > > Cheers Mare, This guide is very helpful! Kevin

Re: Query on installing Solaris 9 into an OBSD LDOM

2022-11-27 Thread Kevin Williams
> Greetings. > > Has anyone tried to install Solaris 9 into an OBSD LDOM running on a TS2000? > > (I found some information on the mailing list pertaining to different > machines and Solaris versions.) > > Sincerely, > N. > We need more information to better assist you. By LDOM, do you

Re: Keyboard won't work during OpenBSD 7.1 or 7.2 installation.

2022-11-22 Thread Kevin Lo
Hi Clint, As mentioned in a private email, you need to disable acpimadt and mpbios in the kernel to make it work. Why don't you give it a try? Also see: https://marc.info/?l=openbsd-bugs=165170229727676=2 On Wed, Nov 23, 2022 at 09:48:24AM +0800, Clint wrote: > > Hi Fred, > > I tried at

Re: cdn.openbsd.org not synced

2022-11-14 Thread Kevin Williams
scan Theo did almost certainly hit a more up to date endpoint. Picking an up-to-date mirror by hand like you did is understandable. Kevin

Re: Question regarding Apache 2.0 license

2022-11-07 Thread Kevin Williams
Hi Jeroen, Thank you for considering the license and venturing to improve OpenBSD base, NSD in this case. The preferred license template is modeled after the ISC license, and 2-clause BSD close behind. License policy: ISC or BSD only https://www.openbsd.org/policy.html ISC license template:

Re: Share your tmux tricks

2022-09-05 Thread Kevin Williams
On Sun, Sep 4, 2022 at 7:38 AM, Alex Holst wrote: > This is my ~/bin/bootstrap-tmux script. > > Maybe it can inspire you to share some of your tmux config snippets or > tricks? I'd also be interested if you have suggestions for improvements > to my script. > > #!/bin/sh > # > # Bootstraps tmux

Re: Mouse touchpad no longer working

2021-11-30 Thread Kevin Chadwick
Ignore this. Sorry for the junk thread. Apparently there is a touchpad disable button that I hit whilst trying to work out why the OpenBSD compatible wireless cards Windows driver isn't working with Windows.

Mouse touchpad no longer working

2021-11-30 Thread Kevin Chadwick
Unfortunately due to covid the following machine hasn't been updated a great deal. The touchpad works in Windows and used to work in OpenBSD but now no movement or button presses have any affect. > OpenBSD 7.0-current (GENERIC.MP) #133: Tue Nov 30 00:53:23 MST 2021 >

Re: How to check that HT is working and used?

2021-11-19 Thread Kevin Chadwick
In case you missed Stuarts email that also mentioned that you were booting the uni processor kernel. Then I will re-mention that HT, if still re-enabled by you, was disabled by default for security reasons (hunch) on OpenBSD. Linux came to realise issues later, but decided to stick with insecure

Re: sim7600 4g modem

2021-09-23 Thread Kevin Lo
On Fri, Sep 24, 2021 at 12:19:35PM +0800, Kevin Lo wrote: > > On Fri, Sep 03, 2021 at 10:08:52PM +, Cord wrote: > > > > > > > > > > > > It looks like it is probably a Qualcomm-based device. It seems likely > > > > > > that as

Re: sim7600 4g modem

2021-09-23 Thread Kevin Lo
On Fri, Sep 03, 2021 at 10:08:52PM +, Cord wrote: > > > > > > > It looks like it is probably a Qualcomm-based device. It seems likely > > > > that as things are now, it will attach to umsm. I can't say for sure if > > > > it will work or not though I think there is a fairly good chance. > >

Re: OpenCV on 6.9 can't open camera

2021-08-10 Thread Kevin Lo
; print(frame) > > jross@aurora-cam:/home/jross $ python3 open_test.py > > Open Failed! > 0.0 0.0 0.0 > False > [None] > > I'd appreciate anyone's thoughts on fixing this! Hi, I encountered the same problem. Just committed a fix: https://marc.info/?l=openbsd-ports-cvs=162857744213080=2 > Jeff Ross Kevin

Re: DHCP non-issues

2021-07-20 Thread Kevin Chadwick
On July 20, 2021 10:35:55 AM UTC, Kevin Chadwick wrote: >On Mon, 19 Jul 2021, 12:47 Christian Weisgerber, >wrote: > >> Look guys, it's simple. >> >> If you want IPv6 (SLAAC) autoconfiguration, you set "inet6 autoconf" >> for that interface. slaa

Re: Adding Password Protection to Single User Mode

2021-07-06 Thread Kevin Chadwick
On 7/6/21 12:27 PM, Valdrin MUJA wrote: > Hi Folks, > > I want to add a small password protection mechanism to > "boot -s" (single-user mode). > > Therefore, I'm working on /sys/stand/boot/boot.c, I've written > some code in boot.c, and run "make", "make obj", "make install" > in /sys/.

