<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[FreeBSD - a lesson in poor defaults]]></title><description><![CDATA[<blockquote>
<p dir="auto">This page lists some of the changes I make to a vanilla install of FreeBSD for security hardening. Some changes to increase network performance or make things a bit more sane are also included. It only covers basic changes that a sysadmin can make to a running system.<br />
It could also be considered a commentary piece on the state of security in FreeBSD's development ecosystem, highlighting their strong resistance to change and unwillingness to replace old cruft with modern alternatives.<br />
The project's security page says the following:</p>
<p dir="auto">FreeBSD takes security very seriously and its developers are constantly working on making the operating system as secure as possible.</p>
<p dir="auto">But is that really true? Let's find out.</p>
</blockquote>
<ul>
<li><a href="https://vez.mrsk.me/freebsd-defaults" rel="nofollow ugc">https://vez.mrsk.me/freebsd-defaults</a></li>
</ul>
<hr />
<p dir="auto"><em>ping: <a href="https://mastodon.social/@CuratedHackerNews/116549957974859573" rel="nofollow ugc">https://mastodon.social/@CuratedHackerNews/116549957974859573</a></em></p>
]]></description><link>https://billboard.bsd.cafe/topic/157/freebsd-a-lesson-in-poor-defaults</link><generator>RSS for Node</generator><lastBuildDate>Sun, 17 May 2026 21:45:27 GMT</lastBuildDate><atom:link href="https://billboard.bsd.cafe/topic/157.rss" rel="self" type="application/rss+xml"/><pubDate>Sun, 10 May 2026 12:08:23 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to FreeBSD - a lesson in poor defaults on Fri, 15 May 2026 13:01:55 GMT]]></title><description><![CDATA[<p dir="auto">No problem with the vote <img src="https://billboard.bsd.cafe/assets/plugins/nodebb-plugin-emoji/emoji/android/1f609.png?v=d540d9eb8c6" class="not-responsive emoji emoji-android emoji--wink" style="height:23px;width:auto;vertical-align:middle" title=";)" alt="😉" /></p>
<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/grahamperrin" aria-label="Profile: grahamperrin">@<bdi>grahamperrin</bdi></a> <a href="/post/461">said</a>:</p>
<p dir="auto">For what it's worth, I think: don't delete it from BSD Cafe Billboard. It's good to raise awareness of the reputation.</p>
</blockquote>
<p dir="auto">I hadn't thought of it that way. Interesting!</p>
]]></description><link>https://billboard.bsd.cafe/post/462</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/462</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Fri, 15 May 2026 13:01:55 GMT</pubDate></item><item><title><![CDATA[Reply to FreeBSD - a lesson in poor defaults on Fri, 15 May 2026 11:27:26 GMT]]></title><description><![CDATA[<p dir="auto">Hi, thanks.</p>
<p dir="auto">The subject line here does match the title of <a href="https://vez.mrsk.me/freebsd-defaults" rel="nofollow ugc">the linked article</a>. This is good practice, good netiquette <img src="https://billboard.bsd.cafe/assets/plugins/nodebb-plugin-emoji/emoji/android/1f44d.png?v=d540d9eb8c6" class="not-responsive emoji emoji-android emoji--+1" style="height:23px;width:auto;vertical-align:middle" title=":+1:" alt="👍" /></p>
<p dir="auto">The downvote (from me) is because the value of the article is disupted; you could not have known this when you shared it. It's a downvote for the article, not for you personally <img src="https://billboard.bsd.cafe/assets/plugins/nodebb-plugin-emoji/emoji/android/1f642.png?v=d540d9eb8c6" class="not-responsive emoji emoji-android emoji--slightly_smiling_face" style="height:23px;width:auto;vertical-align:middle" title=":-)" alt="🙂" /></p>
<p dir="auto">For what it's worth, I think: don't delete it from BSD Cafe Billboard. It's good to raise awareness of the reputation.</p>
<p dir="auto">The <a href="https://news.ycombinator.com/item?id=48082342" rel="nofollow ugc">recent Hacker News story</a> that unearthed the article gained very few votes.</p>
]]></description><link>https://billboard.bsd.cafe/post/461</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/461</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Fri, 15 May 2026 11:27:26 GMT</pubDate></item><item><title><![CDATA[Reply to FreeBSD - a lesson in poor defaults on Wed, 13 May 2026 07:50:20 GMT]]></title><description><![CDATA[<p dir="auto"><strong>In fact, as the subject line seems rather inappropriate, you can even delete it if you have the necessary permissions!</strong></p>
]]></description><link>https://billboard.bsd.cafe/post/448</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/448</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 13 May 2026 07:50:20 GMT</pubDate></item><item><title><![CDATA[Reply to FreeBSD - a lesson in poor defaults on Wed, 13 May 2026 07:30:03 GMT]]></title><description><![CDATA[<blockquote>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/grahamperrin" aria-label="Profile: grahamperrin">@<bdi>grahamperrin</bdi></a> <a href="/post/445">said</a>:</p>
<p dir="auto">a gentle hint: in the absence of quotation marks, casual readers who don't follow links might wrongly imagine that the words above are yours.</p>
</blockquote>
<p dir="auto">Thank for the remark!<br />
In fact, as you’ve realised, they’re not mine, but the author’s; I’ve tweaked the first post slightly.</p>
]]></description><link>https://billboard.bsd.cafe/post/447</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/447</guid><dc:creator><![CDATA[CiotBSD]]></dc:creator><pubDate>Wed, 13 May 2026 07:30:03 GMT</pubDate></item><item><title><![CDATA[Reply to FreeBSD - a lesson in poor defaults on Wed, 13 May 2026 00:18:29 GMT]]></title><description><![CDATA[<p dir="auto"><a href="https://mastodon.bsd.cafe/@grahamperrin/116564335700354892" rel="nofollow ugc">https://mastodon.bsd.cafe/@grahamperrin/116564335700354892</a> "tired old crap" …</p>
<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/ciotbsd" aria-label="Profile: ciotbsd">@<bdi>ciotbsd</bdi></a> a gentle hint: in the absence of quotation marks, casual readers who don't follow links might wrongly imagine that the words above are yours.</p>
<hr />
<p dir="auto">From the <a href="https://freebsdfoundation.org/about-us/our-team/" rel="nofollow ugc">Senior Director of Technology at the FreeBSD Foundation</a> in August 2022:</p>
<blockquote>
<p dir="auto">This link gets shared around every now and then, and my response is always the same: there is some useful insight, but there's also information that's <strong>so outdated it provides no value</strong>, outright <strong>misinformation</strong>, and <strong>self-contradiction</strong>. Some of the technical points are fair, and should be and are being addressed. But the <strong>commentary is often laughably wrong</strong>. The document seems more focused on advancing an agenda than a good-faith effort at improving security in FreeBSD.</p>
</blockquote>
<ul>
<li>emphases: mine</li>
<li><a href="https://lobste.rs/s/2xxp8y/freebsd_lesson_poor_defaults#c_mhsghw" rel="nofollow ugc">https://lobste.rs/s/2xxp8y/freebsd_lesson_poor_defaults#c_mhsghw</a></li>
</ul>
]]></description><link>https://billboard.bsd.cafe/post/445</link><guid isPermaLink="true">https://billboard.bsd.cafe/post/445</guid><dc:creator><![CDATA[grahamperrin]]></dc:creator><pubDate>Wed, 13 May 2026 00:18:29 GMT</pubDate></item></channel></rss>