DuckDB 1.4 adds on-disk encryption (AES-GCM-256/CTR-256) with key derivation, WAL and temporary-file encryption, and near-zero OpenSSL-backed performance impact, but it is not yet aligned with NIST standards.
A data-rich, strongly critical dossier arguing FreeBSD's default security posture is poorly designed and slow to improve, citing long backports, root-running update/build workflows, insecure defaults across OpenSSH, packaging, and SSL, with concrete mitigation recommendations (LibreSSL, non-root builds, swap encryption, tightened sysctl/loader.conf) and governance/transparency concerns.
Kernel vulnerability reports have exploded (2–3 per week years ago to 5–10 per day now), driving more maintainers and prompting a likely shift away from embargoed disclosures toward continuous security maintenance.
AI purportedly found 12 OpenSSL vulnerabilities; source is a Hacker News comment link with no technical details.
Subscribe for real-time topic updates and unlimited access to our intelligence platform.