Skip to content

OpenBSD

53 Topics 166 Posts

Strong, secure, no compromises.
For all things OpenBSD, pf, and pledge.

This category can be followed from the open social web via the handle openbsd@billboard.bsd.cafe

  • Welcome to the OpenBSD Section

    Pinned
    1
    3 Votes
    1 Posts
    343 Views
    stefanoS
    Secure by default, no compromises. Discuss anything related to OpenBSD here: pf, pledge, unveil, httpd, relayd, installations, hardware support, or just why you chose OpenBSD and never looked back. Whether you run it as your daily driver or as the silent guardian of your network, this is your table.
  • Fabricati-diem

    1
    1 Votes
    1 Posts
    32 Views
    CiotBSDC
    26/09/13 ⇒ Deshittification as a Service: Reclaiming Privacy and Performance with OpenBSD pf and Unbound When you buy a modern Smart TV, you are buying a display subsidized by surveillance. Even at high price points, manufacturers make slim margins on physical hardware. To drive post-sale revenue, they track your viewing habits, log your interactions, and serve you targeted ads. Smart TVs, especially LG models running WebOS, have quietly morphed from simple screens into active network spyware appliances. https://fabricati-diem.inform.social/post/deshittification-as-a-service/ 26/09/20 ⇒ Deshittification Part 2: Bypassing the App Store Gatekeeper In my previous post, Deshittification as a Service, I shared a blueprint for taking back control from modern Smart TVs. I placed an LG OLED running WebOS inside an isolated VLAN behind an OpenBSD gateway. My goal was simple. I wanted to block vendor telemetry, strip out ads, and force the TV to act like a plain display again. ⇒ Deshittification Part 3: The Cold-Boot Consent Trap in Three Acts In my first write-up, Deshittification as a Service, I laid out a network blueprint using OpenBSD, pf and Unbound to isolate an LG Smart TV running WebOS inside a dedicated VLAN. In Part 2: Bypassing the App Store Gatekeeper, I documented how WebOS responds to telemetry blocking by locking users out of the LG Content Store with artificial error codes, effectively holding software management hostage. https://fabricati-diem.inform.social/post/deshittification-as-a-service-part3-the-cold-boot-consent-trap-in-three-acts/ 26/10/04 ⇒ Deshittification Part 4: The Factory Reset Consent Trap In Part 1 of this series, I laid out the foundational OpenBSD and Unbound architecture used to reclaim network sovereignty from an LG Smart TV. In Part 2, we saw how the OS holds the App Store hostage. In Part 3, I documented a stateful TCP kill switch that actively terminates Netflix streams if telemetry is blocked. https://fabricati-diem.inform.social/post/deshittification-as-a-service-part4-the-factory-reset-privacy-trap/
  • [Rafael Sadowski: rsadowski.de]

    2
    0 Votes
    2 Posts
    37 Views
    CiotBSDC
    26/10/02 ⇒ Headers Up! What's New in httpd and relayd As I mentioned in my Dead Software Walking: The ongoing evolution of relayd(8) and httpd(8) post, development of relayd(8) and httpd(8) was revived. https://rsadowski.de/posts/2026/update-relayd-and-httpd/
  • [T.I.S: Tech Idea Systems (Blog & Ideas)]

    1
    1 Votes
    1 Posts
    48 Views
    CiotBSDC
    26/09/18 ⇒ Website Migration To OpenBSD! I had an issue with my previous webserver running Arch Linux where my SSH private key suddenly disappeared from the machine. I'm not sure whether it was due to the OpenSSH update from the prior day or a hack, but I wasn't too keen to find out. The main issue I had with running Arch Linux as a webserver was surrounding the replacement of cron with systemd timer files which I found really annoying to use. I personally don't get why the developers chose to replace a solid well-known tool that is simple to use with a tool that has so much complexity to it. https://tech-idea.systems/blog-posts/webserver-migration.html
  • [Undeadly.org] OpenBSD logs

    openbsd packetfilter tables
    10
    3 Votes
    10 Posts
    631 Views
    CiotBSDC
    26/09/18 ⇒ GEFS**, the "Good Enough File System" on the horizon for OpenBSD** Filesystems on OpenBSD have come in two varieties, UFS1 or UFS2. Ori Bernstein has set out to possibly introduce a new option, the "Good Enough File System", which Ori describes as https://undeadly.org/cgi?action=article;sid=20260918115729
  • [Nemin's Blog]

    1
    1 Votes
    1 Posts
    52 Views
    CiotBSDC
    26/09/13 ⇒ Tunnelling SSH over WireGuard on OpenBSD Making your access logs cleaner by restricting who can connect to your VPS https://nemin.hu/wireguard-ssh/index.html
  • OpenBSD VPS for $5 a Year

