Re: alternatives to m0n0
Chris Buechler <[email protected]> Fri, 27 Feb 2015 01:58:03 -0600
| Newsgroups | gmane.comp.security.firewalls.m0n0wall |
|---|---|
| Message-ID | <CAOmxWMWEvj810eo7oN-BVzVBpTriT5w96d-h57JSQv2cU6UH+g@mail.gmail.com> |
Greetings folks, A little late adding in here, but I wanted to have a private exchange with Manuel first, and get our road map for pfSense up before replying. I tried to keep this as short as possible, but it turned into a novel and there isn't anything I can easily snip out without omitting important parts of the story. All of you who have been around here a while know me. For those who haven=E2=80=99t, other than Manuel himself, none have dedicated as much of their time to advancing m0n0wall as I have. I have by far the highest all-time post count to the list here, I wrote the bulk of what=E2=80=99s on doc.m0n0.ch. We host that site on the pfSense infrastructure to this day and have since its inception in 2005. I had a source commit bit and did some development, though not much in that area. While my involvement is largely 8-12 years ago, most of m0n0wall is also largely 8-12 years ago. Manuel and I had a good working relationship at the time, and I thought a good relationship to this day. Private conversation after the announcement indicated that this is still true. I was pretty floored by the announcement recommending OPNsense. There is one decedent project that has stood the test of time, while continually increasing the level development over that time: pfSense. I feel like I got stabbed in the back by the project I put so much time into recommending a shady offshoot that has yet to put out a truly stable release, has existed for only a few weeks, is unlikely to be sustained, and whose entire marketing campaign is FUD and lies against the project from which they forked. I=E2=80=99m giving Manuel the benefit of the doubt assuming he was fed the lies OPNsense is using as marketing points, and that it was difficult to track down any background (though he didn=E2=80=99t ask.) Part of his private response to= me was =E2=80=9Chating the politics=E2=80=9D, and boy do I agree there. I=E2= =80=99d much rather be spending time doing productive things than having to defend myself and my company against completely false accusations. So why the recommendation of OPNsense? I didn=E2=80=99t get a clear answer, but I suspect it=E2=80=99s money. Deciso/Applianceshop.eu were advertising= on m0n0.ch, and I suspect they basically acquired m0n0wall by paying Manuel (they=E2=80=99re going to be taking over the m0n0.ch domain, we offe= red to keep it up as is indefinitely and were declined). This is fine, and I hope they paid Manuel adequately for his efforts and the domain. But if this is the case, it should have been stated as such: =E2=80=9Cm0n0wall = has been acquired by OPNsense=E2=80=9D, or something along those lines, rather than regurgitating their marketing FUD. One old timer I met here on this list and in the #m0n0wall IRC channel back in 2003 got in touch with me when the announcement came out and called it =E2=80=9Ccomplete bullshit=E2=80=9D that pfSense didn=E2=80=99t even get a mention, given my = involvement in m0n0wall. Manuel said he=E2=80=99d put out a post at the end of this month that pfSen= se and OPNsense are both viable alternatives. I hope we=E2=80=99ll see that, a= s I think I=E2=80=99ve earned that much. If you don=E2=80=99t care for the background and details, I=E2=80=99ll TLDR= it as this: OPNsense is extraordinarily shady, proceed with caution. There=E2=80=99s a good deal of background here that=E2=80=99s necessary to = understand how we=E2=80=99ve gotten to this point. In 2004, Scott Ullrich and I forked m0n0wall and started pfSense, to focus on machines where resources weren=E2=80=99t so limited. At the time, people wanted to keep m0n0wall fitting on an 8 MB CF card, when nearly all systems had significantly more resources than that, and the limit of expandability prevented a wide range of functionality that people wanted to see. Where you have significantly different goals, forks are a good thing. Eventually, as with any successful open source project of this nature, demand for commercial support and development services grew. We started BSD Perimeter in 2006 as the company behind the project, and started offering support and development