<?xml version="1.0" encoding="utf-8" ?><transcript><text start="0.64" dur="2.799">all right so this video is going to</text><text start="2" dur="3.759">address something that i&amp;#39;ve been asked</text><text start="3.439" dur="6.08">by a lot of people which is why i don&amp;#39;t</text><text start="5.759" dur="6.321">use openbsd or at least why i don&amp;#39;t use</text><text start="9.519" dur="5.12">openbsd on the desktop and make a bunch</text><text start="12.08" dur="4.08">of content related to that because i do</text><text start="14.639" dur="4.081">use it for servers this here is one i</text><text start="16.16" dur="4.72">message aged into that i&amp;#39;ve updated to</text><text start="18.72" dur="4.639">uh 7.1 recently</text><text start="20.88" dur="4.399">um i made a video like a year ago</text><text start="23.359" dur="4.08">talking about why i was looking to start</text><text start="25.279" dur="4.16">using openbsd</text><text start="27.439" dur="3.92">instead of or at least in conjunction</text><text start="29.439" dur="3.841">with linux servers</text><text start="31.359" dur="5.121">one of the strategies that i&amp;#39;ve pretty</text><text start="33.28" dur="6.799">much settled on is using openbsd on the</text><text start="36.48" dur="7.52">perimeter of a vpc like having it set up</text><text start="40.079" dur="6.16">as a reverse proxy firewall</text><text start="44" dur="4.239">and i think i did make a video</text><text start="46.239" dur="4.16">where i set up a desktop environment on</text><text start="48.239" dur="3.521">openbsd like in a virtual machine or</text><text start="50.399" dur="3.441">something like that</text><text start="51.76" dur="5.2">but you&amp;#39;ll probably never catch me</text><text start="53.84" dur="5.28">actually using openbsd as a daily driver</text><text start="56.96" dur="3.84">on a desktop or laptop</text><text start="59.12" dur="4.079">and it&amp;#39;s because i don&amp;#39;t really think</text><text start="60.8" dur="4.48">that open bsd is meant for that so</text><text start="63.199" dur="4.881">i&amp;#39;m on openbsd.org this is their</text><text start="65.28" dur="3.92">official website there&amp;#39;s the front page</text><text start="68.08" dur="3.28">and</text><text start="69.2" dur="5.04">for example the word desktop doesn&amp;#39;t</text><text start="71.36" dur="5.68">show up anywhere there&amp;#39;s no pictures of</text><text start="74.24" dur="4.72">somebody using an open bsd desktop on</text><text start="77.04" dur="4.399">the website there&amp;#39;s no pictures</text><text start="78.96" dur="4.72">of open bsd with a desktop environment</text><text start="81.439" dur="4.961">or with window managers there is a</text><text start="83.68" dur="5.28">picture of a rack mounted server</text><text start="86.4" dur="4.48">right here which i presume</text><text start="88.96" dur="3.519">is running open bsd</text><text start="90.88" dur="5.04">but still no</text><text start="92.479" dur="6.161">desktops no guise nothing like that now</text><text start="95.92" dur="3.6">compare that to something like linux</text><text start="98.64" dur="2.08">mint</text><text start="99.52" dur="3.12">which</text><text start="100.72" dur="4.24">yeah like if you didn&amp;#39;t know</text><text start="102.64" dur="5.119">anything about linux mint like if you</text><text start="104.96" dur="3.76">just randomly went to linux mint.com one</text><text start="107.759" dur="2.481">day</text><text start="108.72" dur="4.079">and you looked at this you&amp;#39;d be like oh</text><text start="110.24" dur="4.48">okay yeah this is for a desktop</text><text start="112.799" dur="3.441">operating system it&amp;#39;s very obvious or</text><text start="114.72" dur="4.56">even if you went to</text><text start="116.24" dur="6.159">uh what is it artixlinux.org right</text><text start="119.28" dur="5.92">so we go to iso releases</text><text start="122.399" dur="5.681">and look there&amp;#39;s releases that come with</text><text start="125.2" dur="4.96">a desktop environment already set up for</text><text start="128.08" dur="5.04">openbsd</text><text start="130.16" dur="6.079">we don&amp;#39;t have this option so even though</text><text start="133.12" dur="5.52">it is possible of course to set up a</text><text start="136.239" dur="4.241">desktop