Follow

I should probably mention some notable changes, including a few goodies on the side:

  1. The new kernel heap zeroing feature can be enabled by setting hardening.kmalloc_zero to 1.
  2. The TTY pushback vulnerability is mitigated by default.
  3. New , , , and .
  4. Remote syscall over ptrace boundary is prohibited by default.
  5. Latest improvements in core.
  6. Latest improvements in and HardenedBSD 13-STABLE.

Default username and password: root and hbsdfw

Please remember that we do not have a solid in-place upgrade path, so upgrading to new builds requires the following process:

  1. Backup your existing config
  2. Reinstall with the new build
  3. Restore config from backup

· · Web · 1 · 0 · 2

@lattera

Can confirm! Highly recommend OPNsense users this upgrade, to harden their firewall. Should be the most secure device in the network - as a bouncer to keep the baddies out.

Sign in to participate in the conversation
BSD Network

bsd.network is a *BSD-adjacent Mastodon Instance. We have a code of conduct.