9 ms·
> The OpenBSD project uses a lot of electricity for running the > development and build machines. A number of logistical reasons > prevents us from moving
by jdludlow 13y ago
> The OpenBSD project uses a lot of electricity for running the
> development and build machines. A number of logistical reasons
> prevents us from moving the machines to another location which might
> offer space/power for free, so let's not allow the conversation to go
> that way.
I don't understand this comment. If the choice came down to moving versus shutting down entirely, why is moving an unacceptable answer?
- HeyLaughingBoy 13y agoSeriously? What's not to understand? He said they had reasons that prevent them from moving and didn't want to discuss it further. Why push it? Isn't he in a better position to decide what's unacceptable than you are?
- simias 13y agoProbably, but then again if he wants my money he better explain why he needs it and how he's going to spend it, doesn't he? That being said since OpenBSD is all about security maybe that's the reason they don't want to move the servers to some place where they won't be able to monitor physical access to the machines. That's pure speculation though.
- gtaylor 13y agoIf he's asking for money from me, I would like to know why it's not an option. The root of the issue being raised is power/space, so I'd definitely want to know why I'm forking up for something the project could potentially get for free. It's not a big deal, and I don't expect him to go into detail. He just won't get a cent from me without elaborating, and that's OK. I'm not mad, and I understand he has mis-givings. I just don't think that answer is acceptable enough for me to donate, but that's my subjective opinion (and not everyone else's).
- astrodust 13y agoIf you're asking for help and you have constraints, you better qualify those constraints in a way that builds confidence. The more transparency you have in your discussion, the more supportive people will be.
- justin66 13y ago> The more transparency you have in your discussion, the more supportive people will be. I think that's total, obvious nonsense and if you need to be convinced, here's an exercise: consider how much money the average nonprofit would raise if people knew where all that money went.
- cdash 13y agoThe average nonprofit isn't worthy of the money they get so unless you are trying to say OpenBSD is not worthy of the money and the only way they can get it is to hide the details then I don't get what your point is.
- wpietri 13y agoYou mean like publishing accounts? Maybe even including salaries for the highly paid people? Because every US nonprofit is required by law to do that. You can browse it all on line: http://foundationcenter.org/findfunders/990finder/ http://foundationcenter.org/findfunders/990finder/
- justin66 13y agoThat is a nice tool, thanks. Someone else posted something similar recently and it wanted to charge $250 for membership or something like that. The web is bringing a lot of good transparency to nonprofits but there's still a lot of repugnant wastefulness and avarice that often isn't captured well by a 990 form. (publishing salaries is pretty huge, though) I stand by my point that the more a person learns about the average charity the less they're going to want to donate... transparency doesn't magically lead to supportiveness. And wanting a project to account for every watt of electricity is just completely silly. edit: transparency is a way for better charities to look good relative to poor ones, yes, but all things being equal, it's a negative for fundraising: as with business and government, a lot of what goes on in ANY organization is ugly to look at and is bound to turn some people off. (none of that is an argument against transparency itself, let's just not kid ourselves about its usefulness for raising money)
- orbitur 13y agoIf I'm donating I would like to know exactly where the money is going, and what options have already been explored. OpenBSD should have referenced, full documentation about these things if they want to maximize donations. Apparently, there isn't very much documentation/open accounting, and they aren't willing to discuss options to reduce the bill. That doesn't inspire confidence.
- gtaylor 13y ago> Apparently, there isn't very much documentation/open accounting, and they aren't willing to discuss options to reduce the bill. That doesn't inspire confidence. It is a lot of work for a small team to itemize and publish every expense, but some rough breakdown of monthly expenses that my donation would be going towards would really help.
- jff 13y agoIf they know they need $20k, they must have arrived at that number somehow. Publishing that estimation would be a good start.
- cdcarter 13y agoIf their books are clean, this is actually pretty easy. Just pulling an annual operating budget should be much easier, if they have good financial practices and controls in place.
- hhw 13y agoThey're not looking for a lot of smaller donators in this specific instance (although I'm sure it's appreciated), but rather one large Canadian company to foot the bill and on that company's books for accounting purposes.
- justincormack 13y agoThese costs are not much versus the costs of hiring developers.
- 13y ago
- gtaylor 13y agoEspecially if the fate of OpenBSD as it stands is hanging in the balance. Depending on who is offering, this may be because of the uncertainty of whatever arrangement is being proposed. For example, if a smaller company or an individual offers to foot the bill, what happens if the company/individual later has a budget crunch of their own, or decides to cut ties? Of course, if an IBM/Apple/Google/etc offers space/power, it may be a less risky proposition.