environment and use openbsd as a</text><text start="138.64" dur="3.36">desktop i mean i&amp;#39;ve done that at least</text><text start="140.48" dur="3.839">the first part setting up the desktop</text><text start="142" dur="4.879">environment um but</text><text start="144.319" dur="5.201">all of this lack of indications that</text><text start="146.879" dur="4.801">it&amp;#39;s a desktop os um</text><text start="149.52" dur="4.96">kind of clearly tells me that it&amp;#39;s not</text><text start="151.68" dur="4.88">and if you are someone who</text><text start="154.48" dur="3.36">is able to run open bsd on a desktop</text><text start="156.56" dur="3.039">successfully</text><text start="157.84" dur="2.479">then you&amp;#39;re a bit of a hacker and mind</text><text start="159.599" dur="2.72">you</text><text start="160.319" dur="4.161">a hacker is not necessarily someone who</text><text start="162.319" dur="4.161">just puts on a black hoodie and sells</text><text start="164.48" dur="4.399">ransomware on the dark net uh no i&amp;#39;m</text><text start="166.48" dur="5.2">talking about the og definition of a</text><text start="168.879" dur="4.801">hacker which is a skilled person in</text><text start="171.68" dur="4.8">information technology that uses their</text><text start="173.68" dur="5.52">skills to achieve a goal or overcome an</text><text start="176.48" dur="4.479">obstacle by non-standard means so</text><text start="179.2" dur="4.399">basically it&amp;#39;s someone who makes</text><text start="180.959" dur="5.28">technology do things that it wasn&amp;#39;t</text><text start="183.599" dur="5.041">necessarily meant to do like if you</text><text start="186.239" dur="4.961">install and play doom on a graphing</text><text start="188.64" dur="5.04">calculator you&amp;#39;re a hacker if you</text><text start="191.2" dur="4.56">install linux to a nintendo ds you&amp;#39;re a</text><text start="193.68" dur="4.479">hacker and if you install</text><text start="195.76" dur="5.199">open bsd to a desktop and use that as</text><text start="198.159" dur="5.281">your daily driver then in my opinion you</text><text start="200.959" dur="4.56">are a hacker because i just don&amp;#39;t think</text><text start="203.44" dur="4">that open bsd is really meant for that i</text><text start="205.519" dur="4.561">think it&amp;#39;s more meant for servers and</text><text start="207.44" dur="5.76">not the desktops and let me be clear i</text><text start="210.08" dur="5.68">don&amp;#39;t have anything against anybody who</text><text start="213.2" dur="4.56">wants to use open bsd on their desktop</text><text start="215.76" dur="4.72">or anywhere really</text><text start="217.76" dur="4.72">i really don&amp;#39;t get this infighting that</text><text start="220.48" dur="3.759">there seems to be between some linux and</text><text start="222.48" dur="3.6">bsd users like we really shouldn&amp;#39;t be</text><text start="224.239" dur="3.761">fighting a brother war we should be</text><text start="226.08" dur="4.4">getting together and shepherding people</text><text start="228" dur="3.519">away from using proprietary operating</text><text start="230.48" dur="3.039">systems</text><text start="231.519" dur="5.36">but something you should know about</text><text start="233.519" dur="4.8">openbsd if you&amp;#39;re considering using it</text><text start="236.879" dur="3.681">on a desktop</text><text start="238.319" dur="4.56">is that there&amp;#39;s limited support for</text><text start="240.56" dur="4.879">wi-fi i mean you know desktop people</text><text start="242.879" dur="4.72">think of a tower but on a laptop that</text><text start="245.439" dur="4.641">might be a big deal to you</text><text start="247.599" dur="4.401">um limited support for wi-fi there&amp;#39;s not</text><text start="250.08" dur="3.68">support for bluetooth there&amp;#39;s very</text><text start="252" dur="4.16">limited support for device drivers in</text><text start="253.76" dur="5.039">general like graphics cards peripherals</text><text start="256.16" dur="5.039">things like that you can&amp;#39;t install steam</text><text start="258.799" dur="5.281">and you can&amp;#39;t install a lot of other</text><text start="261.199" dur="5.601">software without using ports which</text><text start="264.08" dur="4.48">could