frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

We're (now) moving from OpenBSD to FreeBSD for firewalls

https://utcc.utoronto.ca/~cks/space/blog/sysadmin/OpenBSDToFreeBSDMove
53•zdw•5d ago

Comments

0xWTF•22m ago
I don't understand why this has 29 points and no comments. What's so amazing about this?
wslh•22m ago
Discussion threads about performance?
wslh•22m ago
I imagine a near future where TCP/IP stacks, and device drivers are interchangeable between operating systems. In Linux, NDISWrapper [1] enables to use Windows drivers in Linux but it's a wrapper (with all due respect to this project).

[1] https://en.wikipedia.org/wiki/NDISwrapper

awesome_dude•12m ago
Microsoft started out with BSD's TCP/IP stack, but dropped it for their own (back in Windows 3.5 apparently - https://news.ycombinator.com/item?id=41495551)
zokier•3m ago
[delayed]
jmclnx•22m ago
For me, the only drawback for corporations is the 6 month upgrade. There is no LTS on OpenBSD.

I use OpenBSD as a workstation and it works great, but in a production environment I doubt I would use OpenBSD for critical items, mainly because no LTS.

It is a sad state of affairs because Companies do not want nor will want a system you need to upgrade so often even if its security very good.

rootnod3•9m ago
On the other hand though, updates on OpenBSD are the most painless updates I have ever done. I am more concerned about it's usage of UFS instead of something more robust for drives.
SoftTalker•7m ago
Yet companies insist on enabling unattended upgrades at least for "security" patches, which have introduced breakage or even their own vulnerabilities in the past (Crowdstrike was a recent dramatic example).

OpenBSD will just tell you that maintaining an LTS release is not one of their goals and if that's what you need you'll be better served by running another OS.

awesome_dude•19m ago
> There are some things about FreeBSD that we're not entirely enthused about.

Damn I wish that they had expanded on this a bit (not to start a flame war, but to give readers a fuller picture, or even to prod the FreeBSD community into "fixing" those things)

edit: typo fix

lloydatkinson•11m ago
It does seem like a weird omission doesn’t it?
SoftTalker•19m ago
As noted, recent changes to OpenBSD TCP handling[1] may improve performance.

On a 4 core machine I see between 12% to 22% improvement with 10 parallel TCP streams. When testing only with a single TCP stream, throughput increases between 38% to 100%.

I'm not sure that directly translates to better pf performance, and four cores is hardly remarkable these days but might be typical on a small low-power router?

Would be interesting if someone had a recent benchmark comparison of OpenBSD 7.8 PF vs. FreeBSD's latest.

[1] https://undeadly.org/cgi?action=article;sid=20250508122430

dylan604•16m ago
I once wrote a similar post to an DVD industry centric mailing list (remember those?) regarding switching to FCP7 from Adobe Premiere with a huge difference in how FCP7 would allow capturing of discrete audio channels vs Premiere forcing an interleaved audio stream. Eventually, a rep from Adobe contacted me through my company's PR team (a first for me) to go over the list of complaints. At the end, he agreed these were all valid complaints, and then asked "if Premiere added these changes would I be willing to switch back"? At that point, I said probably not as we'd now be fully switched to FCP7 in all departments. So I understand that sentiment as well. Honestly, I was shocked that someone actually read my missive and actually paid any mind to it. So maybe someone at OpenBSD will be as receptive if not equally unable to do anything about it.
yuvadam•7m ago
What's wrong with Linux for firewalls? Either openwrt, or any distro really.

Why would any BSD perform better?

2trill2spill•4m ago
I assume in this case they already had a bunch of firewall rules for PF and switching from OpenBSD -> FreeBSD is a much easier lift then going to linux because both the BSDs are using PF, although IIRC there are some differences between both implementations.
electric_mayhem•2m ago
PF is really nice. (Source: me. Cissp and a couple decades of professional experience with open source and proprietary firewalls).

And if they are already using it on openbsd, it’s almost certainly an easier lift to move from one BSD PF implementation to another versus migrating everything to Linux and iptables.

theideaofcoffee•3m ago
Just more navel-gazing from UTCC. I still don't understand why all of these submissions get upvoted so often. 10G performance just really isn't that interesting anymore, maybe around 2005 when it was the new kid on the block. If they were talking about squeezing firewall performance out of a box with a couple of 200g or 400g adapters and on run-of-the-mill CPUs and no offloading or something like Netflix publishes with their BSD work, I'd be more interested.