- calpaterson 13y ago> why is moving an unacceptable answer It seems likely that they don't trust anyone else to have physical access to the machines for security reasons. Their threat model probably includes national governments.
- gtaylor 13y agoIt's possible, but without any kind of answer we are all just guessing.
- tptacek 13y agoA somewhat related note about branding. My first "real" job was in the mid-90's; I was the first technical hire at a small Chicago ISP (EnterAct) that grew into a relatively large ISP (when I left, we were default-free peered to several tier-1 providers and had more POPs than I can name). It was great, and the team that started it --- two Big-5 accounting firm programmers --- was inspiring, particularly when it came to business strategy. Anyways, very early on, EnterAct managed to maneuver into a reputation for premium customer support. We got that reputation by doing some concrete things differently than our competitors: we staffed an appropriate number of CSRs, trained them to be nice to customers, did a lot of gratuitous tech support for basic computer problems, and were flexible about resolving billing disputes. Sadly, a lot of those things were differentiators at the time. A couple years in and we were essentially able to hang "best customer support" on our list of features, and eventually we became the most popular ISP in Chicago largely based on that. But something I came to notice pretty quickly: the things we were doing to earn that support reputation stopped being empirical differentiators pretty quickly. Our largest competitor, run by Karl Denninger, did us a continuing series of favors by pissing off their customers. But other large regional ISPs pretty quickly learned not to set fire to their customer base, and, by the end, I think our customer service was pretty much at par for the whole area; we were no longer truly different based on support. The reputation, however, never left. That observation has stuck with me for my entire career. I think about it all the time. It's banal, I know: "early impressions count a lot", but there's a little more to it than that: you can weaponize an early impression by turning it into your market positioning and having some message discipline. I left EnterAct for a job in Calgary with a company called Secure Networks (SNI), doing development and security research. For the year prior to leaving EnterAct, I had also been working with the OpenBSD project, mostly by writing all their security advisories, but also doing a bit of part-time security research. SNI operated the world's first commercial vulnerability research team, and had a very close relationship with Theo; we had a full time employee who had essentially led the first OpenBSD security audit. I went drinking with Theo many times, and vividly remember hanging out in his basement with Tim Newsham eating bad pizza and trying to find vulnerabilities in Daniel Bernstein's qmail (we found one that would work if integers were 128 bits, but ironically missed the LP64 bugs that Georgi Guninski found; it was 1997, though). This is all a long prelude to a simple point, which is that I think OpenBSD's reputation for security works in a very similar way to how EnterAct's reputation worked. OpenBSD started doing something very different than FreeBSD, Linux, and (particularly) NetBSD: they did an OS-wide audit for vulnerabilities, and aggressively fixed apparent bugs whether or not we could demonstrate that they were exploitable. That was a great move. But it was so obviously great that pretty much everyone (with the possible exception of NetBSD) quickly adopted the practice. Among security research insiders, OpenBSD's reputation became a little bit farcical. Not that OpenBSD was comically insecure --- it wasn't --- but that its reputation so far outstripped its actually differentiation. People found a bunch of vulnerabilities in OpenBSD and laughed as the claim at the top of the OpenBSD changed from "no vulnerabilities" to "no remotely exploitable vulnerabilities in the default install". And at some point in the last 10 years, didn't OpenBSD's distro servers get owned up? I'm sure the OpenBSD project would like its threat model to include NSA. But OpenBSD is not a meaningful ally in a contest between you and NSA. NSA wins that fight. OpenBSD's userland was much stronger than FreeBSD's in 1999, but I'm not sure I think their kernel is stronger in 2013, and that's probably what matters more. Let me wind this bloviation up with a caveat: one thing a reputation for security gets you is a feed of talent that is interested in working on security problems. OpenBSD certainly got that. So for instance, OpenBSD's developers designed and built privilege-separated OpenSSH. There is a lot of good security work that has started inside the OpenBSD project, and I don't mean to talk any of that stuff down. I'd just be careful about taking the project's overall reputation to the bank, especially if you have serious adversaries. Sorry for hanging this sprawling comment off your (simpler) point; I just don't want the root comment on the thread to be me talking down OpenBSD.