compromise open bsd security which</text><text start="266.8" dur="4.48">is probably</text><text start="268.56" dur="4.88">the reason why you chose openbsd which</text><text start="271.28" dur="4.56">is considered one of the world&amp;#39;s most</text><text start="273.44" dur="6.24">secure operating systems in the first</text><text start="275.84" dur="6.639">place instead of freebsd which is</text><text start="279.68" dur="5.68">actually meant for desktops look at that</text><text start="282.479" dur="4.881">we see it right there on the front page</text><text start="285.36" dur="4.96">of their website so</text><text start="287.36" dur="4.559">if you can get openbsd working as a</text><text start="290.32" dur="3.04">desktop os the more power too i mean</text><text start="291.919" dur="3.521">like i said i consider you a hacker</text><text start="293.36" dur="3.119">which most people uh consider a huge</text><text start="295.44" dur="3.92">compliment</text><text start="296.479" dur="6.241">but don&amp;#39;t go hitting up the devs of open</text><text start="299.36" dur="5.839">bsd to try to include support for wi-fi</text><text start="302.72" dur="5.6">six or for bluetooth or</text><text start="305.199" dur="5.201">a lot of other desktop things in the</text><text start="308.32" dur="4.4">kernel i highly doubt that they&amp;#39;re ever</text><text start="310.4" dur="6">going to do that and if they did it</text><text start="312.72" dur="7.199">would actually piss off a lot of uh open</text><text start="316.4" dur="7.28">bsd users like myself because wi-fi and</text><text start="319.919" dur="6.161">bluetooth on a server is</text><text start="323.68" dur="4">this is the reason why i started</text><text start="326.08" dur="3.119">switching part of my server</text><text start="327.68" dur="4.4">infrastructure at least the internet</text><text start="329.199" dur="4.56">facing things over to open bsd in the</text><text start="332.08" dur="3.679">first place because</text><text start="333.759" dur="5.521">on linux servers well let me actually</text><text start="335.759" dur="6.561">just show you so this is a debian server</text><text start="339.28" dur="4.96">which i had i was going to use for email</text><text start="342.32" dur="5.52">but i guess this will be a quick rant</text><text start="344.24" dur="6.959">within a rant vaulter refuses to open</text><text start="347.84" dur="6.079">smtp port 25. so i gotta find a</text><text start="351.199" dur="4.881">different hosting provider for email um</text><text start="353.919" dur="4.081">i i do still think that vaulter is great</text><text start="356.08" dur="4.64">for everything else and i might just</text><text start="358" dur="4.479">throw uh my affiliate link in this uh</text><text start="360.72" dur="3.12">video as well so that if you sign up you</text><text start="362.479" dur="2.481">can get some credit to the account and</text><text start="363.84" dur="3.04">so will i</text><text start="364.96" dur="4.4">um that&amp;#39;s probably a big reason why i</text><text start="366.88" dur="4.24">like vaulter to be honest with you but</text><text start="369.36" dur="3.6">as far as the technical stuff goes</text><text start="371.12" dur="4.56">they&amp;#39;re pretty great it&amp;#39;s just i don&amp;#39;t</text><text start="372.96" dur="4.799">know for some reason within the past</text><text start="375.68" dur="4.72">year or so they&amp;#39;ve started refusing to</text><text start="377.759" dur="5.28">do the needful when it comes to using</text><text start="380.4" dur="4.72">email so if you want vaulter for email</text><text start="383.039" dur="4.321">then don&amp;#39;t use my affiliate link and</text><text start="385.12" dur="4.96">don&amp;#39;t use valtter use something else but</text><text start="387.36" dur="5.2">anyway let me show you my</text><text start="390.08" dur="6.559">kernel config</text><text start="392.56" dur="8.88">of this open bsd or excuse me of this uh</text><text start="396.639" dur="6.641">debian box and let me show you</text><text start="401.44" dur="4.479">bluetooth</text><text start="403.28" dur="4.32">okay so remember this is a server this</text><text start="405.919" dur="4.161">is a vps</text><text start="407.6" dur="3.92">and as you can see bluetooth</text><text