services shortly after. It eventually grew to the point where I could take the leap of leaving my day job and doing this full time. A commitment from Netgate, one of our recommended hardware vendors at the time, meant I at least had the majority of my mortgage payment was covered each month. I just crossed my fingers and hoped for the best on the remainder. Making a living off open source isn=E2=80=99t easy. Things have been pretty tight financially since for me personally, as we=E2=80=99ve always been investing back into open source development. In 2012, Scott had moved on to other interests and I couldn=E2=80=99t find = a way to move things forward to the level we=E2=80=99re at today, much less t= he level we expect to be at in the near future. I explored a variety of options for moving forward. Ultimately, I went with Jim and Jamie Thompson of Netgate, who acquired Scott=E2=80=99s share of BSD Perimeter. T= hey had always done right by us, they were always good to work with, and our discussions leading up to that showed we had the same vision for moving things forward. I moved to Austin, Texas in the process. We shut down that Kentucky company and transferred assets over to the Texas company Electric Sheep Fencing. In 2012, Netgate had 3 full time people, BSDP had 3 full time people plus a variety of contractors that added up to somewhere around 2 full time equivalent depending on the month. Today we hired employee number 23 between the two companies combined. We=E2=80=99ve been able to grow revenue considerably via gold subscriptions, support, and sales of hardware and merchandise on store.pfsense.org. And that=E2=80=99s allowed us to significantly grow our investment in developing open source code, both in pfSense itself, and its underlying components. One of the things Jim undertook post-acquisition is cleaning up various legal matters, which out of my own ignorance in that area weren=E2=80=99t necessarily handled properly. Proper handling of trademarks= is one such area. Having a Contributor License Agreement (CLA) is another, as this ensures the proper open source legal standing of the project as a whole. Every project needs a CLA to ensure its open source legal standing. Pretty much every major project has one. Ours is comparable to any of them, and less stringent than many, in that the contributors retain their copyright where some such as the Free Software Foundation require copyright assignment. When you=E2=80=99re cleaning up a legal mess, you=E2=80=99re not going to m= ake many friends, and that=E2=80=99s the situation Jim ended up in. We approached th= e trademark fixes with our partner vendors as best we could, with Jim first getting in touch personally and listing the problems with their usage of the mark, and how they can address those problems. Those who didn=E2=80=99t address the problems on their site within several weeks got = a letter from our law firm. Deciso, the company behind OPNsense, was one of our partner hardware vendors at the time. They=E2=80=99re the *only one* that refused to make th= e changes on their website. This was nothing more than appropriately using the mark on their site, we weren=E2=80=99t trying to get them to stop selling pfSense at all, weren=E2=80=99t trying to extort more money out of them, nothing more than wording changes. We tried to work with them for months to get these changes made, and after their refusal to do so for several months, we removed them from our recommended hardware vendors list until they fixed the issues with the usage of our trademarks. Their response to that was to threaten to challenge our EU trademark registration (pending at the time, now issued), as if they had some right to our brand. We *still* tried to work things out with them even after being threatened, as all along we wanted to continue to build a mutually-beneficial relationship. They refused. The other part of OPNsense is Franco, who works for VC-funded company Packetwerk whose product was originally based on pfSense, and is probably moving to OPNsense. Franco submitted some huge pull requests to pfSense at a time we were trying to get a release out and didn=E2=80=99t immediately have the time to review and merge. A number of pull requests piled up for a bit. When we later got around to catching up on that backlog, we required a signed CLA to accept