Re: pf firewall packet size

2021-03-11 Thread Kevin Chadwick
> > > There is just small ACK packets left. I wonder what is solution for > small packets in OpenBSD Checkout set prio in pf.conf...TCP ACKs with no data payload

Re: sysupgrade failure logs

2021-02-16 Thread Kevin Chadwick
On 2/15/21 2:14 PM, Ed Ahlsen-Girard wrote: > I am confident that I can speak for for ... a non-zero number of > people who use sysupgrade the way it says to on the box and would miss > it if it went away. +1 Even though it is a little surprising that some people don't realise how easy it

Dropping privileges and execve CAVEAT

2021-02-11 Thread Kevin Chadwick
If rather than setuid, a root process calls setgroups(1000) setresgid(1000, 1000, 1000) setresuid(1000, 1000, 1000) Is there anything to worry about in regard to the caveat in execve(2)? "If a program is setuid to a non-superuser, but is executed when the real uid is "root", then the process has

Re: Go language and pledge exec promises

2021-01-21 Thread Kevin Chadwick
On 1/21/21 3:06 PM, Theo de Raadt wrote: >> This is just testing with the most permissable settings. > That statement is wrong. The most permissable setting is to not use > pledge, and use full POSIX. > True, perhaps that explains it. I should have done more testing and not assumed it might be

Re: Go language and pledge exec promises

2021-01-21 Thread Kevin Chadwick
On 1/21/21 2:58 PM, Kevin Chadwick wrote: >>>840 beep CALL pledge(0xcf4000,0xcae384) >>>840 beep STRU promise="stdio rpath wpath cpath dpath tmppath inet >>> mcast fattr chown flock unix d\ >>> ns getpw sendfd recvfd tape

Re: Go language and pledge exec promises

2021-01-21 Thread Kevin Chadwick
On 1/21/21 2:54 PM, Theo de Raadt wrote: >>> Run your code under ktrace and see what is actually passed to pledge(), >>> that might give some clues. >>> >>> >>840 beep CALL pledge(0xcf4000,0xcae384) >>840 beep STRU promise="stdio rpath wpath cpath dpath tmppath inet >>

Re: Go language and pledge exec promises

2021-01-21 Thread Kevin Chadwick
On 1/21/21 2:18 PM, Stuart Henderson wrote: > Run your code under ktrace and see what is actually passed to pledge(), > that might give some clues. > > 840 beep CALL pledge(0xcf4000,0xcae384) 840 beep STRU promise="stdio rpath wpath cpath dpath tmppath inet mcast fattr

Go language and pledge exec promises

2021-01-21 Thread Kevin Chadwick
I can live without exec promises. However I believe I have stumbled across an issue on 6.8 and current. When I try to exec /bin/sh where promises is a string of all possible promises from the man page and the second parameter is exec promises. unix.Pledge(promises, "") I get sh[97964]: pledge

Re: Usermod -G failure without error

2021-01-19 Thread Kevin Chadwick
On 1/19/21 10:59 AM, Kevin Chadwick wrote: > Sorry, I think that I must have ran groupadd first which brought users and > groups IDs, out of sync. Ok, after failing to reproduce it this morning; With admin safely jumping to 1020, I worked it out. groupadd elansys useradd admin userdel

Re: Usermod -G failure without error

2021-01-19 Thread Kevin Chadwick
> For example, does 'admin' exist in /etc/passwd?  What does "grep elansyssftp > /etc/group" return? I had played a little. So it shows /bin/ksh and test user etc. /etc/passwd admin:*:1018:1018::/home/admin:/bin/ksh /etc/group admin:*:1019: elansyssftp:*:1018:test Sorry, I think that I must