start="410.08" dur="3.119">all the different configs related to</text><text start="411.52" dur="5.119">bluetooth are either</text><text start="413.199" dur="5.041">um built in to the kernel or they&amp;#39;re um</text><text start="416.639" dur="3.361">a module</text><text start="418.24" dur="2.799">uh same thing like if we keep scrolling</text><text start="420" dur="3.28">through here you&amp;#39;ll probably find a</text><text start="421.039" dur="3.841">bunch of other wireless things that we</text><text start="423.28" dur="4.639">just don&amp;#39;t need</text><text start="424.88" dur="4.48">um let&amp;#39;s see yeah so near field</text><text start="427.919" dur="3.28">communication right this is another</text><text start="429.36" dur="2.959">thing that&amp;#39;s just there&amp;#39;s no reason to</text><text start="431.199" dur="4">have this</text><text start="432.319" dur="5.121">on a server but yet it&amp;#39;s built in there</text><text start="435.199" dur="4.72">there&amp;#39;s tons of things in</text><text start="437.44" dur="5.039">this kernel that i just don&amp;#39;t need for a</text><text start="439.919" dur="3.68">server and if i was using debian on my</text><text start="442.479" dur="3.041">desktop</text><text start="443.599" dur="3.281">then i would have the same deal going on</text><text start="445.52" dur="2.88">i would have a bunch of server things in</text><text start="446.88" dur="4.319">the kernel that i wouldn&amp;#39;t need on a</text><text start="448.4" dur="5.199">desktop and debian is not the only</text><text start="451.199" dur="3.28">distro that does this okay ubuntu fedora</text><text start="453.599" dur="2.481">arch</text><text start="454.479" dur="4.16">most distros</text><text start="456.08" dur="3.6">ship with a really generic kernel</text><text start="458.639" dur="2.56">and</text><text start="459.68" dur="3.84">customizing the kernel i mean you can</text><text start="461.199" dur="4.161">customize a kernel on any distro but</text><text start="463.52" dur="3.76">generally it&amp;#39;s not</text><text start="465.36" dur="4">part of the process when you&amp;#39;re setting</text><text start="467.28" dur="3.52">up your distro</text><text start="469.36" dur="3.36">they all come with these really generic</text><text start="470.8" dur="3.679">kernels that do a lot of things that you</text><text start="472.72" dur="4.96">don&amp;#39;t need them to do</text><text start="474.479" dur="6">also most people using a linux box</text><text start="477.68" dur="5.359">whether it&amp;#39;s for a desktop or a server</text><text start="480.479" dur="4">they&amp;#39;re not using a hardened kernel</text><text start="483.039" dur="3.041">so in case you didn&amp;#39;t know about this</text><text start="484.479" dur="3.44">project there&amp;#39;s</text><text start="486.08" dur="4">another</text><text start="487.919" dur="4.641">kernel like another version of the linux</text><text start="490.08" dur="4.48">kernel called linux hardened which has</text><text start="492.56" dur="4.479">dozens of options</text><text start="494.56" dur="5.199">that we were just looking at changed</text><text start="497.039" dur="5.921">to reduce the attack surface so</text><text start="499.759" dur="5.921">really good stuff probably a great thing</text><text start="502.96" dur="5.44">to use to further enhance the security</text><text start="505.68" dur="5.519">of your vps or maybe even on your linux</text><text start="508.4" dur="4.639">desktop but almost nobody does this</text><text start="511.199" dur="4.32">almost everyone is just using the</text><text start="513.039" dur="4.321">generic version of the kernel that ships</text><text start="515.519" dur="4.08">with their operating system and maybe if</text><text start="517.36" dur="3.84">you use a distro i can&amp;#39;t even think of</text><text start="519.599" dur="2.401">any off the top of my head that ship</text><text start="521.2" dur="2.639">with</text><text start="522" dur="4.64">uh the hardened kernel by default but</text><text start="523.839" dur="4.241">maybe if you use a uh distro</text><text start="526.64" dur="4.8">you know the few people that are setting</text><text start="528.08" dur="4.879">up a vps with that kind of linux iso are</text><text start="531.44" dur="2.959">using the heart of kernel but most</text><text