patches. Franco refused to accept the CLA, though it=E2=80=99s ultimately equal to or less restrictive than the CLAs those who contribute to Apache Software Foundation projects, Ubuntu, anything under the Free Software Foundation, the list could go on and on and on. Part of the trademark clean-up at hand was addressing the risk of =E2=80=9Cnaked licensing=E2=80=9D, which is how Google almost lost the trad= emark on Chromium. That entailed removing the pfsense-tools repo from Github, and making it a requirement to execute a license agreement to obtain access. The code is still under an open source license, and immediately available to anyone who completes the license agreement. Specifics are here: https://forum.pfsense.org/index.php?topic=3D76132.msg415051#msg415051 But in a nutshell, you just have to agree you won=E2=80=99t build a product called =E2=80=9CpfSense=E2=80=9D (which is nothing more than agreeing you w= on=E2=80=99t violate trademark law), and if you use the code in something else, you must attribute the source of the code (which is the BSD license). That=E2=80=99s really it - agree you=E2=80=99ll abide by the BSD license an= d won=E2=80=99t violate our trademarks, and you have access to the tools repo immediately. We tried to continue to work with Franco and Deciso. They both refused. I don=E2=80=99t care in the least about forks. A number of others have fork= ed before, and more will do so in the future. It=E2=80=99s the nature of open source. But when the marketing plan for your fork is to blatantly lie about the project you forked and try to scare people into moving, I have a serious problem. The people behind OPNsense imply we=E2=80=99re not =E2=80=9Copen=E2=80=9D though *all* our code is available under an open sou= rce license. They=E2=80=99ve put out =E2=80=9Ccreative fiction=E2=80=9D (lies) = such as this: https://twitter.com/Commander1024/status/570875239405649920 We=E2=80=99ve literally not spent even a single second discussing going clo= sed source internally - it=E2=80=99s NEVER been up for discussion. I=E2=80=99ve= most certainly never talked to any mystery =E2=80=9Chardware vendor=E2=80=9D abo= ut going closed source, and I=E2=80=99ve not spent a second of time discussing the s= ame plan with my business partners. Who favorited that tweet? @opnsense. Obviously Deciso is the hardware vendor making that up out of thin air. Then there=E2=80=99s this thread, where if I get the gist of it from Google Translate, they=E2=80=99re claiming our road map doesn=E2=80=99t help them = because they can=E2=80=99t use the code, trying to perpetuate the lie that our lice= nse isn=E2=80=99t open source. https://forum.opnsense.org/index.php?topic=3D89.0 So they can fork our code and include that, which is under the exact same license as these future developments will be. But now our future code, under the *exact same license* as what they forked, can=E2=80=99t be? Obviously, he=E2=80=99s lying. Then Franco=E2=80=99s making claims that our code can=E2=80=99t be contribu= ted into FreeBSD, including trying to poison FreeBSD developers against us. Bullshit. OPNsense has never done anything for FreeBSD that I=E2=80=99ve se= en. We=E2=80=99ve contributed financially and in code for many years, and are contributing more every year than in any previous year. Here is a quote from Jim to the FreeBSD devs who Franco was attempting to turn against us: ---- =E2=80=9CWe don=E2=80=99t force *anyone* to buy Gold, and we direct anyone = who wants to =E2=80=9Cdonate=E2=80=9D to pfSense to, instead, donate to the FreeBSD F= oundation. We support several BSD-focused conferences. We sponsored MeetBSD (and have for many years). Last year with cash and a give-away https://blog.pfsense.org/wp-content/uploads/2014/01/image-e1391215504995.jp= eg We sponsored a Cyber Defense Competition Team last year. They won their nationals. https://hackucf.org/blog/pfsense-at-hackucf/ https://blog.pfsense.org/?p=3D1287 In addition to sponsoring BSDCan, for many years now: https://www.bsdcan.org/2015/sponsors.php (Netgate) https://www.bsdcan.org/2014/sponsors.php (Netgate) https://www.bsdcan.org/2013/sponsors.php (Netgate) https://www.bsdcan.org/2012/sponsors.php (BSD Perimeter) We made two custom-etched APUs for the Foundation to give-away at BSDcan last year. Note that neither of these had any pfSense or Netgate markings on