    1
    3 Votes
    1 Posts
    54 Views
    CiotBSDC
    A guide to deploying an OpenBSD VPS on TierHive, a NAT VPS provider offering supported OpenBSD images for under $5 per year. It covers setting up a 512 MB instance, SSH keys, and routing domain traffic with SSL using TierHive's built-in HAProxy service. https://btxx.org/posts/cheap-openbsd-vps/
  • [Miod Vallat] OpenBSD stories

    openbsd zaurus
    8
    5 Votes
    8 Posts
    668 Views
    CiotBSDC
    26/09/02 ⇒ OpenBSD stories—Strange Medieval Devices In the late 1970s and the 1980s, the best choice for high-performance, high-capacity storage was so-called SMD disks. http://miod.online.fr/software/openbsd/stories/smd.html
  • [Dr Brian R. Callahan]

    openbsd antirop
    2
    1 Votes
    2 Posts
    235 Views
    CiotBSDC
    26/08/11 ⇒ Cleaning costs, or, examining the OpenBSD -fret-clean flag I start with apologies to williewillus, calvin, and reezer on Lobste.rs. Prior to July 9, I would have agreed with you all. But it appears I was wrong. There is no need to further engage; it is clear that critique-from-within is undesirable. Which is perfectly OK, because I stepped away from being on the inside. So let's just keep evaluating OpenBSD's mitigations and we'll continue to learn interesting things along the way. https://briancallahan.net/blog/20260811.html
  • OpenBSD in the wild... spotted at the gym

    9
    2
    4 Votes
    9 Posts
    234 Views
    naltunN
    Thanks to everyone who pointed out Linux. Now that I'm paying attention this is clearly the systemd startup logging.
  • wg(4), pf(4), and relayd(8): a love story

    1
    2 Votes
    1 Posts
    105 Views
    naltunN
    tl;dr I used wg(4), pf(4), and relayd(8), all OpenBSD native tools, to encrypt all inbound connections from a gateway VPS to my local home server. This also hides my local IP information and I managed it all without much hassle and pain. I recently stood up a VPS running OpenBSD 7.9 on Vultr. The VPS is hosted in Chicago, Illinois, USA. I then took OpenBSD's native WireGuard driver, wg(4), to establish an encrypted tunnel to my local home lab server. Using relayd(8), OpenBSD's native reverse proxy, I can now forward virtual host connections to my home lab server, which has httpd(8) as a web server frontend. I used pf.conf(5) to configure OpenBSD's native fireweall, pf(4), which was incredibly easy. The result is a secure gateway that routes all traffic via WireGuard to my local server, obfuscating its location and other IP information. This was done by simply configuring handful of system daemons. I've done some OpenBSD network configuration before, but this was the most work I've done. The best part, it wasn't that difficult, and all manual pages provided sufficient details to work with them. Once I get my site set up I'll write up the experience and step-by-step instructions and share the page here. New OpenBSD milestone unlocked; no intent to stop anytime soon Happy hacking, hackers!
  • [Arxiv.org]

    openbsd study measures
    2
    0 Votes
    2 Posts
    130 Views
    grahamperrin@mastodon.bsd.cafeG
    @phessler FYI
  • [dataswamp.org/~solene] Full-featured email server running OpenBSD

    4
    1 Votes
    4 Posts
    205 Views
    CiotBSDC
    @naltun said: tyvm ??? Hummm, maybe: "Thank you very much", isn'it?!
  • 3 Votes
    1 Posts
    94 Views
    izder456I
    What title says More info here: https://github.com/outpaddling/desktop-installer/issues/30#issuecomment-4835472901
  • 2 Votes
    4 Posts
    265 Views
    CiotBSDC
    @grahamperrin said: OT ???
  • Partitioning without /usr/src and /usr/obj

    1
    3 Votes
    1 Posts
    119 Views
    V
    Hi! So I have a small VPS with OpenBSD on it and I anticipate that disk space will not be enough, so my question is, if I know that I will never compile the whole system from source, can I just repurpose the space allocated to /usr/obj and /usr/src and mount those partitions where they're needed? Or is this a really really bad idea? It would free up about 10GB (out of 40GB total).
  • SSH port knocking with OpenBSD 7.9

    openbsd ssh port-knocking
    1
    2 Votes
    1 Posts
    159 Views
    CiotBSDC
    Port knocking is mostly a bad idea. But people keep wanting to do it, for some false sense of security. If you don't consider it a security control but a way to keep garbage out of your logs, it might be valid. In my case I'm using an old USG Pro 4 running OpenBSD as my firewall and I'd prefer to avoid writing stuff to the logs, as I'd prefer the flash not to wear out sooner than needed, definitely not thanks to background radiation on the internet. https://dgl.cx/2026/06/ssh-port-knocking-with-openbsd
  • [astharoshe.net] Hello assembler!

    1
    4 Votes
    1 Posts
    117 Views
    naltunN
    Sharing this [1] link as I dive into amd64 assembly programming on OpenBSD (it really came in handy!). This [2] Reddit thread also helped me understand the elf(5) requirements for programming assembly on OpenBSD. Happy hacking! [1] https://astharoshe.net/2020-06-28-Hello_assembler.html [2] https://www.reddit.com/r/openbsd/s/JN0hTLNKQF e: typo
  • 3 Votes
    3 Posts
    230 Views
    CiotBSDC
    @grahamperrin said: … The code originated from FreeBSD, which itself derived it from Cronyx Engineering Ltd.'s implementation written by Serge Vakulenko in 1994-1996. … I assume that FreeBSD is not affected. Surely (!?) But I dont known!
  • [Kirill's journal]

    openbsd qemu
    1
    2 Votes
    1 Posts
    156 Views
    CiotBSDC
    ⇒ OpenBSD under QEMU Architecture specific notes for OpenBSD guests under QEMU, with working command lines where installation succeeds and failure points where it does not. https://kirill.korins.ky/articles/openbsd-under-qemu/