Usermod -G failure without error

2021-01-18 Thread Kevin Chadwick
When I run the following commands, the elansyssftp group isn't populated. Yet using a differently named group seems to work. I seem to have been able to do so, on two different systems. useradd -m -s /sbin/nologin -p `cat /etc/ssh/ssh_host_ed25519_key.pub | /usr/bin/encrypt -b a` admin groupadd

Re: help needed with httpd.conf and rewrite directive

2021-01-06 Thread Kevin
Thanks Edgar, Unfortunately, still no dice. Maybe there's a bona fide expert who can chime in and pull my ass from the fire here. :-) Kevin On Wed, Jan 6, 2021 at 3:46 PM Edgar Pettijohn wrote: > On Wed, Jan 06, 2021 at 02:12:40PM -0800, Kevin wrote: > > Hey gang, > > > >

help needed with httpd.conf and rewrite directive

2021-01-06 Thread Kevin
they provide. Anyone with some httpd rewrite foo mind whacking me with a clue stick on how to accomplish this purty please? Thanks, Kevin location /sendy/l/ { rewrite ^/sendy/l/([a-zA-Z0-9/]+)$ /sendy/l.php?i=$1 last; }

Re: wg(4) listen on a specific interface / address

2020-10-29 Thread Kevin Chadwick
On 10/29/20 5:20 PM, Kevin Chadwick wrote: > I believe it actually operates at layer 2/3 below IP and uses the default gw > IP > to decide where to operate for a peer to peer link. I'm not actually sure how that makes any sense as it uses UDP which is layer 4. But this says layer

Re: wg(4) listen on a specific interface / address

2020-10-29 Thread Kevin Chadwick
On 10/29/20 4:00 PM, Pierre Emeriaud wrote: >>> Is there a reason why wg needs such a large bind? >> I don't know why wg does that, because I haven't looked at the code. >> Your configuration is definately pushing the limits. > Allright many thanks Theo. Maybe Jason can chime in on this topic. I

Re: OpenBSD UEFI on QEMU emulator

2020-10-26 Thread Kevin Shell
Makefile uses the GNU tool mkhybrid, which does not support multiple el torito boot images, why not use the BSD makefs that is in OpenBSD tree to create the iso file, it supports multiple el torito boot images for both BIOS and UEFI, FreeBSD does it this way. -- kevin

Re: OpenBSD UEFI on QEMU emulator

2020-10-24 Thread Kevin Shell
On Sat, Oct 24, 2020 at 08:55:34AM +0100, Ottavio Caruso wrote: > On 24/10/2020 02:27, Kevin Shell wrote: > > Why I keep received 2 copies email again? > > Please don't To or Cc me. :-) > > > > Because this is how old school mailing lists work. To: the OP and cc: the &

Re: OpenBSD UEFI on QEMU emulator

2020-10-23 Thread Kevin Shell
On Fri, Oct 23, 2020 at 10:03:08PM -0400, Brad Smith wrote: > On 10/22/2020 11:22 PM, Jonathan Gray wrote: > > On Thu, Oct 22, 2020 at 10:37:31PM -0400, Brad Smith wrote: > > > On 10/22/2020 9:59 PM, Kevin Shell wrote: > > > > Hello misc@. > > > &

Re: OpenBSD UEFI on QEMU emulator

2020-10-23 Thread Kevin Shell
Why I keep received 2 copies email again? Please don't To or Cc me. :-) On Fri, Oct 23, 2020 at 07:58:27AM -0600, jpegb...@dismail.de wrote: > I would also like to point out that kevin doesn't have a virtual disk > to install openbsd to, just the openbsd iso. You can create one with > qe

Re: OpenBSD UEFI on QEMU emulator

2020-10-23 Thread Kevin Shell
Please don't To or Cc me, I'm on the list. On Fri, Oct 23, 2020 at 12:49:13PM +0900, YASUOKA Masahiko wrote: > On Fri, 23 Oct 2020 09:59:24 +0800 > Kevin Shell wrote: > > I want to try out OpenBSD UEFI. > > How to install OpenBSD with UEFI boot on qemu? > > The install68

OpenBSD UEFI on QEMU emulator

2020-10-22 Thread Kevin Shell
\ -smp cores=4,threads=1 \ -m 1G \ -bios /usr/share/edk2/ovmf/OVMF_CODE.fd \ -drive file=install68.img,format=raw -- kevin