them. Pictures here: https://plus.google.com/+BsdcanOrg/posts/LzzCwfKbqUH We are the largest advertiser in FreeBSD Journal (and have been from the start). I actually called for doubling the ad rates and giving the magazine away at MeetBSD. We=E2=80=99ve donated to the FreeBSD Foundation every year for many years n= ow. And Renato already pointed out the co-development we did with the Foundatio= n. We have a ports committer and a src commuter on-staff. Renato and I, and another person here (Matt Smith) are on the start of the path toward getting a src commit bit (George is our mentor). Intel is supporting our efforts to bring QuickAssist Crypto to FreeBSD (yes, in the FreeBSD tree). Something linux got last Summer. So we advertise in FreeBSD Journal, sponsor conferences, sponsor the Foundation, sponsor technical work, do technical work ourselves and offer it back, ask people to donate to the Foundation instead of us, and employ committers.=E2=80=9D ----- end quote from Jim. I don=E2=80=99t think any of the people involved in OPNsense can even name the first thing they=E2=80=99ve ever done for FreeBS= D, but for sure any list they could assemble would be far shorter. Yet Franco is out telling FreeBSD developers that we=E2=80=99re hostile to FreeBSD. That=E2=80=99s since been cleared up with those developers, and we= =E2=80=99ve gotten apologies from those who originally believed him and were perpetuating his lies, but Franco doubtless continues his campaign of hate and deception. On Mon, Feb 16, 2015 at 11:01 AM, Thomas Sprinzing <[email protected]> w= rote: > > - pfsense forums: i was shocked by the attitude and the tone of some of t= he core wizards on > the forum. Outside of threads where we're having to FUD bust and respond to people who were spewing garbage, I disagree that there is an attitude and tone problem. Some of our regulars can certainly be abrasive. Doktornotor on the forum comes to mind. He=E2=80=99s helpful, but sometimes that help comes with snark or abrasiveness. Frankly, no community of any type on the Internet is free from such things. But largely, we have a great, friendly, helpful community. If you come in attacking us, the gloves might come off. > - pfsense business vs. community: truly versus. see before. Pfsense seem= s to be stuck in a > rut there, the opnsense fork was already on the horizo= n > last summer. There is a huge gap between some people's impression there, and the reality of the matter. That=E2=80=99s pretty well covered above. We=E2=80= =99ve done nothing that=E2=80=99s anti-community. Nothing is any different than it=E2= =80=99s ever been for the community, and in fact things are better than ever since our growing business is leading more open source development. > - Let me make an uneducated guess: the need for developer hangouts will b= e limited with > this audience. Thus, pfsense gold support contracts will most probably no= t skyrocket now. > That=E2=80=99s fine, we don=E2=80=99t force anyone to buy anything. We enco= urage people to support our work, but if you don=E2=80=99t have a need to buy anything from us, the software is freely available for all - knock yourself out. > - those of you catering for businesses: Maybe it=E2=80=99s the best reaso= n to talk to your customers. > Talk about business continuity and such=E2= =80=A6. I=E2=80=99d say for the > moment, you won=E2=80=99t do wrong going pfsense > This is the correct answer if you want something that=E2=80=99s proven to b= e sustainable. Sustaining a project along these lines over the long term is hard. You can=E2=80=99t trust a project in the honeymoon period of their fork to be sustained for any length of time. Especially one that=E2=80=99s undertaking the tactics OPNsense has thus far. On Mon, Feb 16, 2015 at 11:20 AM, Lee Sharp <[email protected]> wrote: > > I used to play a bit with pfSense, and recommend it in some cases, but... > Chris partnered with a new guy, and the new guy is the cause of all of th= e > woes you have mentioned. See above re: cleaning up legal issues not being a recipe for making friend= s. > He is combative, and unprofessional, Jim=E2=80=99s caught flak from the licensing changes, but that=E2=80=99s re= ally not true at all. Quoting him in an email to Manuel: =E2=80=9CAnd yes, things we= nt too far in the debacle about the licensing, but I had a job to do.