France threatens GrapheneOS with arrests / server seizure for refusing backdoors

https://mamot.fr/@LaQuadrature/115581775965025042
493•nabakin•1h ago•161 comments

SHA1-Hulud the Second Comming – Postman, Zapier, PostHog All Compromised via NPM

https://www.aikido.dev/blog/shai-hulud-strikes-again-hitting-zapier-ensdomains
292•birdculture•2h ago•94 comments

Cool-retro-term: terminal emulator which mimics look and feel of the old CRTs

https://github.com/Swordfish90/cool-retro-term
30•michalpleban•1h ago•10 comments

We're (now) moving from OpenBSD to FreeBSD for firewalls

https://utcc.utoronto.ca/~cks/space/blog/sysadmin/OpenBSDToFreeBSDMove
54•zdw•5d ago•16 comments

NSA and IETF, part 3: Dodging the issues at hand

https://blog.cr.yp.to/20251123-dodging.html
251•upofadown•6h ago•118 comments

Inside Rust's std and parking_lot mutexes – who wins?

https://blog.cuongle.dev/p/inside-rusts-std-and-parking-lot-mutexes-who-win
79•signa11•4d ago•13 comments

Launch HN: Karumi (YC F25) – Personalized, agentic product demos

https://www.karumi.ai/meet/start/phlz
3•tonilopezmr•20m ago•0 comments

Chrome Jpegxl Issue Reopened

https://issues.chromium.org/issues/40168998
149•markdog12•6h ago•47 comments

Show HN: Cynthia – Reliably play MIDI music files – MIT / Portable / Windows

https://www.blaizenterprises.com/cynthia.html
67•blaiz2025•4h ago•17 comments

Corvus Robotics (YC S18): Hiring Head of Mfg/Ops, Next Door to YC Mountain View

1•robot_jackie•1h ago

Shai-Hulud Returns: Over 300 NPM Packages Infected

https://helixguard.ai/blog/malicious-sha1hulud-2025-11-24
634•mrdosija•8h ago•500 comments

Serflings is a remake of The Settlers 1

https://www.simpleguide.net/serflings.xhtml
102•doener•2d ago•33 comments

Andrej Karpathy on X: implications of AI to schools

https://twitter.com/karpathy/status/1993010584175141038
37•bilsbie•1h ago•26 comments

We stopped roadmap work for a week and fixed bugs

https://lalitm.com/fixits-are-good-for-the-soul/
198•lalitmaganti•1d ago•272 comments

Historically Accurate Airport Dioramas by AV Pro Designs

https://www.core77.com/posts/138995/Historically-Accurate-Airport-Dioramas-by-AV-Pro-Designs
22•surprisetalk•3d ago•4 comments

Slicing Is All You Need: Towards a Universal One-Sided Distributed MatMul

https://arxiv.org/abs/2510.08874
83•matt_d•5d ago•9 comments

Disney Lost Roger Rabbit

https://pluralistic.net/2025/11/18/im-not-bad/
421•leephillips•6d ago•207 comments

RuBee

https://computer.rip/2025-11-22-RuBee.html
319•Sniffnoy•15h ago•56 comments

Japan's gamble to turn island of Hokkaido into global chip hub

https://www.bbc.com/news/articles/c8676qpxgnqo
254•1659447091•15h ago•377 comments

A New Raspberry Pi Imager

https://www.raspberrypi.com/news/a-new-raspberry-pi-imager/
35•raus22•2h ago•10 comments

µcad: New open source programming language that can generate 2D sketches and 3D

https://microcad.xyz/
361•todsacerdoti•22h ago•117 comments

Ask HN: Hearing aid wearers, what's hot?

309•pugworthy•16h ago•176 comments

I built a faster Notion in Rust

https://imedadel.com/outcrop/
134•PaulHoule•4d ago•69 comments

Google's new 'Aluminium OS' project brings Android to PC

https://www.androidauthority.com/aluminium-os-android-for-pcs-3619092/
4•jmsflknr•8m ago•0 comments

GrapheneOS migrates server infrastructure from France

https://www.privacyguides.org/news/2025/11/22/grapheneos-migrates-server-infrastructure-from-fran...
6•01-_-•9m ago•2 comments

The Rust Performance Book (2020)

https://nnethercote.github.io/perf-book/
189•vinhnx•5d ago•31 comments

Lambda Calculus – Animated Beta Reduction of Lambda Diagrams

https://cruzgodar.com/applets/lambda-calculus
128•perryprog•13h ago•8 comments

New magnetic component discovered in the Faraday effect

https://phys.org/news/2025-11-magnetic-component-faraday-effect-centuries.html
192•rbanffy•4d ago•69 comments

Show HN: Virtual SLURM HPC cluster in a Docker Compose

https://github.com/exactlab/vhpc
38•ciclotrone•5d ago•6 comments

Mind-reading devices can now predict preconscious thoughts: is it time to worry?

https://www.nature.com/articles/d41586-025-03714-0
11•srameshc•31m ago•1 comments