Hacker News new | ask | show | jobs
by terry_hc 30 days ago
The slides are over 6 years old. The developers' attitudes haven't changed much, but are all of the arguments still valid?

I've followed this discussion here and there over the years and it always goes like this:

1) everyone makes fun of the mitigations

2) many even outright assert they can easily defeat and exploit OpenBSD

3) nobody provides a working PoC when asked to demonstrate how insecure the OS is

And somewhere in the mix there's also you and your usual blabber, also without any substantial examples of how insecure and exploitable the OS is. Always.

1 comments

The site isn't the slide deck. Let's talk after you've read it?
I have now read all of the points in the mitigations section. Just like the slides, the commentaries to the mitigations willingly assert uselessness and imply a sense of absolute insecurity, but without specific or even general examples.

So I'm looking forward to your careful explanation of how insecure the whole thing is and how easily it can be dismantled. Because I really want and need to know. Let's talk.

Wait, what? No they don't. The author is an OpenBSD person and calls out several mitigations as clever and worthwhile.
No, the author isn't an "OpenBSD person".
Isn't this Joshua Stein? (I feel like I've gotten this wrong before.)
No, AFAIK the author is German and his nickname is stein (stone).
It's not, and you have.