=E2=80=9D > and is constantly looking to maximize revenue at the expense of everythin= g else. This is a frequent accusation, but give me one thing that was done to =E2=80=9Cmaximize revenue at the expense of everything else=E2=80=9D. There= were plenty of people with tin foil hats on who insisted this was some huge shift and that things would change. We wasted inordinate amounts of time fighting FUD after that. A year later, I thought that was all past us. Among our community, it is. Those who were active contributors at that point and had objections and/or concerns about the changes have since come to recognize that *nothing has changed*. > I had worked with Chris a few times over the years, so when his partner > blasted me on LinkedIn, I tried to contact Chris privately to find out wh= at > was going on. I heard nothing, so I suspect he is contractually enjoyed > from saying anything. I contacted Lee off-list to find out what I dropped the ball on here. I=E2=80=99m not under any sort of contractual obligation to not say anythin= g. Until more recently I got an absurd amount of email and things could fall through the cracks. As we=E2=80=99ve grown the business side, we=E2=80= =99ve been able to offload a lot of what I was doing so that=E2=80=99s not an issue anymore. It just so happened that Lee=E2=80=99s email came in a matter of hours before a family emergency that kept me tied up for much of a couple weeks, with everything that wasn=E2=80=99t an immediate customer nee= d getting pushed aside. His email ended up archived along with others I gave up on catching up on. > This means that I can not trust Chris (who I still > consider a very good guy) Thank you for the benefit of the doubt. > to keep pfSense trustworthy. So pfSense is off > the table. I hope you=E2=80=99ll reconsider that, from our discussion off-list, and th= e above points. On Mon, Feb 16, 2015 at 11:33 AM, Bao Ha <[email protected]> wrote: > > Jim roughed me up too early last year! I still like Chris and he was very > helpful before Jim arrived. Thanks, Bao. I don=E2=80=99t think Jim roughed you up too badly. :) You wer= e willing to make the changes Deciso wasn=E2=80=99t, and are still on our ven= dor list. On Wed, Feb 18, 2015 at 11:06 AM, <[email protected]> wrote: > > Funny that you should bring this up... When Heartbleed came out, pfSense > needed a new build. When Shellshocked came out, pfSense and nas4free bot= h > needed new builds. m0n0wall did not. Lean systems have less attack > vectors. m0n0wall only didn't need an update for Heartbleed because its openssl was so outdated it predated the introduction of the Heartbleed bug. In that case, being really outdated was a benefit. The openssl in m0n0wall is vulnerable to a wide range of other, less significant vulnerabilities though. pfSense does not include bash in the base system and did *not* require an update for Shellshock. We did update a couple add-on packages that included bash as a dependency, but the vast majority of systems don=E2=80=99t use said packages. The PHP 4.x in m0n0wall has a slew of vulnerabilities. Updating it to a current PHP version is a massive undertaking because of the number of things that have been deprecated from PHP 4.x to the 5.5x/5.6x currently-supported versions. I=E2=80=99ll jump into the discussion over at SmallWall when I get some tim= e, to add some advice on moving forward. > While I dislike the idea > that it has become harder to build pfSense yourself, I understand that > were reasons for that step. As I saw it, some of the guys behind the > pfSense project perceived a legal threat against them and they had to > take actions. Correct, detailed above. It=E2=80=99s actually easier now to build than it = was before. Sure, you have to take 5 minutes to create an account and accept the license agreement, but we=E2=80=99ve done so much clean up in th= e build tools recently that make things significantly easier to deal with, faster, and more reliable. The entire build tools is getting rewritten for v3.0 to address the remaining issues. Here is our upcoming road map. https://blog.pfsense.org/?p=3D1588 We welcome everyone to join us at pfSense. Hopefully the drama stops now, and we can get back to doing productive work. I wish Manuel the best in his new endeavor, and hope to see some of you who haven't moved over already around pfSense. Best, Chris