- takeda 13y agoI've seen a picture posted on Slashdot how they server rack looks like. There are many very old machines, I am sure that at least one reason is fear that they break during transportation. Found it: http://www.openbsd.org/images/rack2009.jpg http://www.openbsd.org/images/rack2009.jpg
- sliverstorm 13y agoWhy not move the machines, and if the Amiga breaks down and they can't find a replacement, end Amiga support? I mean, that's not a wonderful outcome, but what would you prefer to see given the following options? a) Shut down OpenBSD b) Shut down Amiga support in OpenBSD I mean, is it even a hard choice? Besides, if there are many developers who like developing for Amiga, surely they would be able to find a replacement?
- d_theorist 13y agoOr hidden option c): ask people to donate money.
- sliverstorm 13y agoWell, yes, clearly. But it's been a month since the initial ask, and this sort of "threat": the fact is right now, OpenBSD will shut down if we do not have the funding to keep the lights on. suggests the necessary $20k (cash) has not been forthcoming. P.S. I understand it's not a threat in the sense of ransom etc, but the most correct word is not coming to my mind.
- sdkmvx 13y agoOpenBSD supports a number of odd and unusual platforms and does builds on them. See http://www.openbsd.org/plat.html http://www.openbsd.org/plat.html. Older hardware can both use a significant amount of electricity and require much more hand-holding than is possible. Virtualization and emulation are not acceptable substitutes because they claim that doing builds on e.g. VAX is one of the best ways to ensure that the code works on VAX as opposed to simply booting on VAX. They also regularly find bugs affecting all platforms that are exacerbated by one particular architecture (think alignment or endianness issues).
- nailer 13y agoOpenBSD's main value is high security standards. - Is there a significant amount of people with high security standards and an interest in SGI workstation hardware? - What about people who have high security standards and Sharp Zaurus hardware? If these groups aren't as important, as say, ARM and x86 users, perhaps it could be worth dropping some of these platforms?
- chrissnell 13y agoAs a longtime OpenBSD fan and advocate, this has always fascinated me. I loved SGIs back in the day but they are slow as shit today and unusable for any kind of modern desktop usage unless all you do is write code in a terminal. These platforms survive in OpenBSD land because somebody still cares enough about them to enjoy hacking on them. There's no point in saying "Drop them!" because the devs working on them probably could care less what the rest of us think. Personally, I do wish OpenBSD could somehow regain the popularity it once had and that support for modern hardware like 10GBE and scaling PF throughput w/ multi-core CPUs would improve. I don't know what it would take to bring people back.
- gwu78 13y ago"... and unusable for any kind of modern desktop usage unless all you do is write code in a terminal." Sounds good to me. Many times (actually most times) I have no need for a "desktop" metaphor on my screen in order to get things done. I actually get more done big jobs done faster without the desktop metaphor in the way. "... the devs working on them probably could care less what the rest of us think." That's what makes them so special. Perhaps in the long run the most "powerful" and sought after computers will not be the ones with the latest chips, but the ones that the user has the most knowledge of and control over. Can you imagine the old-timer reminiscing: "Remember when computers didn't have backdoors built-in?" or "Remember when you did not have to pay for a license to write programs for hardware you bought?"
- mrweasel 13y agoI'm pretty sure that a lot of the older hardware at least require some degree of hands on administration. Rebuilding an testing a new kernel on a VAX with no remote administration features would slow things down. Having stuff easily available makes a lot of sense to me.
- jlgaddis 13y agoBecause Theo.
- tobiasu 13y agoThis discussion comes up every time only because some people seem to think OS development is like racking new x86 servers running RHEL. Many of the machines do not have LOM. They have hardware failures instead. They hang because they get trashed building OpenBSD and ports pretty much 24/7. There is debugging and serial cables going on. Someone needs to push that NMI button and check the LEDs flicker like they should. Reboot them. Constantly update to the latest development version, making them panic quite a bit. Diagnose that. Installation procedure requires console access, monitor adapters, weird keyboards, ... They don't fit in racks properly. There are security concerns. Etc, etc. It's wrong to think of the machine room as rack space than can be had for cheap somewhere else. It's much more like a lab (with the mad professor living on top, controlling the experiment).
- myrandomcomment 13y agoWhile what you say is correct, Theo's stance on this is still a bit unreasonable. A review should be done to see which systems can be moved or supported by the means of remote power off strips and IP console servers. They should be perfectly willing to move that gear if someone offers them the space. All the Sun SPARC, Alpha and Intel most likely falls into this category. Only systems that someone needs to be physically there to access should be left onsite. I have donated to OpenBSD a number of times because I believe the project is of great value. In all cases where I used a release (for firewalls mostly) I purchased a CD set.
- Istof 13y agomaybe he doesn't want anyone else to have physical access (for security.