Re: Issues with TP-Link UE300

2020-09-28 Thread Kevin Lo
On Tue, Sep 29, 2020 at 12:08:42AM +0200, Joel Carnat wrote: > > Hi, Hi Joel, > This seems to work much better! > Transferring files via NFS, I could sustain from 118 to 148Mbps. > > Kernel says: > ure0 at uhub0 port 15 configuration 1 interface 0 "TP-LINK USB 10/100/1000 > LAN" rev

Re: Issues with TP-Link UE300

2020-09-27 Thread Kevin Lo
On Sun, Sep 27, 2020 at 11:43:13PM +0200, Joel Carnat wrote: > > Hi, > > I have plugged a TP-Link UE300 on my ThinkPad X260 running OpenBSD -snapshot > and it seems I can't get more than 100Mbps. > > The dongle attaches and get an IP address. But the speed seems limited. > Same behaviour when

Re: Firefox Security 2020

2020-08-17 Thread Kevin Chadwick
On 2020-08-17 06:06, Stuart Henderson wrote: >> With the recent news. I decided to take a look again at Firefox and after a >> days >> use on multiple systems, it even seems to be faster than Chrome. >> >> I notice significant work on pledge support. Does anyone know if it's >> comparable >> to

Firefox Security 2020

2020-08-14 Thread Kevin Chadwick
With the recent news. I decided to take a look again at Firefox and after a days use on multiple systems, it even seems to be faster than Chrome. I notice significant work on pledge support. Does anyone know if it's comparable to Chrome on that front now or still held back by not being designed

TLS stall ftp or pkg_add

2020-07-18 Thread Kevin Chadwick
Has anyone else noticed stalls when using a https link in /etc/installurl. I found that downloading the following file works fine in Chrome but stalls at 128K every time via ftp before completing a significant time later. https://ftp.heanet.ie/pub/OpenBSD/snapshots/packages/amd64/bzip2-1.0.8.tgz

Re: An Athn ar9280 client seems to require cold boots of late?

2020-07-06 Thread Kevin Chadwick
With this patch I have been able to bring the device down and back up with a subsequently successful dhclient and http download. Annoying how quirky and poorly documented, chips often are! Thank You

Re: An Athn ar9280 client seems to require cold boots of late?

2020-06-29 Thread Kevin Chadwick
On 2020-06-29 08:35, Kevin Chadwick wrote: > After leaving this up all weekend, the issue seems to have occurred without an > ifconfig down command too. Though the down triggers it immediately. Perhaps it's a hw issue. I have tried updating the coreboot firmware to see if it helps a

Re: An Athn ar9280 client seems to require cold boots of late?

2020-06-29 Thread Kevin Chadwick
On 2020-06-29 07:36, Stefan Sperling wrote: > There is one interop problem in 6.7 which has been fixed in -current > by reverting a change which was committted between 6.6 and 6.7: > https://marc.info/?l=openbsd-cvs=159100149411516=2 > Perhaps that applies to your situation? Could you check if a

An Athn ar9280 client seems to require cold boots of late?

2020-06-26 Thread Kevin Chadwick
After upgrading via sysupgrade for a few releases, I have had to cold boot to get dhclient athn0 working on an ar9280 in client mode. Since my latest upgrade to a snapshot of Jun 17 kernel #275 with the previous kernel being from Jun 2nd #237. I seem to have to cold boot after running ifconfig

Re: Thoughts or links on optimally secure defaults for pf.conf and fstab, whilst aiming to minimise support issues.

2020-06-14 Thread Kevin Chadwick
On 2020-06-14 13:58, Kevin Chadwick wrote: > set reassemble yes no-df > match scrub (random-id max-mss 1389) > > Should I drop the no-df from set reassemble? Any other recommendations > welcome? To be clear. Previously, with scrub (no-df... the set reassemble line was missing/default.

Thoughts or links on optimally secure defaults for pf.conf and fstab, whilst aiming to minimise support issues.

