HACKER Q&A
📣 iio7

I am seriously worried about security in FreeBSD


I have just finished reading through tons of security bug reports in the FreeBSD bug report archive, and also normal bugs, and I am "scared" about the lack of attention these issues get.

It's like no one "cares", or the few that does is simply overburden.

This proposal from 2018, with the problems it lists, still seems very valid: https://web.archive.org/web/20210401214138/https://lists.freebsd.org/pipermail/freebsd-arch/2018-March/018892.html

Are any of you - who runs FreeBSD in serious production (please home labs, desktop/laptop use, don't reply) - not worried about the current state of affairs?


  👤 Mo3 Accepted Answer ✓
Yes. I‘ve migrated over all of our servers to Debian recently.

I don’t believe in waiting until the general hivemind consensus catches up with reality and I like not having problems down the road..


👤 gtirloni
Could you give some examples of "no one cares"? Besides the URL to the 2018 proposal, you didn't give much to work with it.

👤 technobabbler
Hmm. Isn't there something to be said about running a less popular stack so the drive-by zero days won't affect you as much? Sure there are slower fixes, but also fewer people hunting for exploits. You're a less juicy target.