I've just updated my GitHub #Sponsors profile! Now, supporters get access to a monthly newsletter with insights on my latest work, project updates, and thoughts on OpenBSD development. Check it out and join the journey. #OpenBSD #OpenSource
"coding is solved" they said
"use AI" they said
me working on OpenBSD writing C: dead software walking
https://rsadowski.de/posts/2026/dead-software-walking-relayd-and-httpd/
httpd(8) gains support for custom HTTP headers https://www.undeadly.org/cgi?action=article;sid=20260725103657 #openbsd #httpd #customheaders #securityheaders #webserver #security #libresoftware #freesoftware
Generative AI Is an engineering disaster. A shockingly inefficient trillion-dollar project…
Paywalled article:
https://www.theatlantic.com/technology/2026/07/generative-ai-engineering-disaster/687901/
#tech #technology #BigTech #IT #AI #ArtificialIntelligence #LLM #LLMs #ML #MachineLearning #GenAI #generativeAI #AIAgent #AISlop #FuckAI #Fuck_AI #enshittification #microslop #microsoft #copilot #meta #google #NVIDIA #amazon #gemini #OpenAI #ChatGPT #anthropic #claude
relayd(8) and httpd(8) TLS settings update.
Both
relayd(8)
and
httpd(8)
now have the "secure" list of allowed crypto methods for
HTTPS, which include
TLSv1.3 and the TLSv1.2 AEAD cipher suites.
The previous list was "HIGH:!aNULL" which contain non-perfect-forward-security
methods and this change may cause old clients to not be able to connect.
Three days fighting Rust in CMake so KDE Plasma 6.7 can land in OpenBSD ports, then back to httpd & relayd. My g2k26 hackathon writeup: https://rsadowski.de/posts/2026/g2k26-netherlands-openbsd-hackathon/
By the way, our first two publications on evaluating #OpenBSD mitigations are out. Both of these papers evaluate some amd64 anti-ROP mitigations: specifically changing the register selection order and semantically equivalent rewriting of instructions that may produce a potential polymorphic gadget instruction. This tracks a paper by mortimer@ back in 2019 at AsiaBSDCon.
The TL;DR is "OpenBSD can shrink binaries a little and gain a little performance without any security loss simply by reverting these mitigations." The mitigations did not hold up to independent evaluation.
The first paper did an exact 1:1 port of these mitigations to FreeBSD and found that register reallocation eliminates only about 0.3% of unique gadgets, for a 0.5% increase in binary size (mortimer@ claimed 6% reduction and "entirely free"). It is useless at best but more likely actively detrimental, as it produces a false sense of security. It also found the instruction rewriting reduces unique gadgets by about 3.5% with a binary size increase of about 1.8% (mortimer@ claimed 5% reduction with 0.15% binary size increase).
We then did a separate implementation of the instruction rewriting mitigation to GCC in the second paper. Our GCC implementation does the older <xchg; op; xchg> dance, as that's what mortimer@'s paper described. This is way worse; producing about a 3% performance hit for no security benefit at all.
The only part of both mitigations worth saving is for basic arithmetic, OpenBSD LLVM now takes advantage of the fact that basic arithmetic has two forms. For example, the newer instruction rewriting mitigation turns
addq %rax, %rbx (48 01 c3)
into
{load} addq %rax, %rbx (48 03 d8)
The new instruction rewriting mitigation is genuinely free in terms of binary size and execution speed, but doesn't move the security needle, so this one can stay as it is harmless. Other rewritings still have the flaw of increasing binary size and reducing performance for no security benefit.
Anyhow feel free to read the papers:
https://ieeexplore.ieee.org/abstract/document/11458911
https://www.researchgate.net/publication/405728967_A_Final_Return_for_OpenBSD_Anti-Return-Oriented_Programming_Mitigations
#BSD #FreeBSD #NetBSD #DragonFlyBSD #Linux #Unix #security #cybersecurity
If you have the Facebook app on your phone, Mark Zuckerberg would like to monitor your entire life by uploading every photo you take to a secret Facebook database and have AI identify every place you have been, every person you have met, every activity you have participated in, etc.
I do not know how Facebook lures people into turning this on, but I recommend everyone check their settings, and I have made these four pictures which show how you turn it off.
Please reply if yours was on.
Der Vortrag von @sizeofvoid zu den Grundsätzen und (#Security-)Prinzipien von #OpenBSD auf den #CLT2026 war ganz hervorragend. 👍
Selbst ohne BSD-Kenntnisse gut verständlich! Klare Guck-Empfehlung, gerade in Zeiten von AI-Slop und Security-Desastern, die inzwischen teilweise wie Naturkatastrophen behandelt werden.
rsadowski@openbsd.org