2020-06-14 Thread Kevin Chadwick
We are basing the server part of our products on OpenBSD. We care more about reducing support issues than say performance. We will have batteries but I hope to deploy some kind of root partition redundancy, for upgrades. However, Is sync or softdep a better default for the best chance of

Re: OpenBSD Readonly File System

2020-06-12 Thread Kevin Chadwick
On 2020-06-11 23:47, Dirk Coetzee wrote: > I always thought that 'sync' mount option is enough to avoid corruption of the FS. > Am I just "fooling" myself ? > I guess it boils down to a matter of preference and business requirements. > > "slow writes" vs "no writes". It's a good point,

Re: Mounting encrypted drive on boot

2020-06-03 Thread Kevin Chadwick
On 2020-06-02 23:27, Chris Narkiewicz wrote: > Somebody on StackOverflow advised on modifying /etc/rc > and run bioctl before disks are mounted, but I'm not sure > if this is a right approach, especially that attaching > more disks might change the /dev/sd* numberign. That would cause yourself

Re: Could somebody please put unveil() in ftp(1)?

2020-06-01 Thread Kevin Chadwick
On 2020-06-01 13:30, Theo de Raadt wrote: >> I wonder, if 99% of users just use /etc/ssl/cert.pem? whether a flag that >> breaks/enables other use cases (removes capath support at runtime), might >> work? > I guess you don't understand unveil. You didn't understand what Stuart > just said *at

Re: Could somebody please put unveil() in ftp(1)?

2020-06-01 Thread Kevin Chadwick
On 2020-06-01 11:20, Stuart Henderson wrote: > We went through this earlier when unveil was added to nc. The way capath > directories are often populated in the real world is not compatible with > unveil, you would need to resolve all files in capath, recursively resolve > symlinks, and add the

Re: Article OpenBSD: Not Free Not Fuctional and Definetly Not Secure and BSD, the truth blog

2020-05-28 Thread Kevin Chadwick
On 2020-05-28 18:38, Amarendra Godbole wrote: > It indeed is written by someone lacking knowledge about everything. It > is funny, and gave me a good laugh - the comments are even funnier! Be aware that the author deletes your comments and replaces them with his own, under your name, whilst

Re: Intel wireless issue after upgrading to 6.7

2020-05-28 Thread Kevin Chadwick
On 2020-05-28 14:40, Michael Steeves wrote: > but I'm wondering if there's some other way to get any more detail out of the > laptop about what's going on? ifconfig has a debug flag. A packet capture from another device with monitor mode, may be a helpful option too. e.g. iwm or athn

Re: Dovecot and multi-factor auth support

2020-05-25 Thread Kevin Chadwick
>> Is there any sort of supported way of wiring up login_duo with >> OpenSMTPD and Dovecot, or using bsdauth in some way to enforce a >> second auth factor? > >bsdauth isn't really setup for multi factor, the only way I've seen >this >done is splitting the password field into a fixed-length OTP

Re: Why does OpenBSD still include Perl in its base installation?

2020-05-21 Thread Kevin Chadwick
On 2020-05-21 09:55, Anders Andersson wrote: >> I am a huge fan of minimal and custom installations >> as I mostly use OpenBSD to host simple HTTP servers. > ... >> I would like to get your opinion on that. > From what I've seen, those goals are not compatible with OpenBSD, as > in: You're just

Re: Howto change login mechanism on OpenBSD

2020-05-20 Thread Kevin Chadwick
On May 20, 2020 9:31:19 PM UTC, Edgar Pettijohn wrote: >On Wed, May 20, 2020 at 08:48:20PM +0200, Valdrin MUJA wrote: >> Hi Misc, >> >> I have an interactive shell program which has an authentication >section and I want to login via my program. How can I do that? >> >> Actually I want to run

unveil documentation

2020-05-13 Thread Kevin Chadwick
The unveil man page is perfectly correct and it is not hard to test it's behaviour. I just wonder if it may aid unveil adoption in languages other than C, if it explicitly mentioned that exec is not required on a dir to allow reading the files within, e.g. if the dev is more used to filesystem

Re: Mandate control in OpenBSD like SELinux or AppArmor

2020-05-11 Thread Kevin Chadwick
On May 11, 2020 7:27:49 PM UTC, i...@aulix.com wrote: >Please let me know, what are analogues of SELinux and AppArmor in OBSD > http://www.openbsd.org/mail.html You are supposed to "do your homework" and try googling and searching the mailing list archive before asking questions. Clearly you

Re: OpenBSD insecurity rumors from isopenbsdsecu.re

2020-05-11 Thread Kevin Chadwick
Here's a game. Name as many operating systems as you can that encrypt the page file or swap space by default?