start="532.959" dur="2.88">people they&amp;#39;re probably using debian</text><text start="534.399" dur="2.481">they&amp;#39;re probably using red hat something</text><text start="535.839" dur="3.761">like that</text><text start="536.88" dur="5.2">and it&amp;#39;s just generic linux</text><text start="539.6" dur="4.56">and don&amp;#39;t get me wrong the kernel is</text><text start="542.08" dur="4.08">really not a huge</text><text start="544.16" dur="3.84">security concern i mean as long as it&amp;#39;s</text><text start="546.16" dur="4">updated okay don&amp;#39;t get me wrong if</text><text start="548" dur="4.399">you&amp;#39;re using like version four or three</text><text start="550.16" dur="3.76">or something crazy like that that should</text><text start="552.399" dur="4.321">be a concern to you but if you&amp;#39;re using</text><text start="553.92" dur="5.12">an up-to-date or an lts kernel</text><text start="556.72" dur="4.16">um i wouldn&amp;#39;t really</text><text start="559.04" dur="4.4">lose sleep over</text><text start="560.88" dur="4.959">having modules enabled that i don&amp;#39;t need</text><text start="563.44" dur="5.519">because it&amp;#39;s really unlikely that yours</text><text start="565.839" dur="4.401">or anyone else&amp;#39;s vps is going to get</text><text start="568.959" dur="3.681">hacked</text><text start="570.24" dur="4.96">that way from a vulnerability in a</text><text start="572.64" dur="4.24">kernel module attackers are going to go</text><text start="575.2" dur="5.04">after the lowest hanging fruit they&amp;#39;re</text><text start="576.88" dur="6.24">going to go for things like unsecure ssh</text><text start="580.24" dur="4.24">unsecured cpanels or like if you&amp;#39;re</text><text start="583.12" dur="3.04">running wordpress they&amp;#39;re going to go</text><text start="584.48" dur="4.32">after the people who have outdated</text><text start="586.16" dur="5.44">plugins or outdated versions of</text><text start="588.8" dur="4.8">wordpress django or whatever server</text><text start="591.6" dur="3.919">applications you&amp;#39;re using it doesn&amp;#39;t</text><text start="593.6" dur="4.4">change the fact though that the linux</text><text start="595.519" dur="5.521">kernel is very large and insecure</text><text start="598" dur="3.839">compared to open bsds and that&amp;#39;s why</text><text start="601.04" dur="2.88">if</text><text start="601.839" dur="4">i&amp;#39;m going to have an internet facing box</text><text start="603.92" dur="4">that people are going to be scanning</text><text start="605.839" dur="4.56">people are going to be trying to break</text><text start="607.92" dur="4.88">into and do all kinds of dirty things to</text><text start="610.399" dur="4.641">my poor little vps</text><text start="612.8" dur="4.4">i wanted to be running the most secure</text><text start="615.04" dur="5.2">operating system in the world and have</text><text start="617.2" dur="5.12">it do only what i want it to do</text><text start="620.24" dur="4.24">but my desktops</text><text start="622.32" dur="3.519">they&amp;#39;re not openly accessible from the</text><text start="624.48" dur="3.84">internet so</text><text start="625.839" dur="4.481">my main concerns with them is things</text><text start="628.32" dur="4.56">like the web browser or</text><text start="630.32" dur="5.759">potentially with email right like i</text><text start="632.88" dur="5.36">should not be clicking on links and and</text><text start="636.079" dur="3.041">uh you know nonsense that&amp;#39;s in my email</text><text start="638.24" dur="3.36">box</text><text start="639.12" dur="4.24">uh there&amp;#39;s some security overlap between</text><text start="641.6" dur="3.76">servers and desktops right like i still</text><text start="643.36" dur="4.96">use very strong passwords on both i</text><text start="645.36" dur="4.88">still use encryption on both but for the</text><text start="648.32" dur="5.519">most part my approach to securing</text><text start="650.24" dur="5.12">servers and desktops is pretty different</text><text start="653.839" dur="5.041">so don&amp;#39;t hold your breath waiting for me</text><text start="655.36" dur="6.24">to make open bsd desktop content but if</text><text start="658.88" dur="5.44">you do want to watch desktop bsd content</text><text