Re: 'post quantum' encryption algorithm(s) in latest libressl and upcoming 6.7 to chose

2020-05-09 Thread Kevin Chadwick
On 2020-05-09 16:25, i...@aulix.com wrote: > Note: Since these MS / U.S. government keys are deeply sticking in Intel XEON > processor hardware, it doesn’t play a role, what other OS you install or boot > afterwards: Debian/UBUNTU Linux, OpenBSD, … If your software uses Intel > AES-NI hardware

Re: 'post quantum' encryption algorithm(s) in latest libressl and upcoming 6.7 to chose

2020-05-09 Thread Kevin Chadwick
On 2020-05-09 14:34, i...@aulix.com wrote: > D-waves has too uncoupled qubits if I understand it correctly, it is nothing > to do about qubits quantity as we used to think about it. Like a "cluster" of > completely isolated hosts (which is already not a cluster or course). I don't care for the

Re: 'post quantum' encryption algorithm(s) in latest libressl and upcoming 6.7 to chose

2020-05-09 Thread Kevin Chadwick
On 2020-05-09 14:31, i...@aulix.com wrote: > guessed by quantum provided session symmetric cipher is strong enough? Quantum does not break any in use today and AES-256 symmetric is expected to be quantum resistant in any case. I personally prefer AES-256 ctr over the more complex GCM. I am not

Re: 'post quantum' encryption algorithm(s) in latest libressl and upcoming 6.7 to chose

2020-05-09 Thread Kevin Chadwick
On 2020-05-09 07:41, Martin wrote: > This one > https://www.tomshardware.com/news/d-wave-5000-qubit-first-sale,40470.html > is the most powerful 5000qbits quantum computer sells nowadays. D-waves definition of qubit is different and their machines will never be capable of breaking public key

Re: 'post quantum' encryption algorithm(s) in latest libressl and upcoming 6.7 to chose

2020-05-09 Thread Kevin Chadwick
On 2020-05-09 07:41, Martin wrote: > This one > https://www.tomshardware.com/news/d-wave-5000-qubit-first-sale,40470.html > is the most powerful 5000qbits quantum computer sells nowadays. > > Moreother, D-Wave opened online service to access 5000qbit remotely for > solving 'special' tasks which

Re: OpenBSD insecurity rumors from isopenbsdsecu.re

2020-05-07 Thread Kevin Chadwick
On 2020-05-07 14:48, Aisha Tammy wrote: >> I wouldn't want to read an OS written in Rust and I would love to see secure >> developments in C even if it hampers potential performance. Things like Go >> are >> not suitable for an OS with many small programs. >> > Curious about why... though

Re: List a package's dependencies

2020-05-07 Thread Kevin Chadwick
On 2020-04-21 17:54, Kevin Chadwick wrote: >> Nope, it's definitely the wrong place to fix things. >> >> You should fix your pipes (change the timeouts or whatever). >> >> If worse comes to worst, pkg_add could *possibly* retry running ftp(1), >> but that ma

Re: OpenBSD insecurity rumors from isopenbsdsecu.re

2020-05-07 Thread Kevin Chadwick
On 2020-05-07 14:10, Consus wrote: > On Thu, May 07, 2020 at 04:00:15PM +0200, i...@aulix.com wrote: >> Dear OpenBSD fans, >> >> Can you please comment negative appraisal from the following website: >> >> https://isopenbsdsecu.re/quotes/ >> >> I did not want to hurt anyone, just looking for a

Re: How to enable TLS 1.3?

2020-04-30 Thread Kevin Chadwick
On 2020-04-30 13:55, Chad Hoolie wrote: > Any idea about relayd though? I don't see any mentioning of 1.3 in man > relayd.conf: I'm not a dev but tls1.3 dropped RSA and I think requires ecdsa key support that relayd currently lacks. Although httpd was originally based on relayd. I assume the

Cross platform apps.

2020-04-22 Thread Kevin Chadwick
Go/Golang can cross compile non graphical programs for many systems including OpenBSD from Windows etc. This means that web apps can be almost as cross platform. Of course the browser isn't so easily built/bundled cross platform with many app creation technologies supporting OSX, Windows, Linux

Re: Has anyone launched Steam for Linux on openbsd?

2020-04-22 Thread Kevin Chadwick
der > > There's also the https://www.playonbsd.com/ website that has more > information on gaming with BSD systems. > Both very cool > Kevin Chadwick wrote: >> Not sure but there wouldn't be much incentive anyway as there >> aren't many steam games that run on

Re: List a package's dependencies

2020-04-21 Thread Kevin Chadwick
On 2020-04-20 22:47, Marc Espie wrote: > Nope, it's definitely the wrong place to fix things. > > You should fix your pipes (change the timeouts or whatever). > > If worse comes to worst, pkg_add could *possibly* retry running ftp(1), > but that makes little sense. I agree ftp/tcp should be

Re: List a package's dependencies

2020-04-20 Thread Kevin Chadwick
> There are some unavoidable complexities to the sheer size of the tree, > and the necessities of updates not to fail... I have noticed recently that I occasionally get a gz truncated message (I think due to tcp timeout) and then the dependent package doesn't get updated. I then re-run pkg_add

Re: WLAN throughput less 10Mb/s

2020-04-14 Thread Kevin Chadwick
On 2020-04-14 09:21, Stefan Sperling wrote: > Regarding other chipsets, if you want the fastest possible AP on OpenBSD > your best option right now is to get a bwfm(4) device, which offloads almost > all of its 802.11 operation into a firmware blob running in the embedded > system on the device.

Re: Will windows 10 boot after installing openBSD?

2020-04-14 Thread Kevin Chadwick
You can also install Windows after and boot OpenBSD quite easily by following the faq. This is not easy on grub/Linux as grub is greedy. Atleast the guides that I found for grub/Linux, failed to work. I have no interest in running Linux these days though and little interest then. I had the notion

Re: Iridium vs Chromium

2020-04-12 Thread Kevin Chadwick
On April 12, 2020 7:07:01 PM UTC, Patrick Harper wrote: >The effort to support Chromium and Firefox (sans ESR) on OpenBSD akin >to Windows/macOS/'Linux' has not happened. On atleast current as Theo showed, Chromium is just as well if not better supported on OpenBSD than on Linux, these days. I

Re: Has anyone launched Steam for Linux on openbsd?

2020-04-11 Thread Kevin Chadwick
Not sure but there wouldn't be much incentive anyway as there aren't many steam games that run on Linux!

Re: secure MTA

2020-04-09 Thread Kevin Chadwick
> Now this whole debate boils down to "how much effort is someone willing to > invest > into hacking Cord's computers?", and that's something I can't answer. And how competent Cord is at defending his computer because they may not be able to if he is competent enough, which is my point; It is

Re: secure MTA

2020-04-09 Thread Kevin Chadwick
On 2020-04-09 10:55, Rudolf Leitgeb wrote: > My point was, that security is an ongoing effort. Flaws and new > exploit venues are discovered. There will be different numbers > of flaws for different operating systems, but none remains unscathed > for years. As soon as your server does anything

Re: secure MTA

2020-04-08 Thread Kevin Chadwick
On 2020-04-08 18:39, Claus Assmann wrote: > - Client-side exploitation: This vulnerability is remotely exploitable > in OpenSMTPD's (and hence OpenBSD's) default configuration. Although You missed some out. I assume on purpose. Client-side exploitation: This vulnerability is remotely

Re: news from my hacked box

2020-04-08 Thread Kevin Chadwick
On 2020-04-08 18:02, Rudolf Leitgeb wrote: > A public facing server with ftp, http, smtp and sshd would have had to be > patched > in regular intervals to remain reasonably secure. False, even though you have lowered the bar from "anything/everything is hackable". httpd and libressl have done

Re: news from my hacked box

2020-04-08 Thread Kevin Chadwick
On 2020-04-08 12:08, Rudolf Leitgeb wrote: >> I believe that is false too. > You're kidding, yes? Did you somehow miss the opensmtp hole? > > https://poolp.org/posts/2020-01-30/opensmtpd-advisory-dissected/ OpenSMTPD does not listen to the internet, by default and even if you do set it to, it

Re: news from my hacked box

2020-04-08 Thread Kevin Chadwick
On 2020-04-07 18:21, Rudolf Leitgeb wrote: > You have no chance defending your desktop against each and every attacker, no > matter > which operating system you have running. True if you consider physical attacks and for most hardware, otherwise mostly false. Anything can be hacked is also one

  1   2   3   4   5   6   7   8   9   10   >