start="661.6" dur="4.56">and maybe learn how to use openbsd</text><text start="664.32" dur="4">on the desktop for yourself</text><text start="666.16" dur="4.08">let me show you some content creators</text><text start="668.32" dur="6.16">that can help you out with that so</text><text start="670.24" dur="5.599">uh this is zany zhani um not exactly</text><text start="674.48" dur="4.56">sure how to pronounce his name but he</text><text start="675.839" dur="4.641">makes a lot of open bsd desktop content</text><text start="679.04" dur="3.52">like we search</text><text start="680.48" dur="3.919">for desktop look at all this he&amp;#39;s got a</text><text start="682.56" dur="3.279">new computer and a new rice which i</text><text start="684.399" dur="3.68">think you can also download so if you</text><text start="685.839" dur="3.68">want to just like copy his config which</text><text start="688.079" dur="3.76">actually does look pretty clean i</text><text start="689.519" dur="4.401">watched like a couple of his videos</text><text start="691.839" dur="3.68">um just to see and like you see he&amp;#39;s got</text><text start="693.92" dur="3.12">these long</text><text start="695.519" dur="3.041">maybe their live streams or maybe</text><text start="697.04" dur="2.479">they&amp;#39;re just recordings i don&amp;#39;t know but</text><text start="698.56" dur="3.92">he&amp;#39;s got</text><text start="699.519" dur="5.201">obviously tons of desktop</text><text start="702.48" dur="5.28">open bsd content</text><text start="704.72" dur="6.32">and then we&amp;#39;ve also got root bsd so same</text><text start="707.76" dur="5.519">thing and this person clearly went to</text><text start="711.04" dur="4.08">the mental outlaw academy of based</text><text start="713.279" dur="4.721">thumbnails because just look at this</text><text start="715.12" dur="4.719">he&amp;#39;s utilizing the apoos and the anime</text><text start="718" dur="4">girls expertly</text><text start="719.839" dur="4.24">this guy he you know he he might be able</text><text start="722" dur="4">to teach the class himself and he&amp;#39;s also</text><text start="724.079" dur="3.361">got an odyssey channel</text><text start="726" dur="3.2">so look at that we don&amp;#39;t even have to</text><text start="727.44" dur="4.399">watch him on cringe tube</text><text start="729.2" dur="5.199">we can watch him on base tube</text><text start="731.839" dur="4.8">see look at this so you don&amp;#39;t have to</text><text start="734.399" dur="4.801">show google that you&amp;#39;re learning how to</text><text start="736.639" dur="6.32">use open based on the desktop so go</text><text start="739.2" dur="5.52">forth and consume desktop open bsd</text><text start="742.959" dur="3.361">content from these guys they&amp;#39;re they&amp;#39;re</text><text start="744.72" dur="2.799">actually small channels so you know</text><text start="746.32" dur="4.4">definitely</text><text start="747.519" dur="5.281">uh go show them some love both zany</text><text start="750.72" dur="3.679">and root bsd</text><text start="752.8" dur="4.88">and um</text><text start="754.399" dur="5.68">like i said i&amp;#39;m using it on this on for</text><text start="757.68" dur="4.24">servers like kind of on the perimeter of</text><text start="760.079" dur="5.041">a vpc so</text><text start="761.92" dur="4.159">maybe i&amp;#39;ll do some tutorials for openbsd</text><text start="765.12" dur="2.719">once</text><text start="766.079" dur="4.32">i&amp;#39;ve got things set up how i like them</text><text start="767.839" dur="4.961">maybe i&amp;#39;ll show you guys how to</text><text start="770.399" dur="4.961">use it as like a reverse proxy or how to</text><text start="772.8" dur="5.52">use it as a vpn server</text><text start="775.36" dur="5.36">uh maybe i&amp;#39;ll do some pf tutorials but</text><text start="778.32" dur="4.639">it&amp;#39;s gonna be you know dry boring stuff</text><text start="780.72" dur="4.88">it&amp;#39;s not it&amp;#39;s not gonna be cool</text><text start="782.959" dur="5.12">uh desktop stuff or like gaming on open</text><text start="785.6" dur="4.56">bsd or anything like that</text><text start="788.079" dur="6.921">like and contact the algorithm subscribe</text><text start="790.16" dur="4.84">to me on odyssey have a great day</text></transcript>