Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

Proton 11.0-2 Brings Support for AsteroidsHD, Portal Worlds, and Plain Sight

Proton 11.0-2 adds support for new games, including AsteroidsHD, Portal Worlds, Plain Sight, Warhammer: Dark Omen (Classic), Heroes of the Three Kingdoms 7, Tetrageddon Games, SMILE GAME BUILDER, Konkan Coast Pirate Solutions, and Otherworld Legends (战魂铭人).

NetworkManager 1.58.1 Improves Support for Private Connections and Fixes Bugs

NetworkManager 1.58.1 improves support for private connections, the ones that specify a user in the “connection.permissions” property, to use “ca-cert” or “system-ca-certs” rather than using the 802.1X “ca-path” and “phase2-ca-path” properties, which are no longer accepted.

LinuxGizmos.com

ESP32-S3 handhelds with 3.97-inch e-paper and optional LoRa/NFC

M5Stack’s new PaperMono and PaperMono-Lite are compact ESP32-S3-based e-paper development platforms built around a 3.97-inch grayscale touchscreen. Both models include Wi-Fi, microSD storage, an IMU, real-time clock, frontlight, microphone, buzzer, and an integrated 1150mAh battery, while the higher-end PaperMono adds LoRa and NFC connectivity.

K230 handheld couples AMOLED display with LoRa and keyboard

LILYGO has updated its T-Display K230 handheld, packaging its Kendryte K230-based development platform into a compact enclosure with a physical keyboard. The device combines dual-core 64-bit RISC-V processing with a 4.1-inch AMOLED touchscreen, LoRa, Wi-Fi, Ethernet, camera support, HDMI output, and an nRF52840 companion microcontroller.

EPIC SBC packs Ryzen AI X100 with dual 2.5GbE and triple M.2

IEI has detailed the NANO-X100, a compact EPIC single-board computer based on AMD’s Ryzen AI Embedded X100 Series. The 115 × 165mm board integrates 64GB of LPDDR5X memory, dual 2.5GbE networking, three M.2 expansion slots, four USB 3.2 ports, HDMI and DisplayPort outputs, and multiple serial interfaces for embedded and industrial applications.

news

Security and blobs, by Alex Oliva (GNU Linux-Libre)

posted by Roy Schestowitz on Feb 23, 2026,
updated Feb 23, 2026

Alexandre Oliva

Reprinted with permission from Alex Oliva.

Linux-libre turned 18 recently, and I'm told there are still some people who try to pass as security experts who disapprove of the refusal to load binary blobs that claim to fix security problems.

I kind of understand the appeal of security bug fixes, but delivering them in the form of binary blobs mean that the one who accepts them has to trust them blindly and to give up any pretense of security from the vendor, and that seems to be a problem that many pretense security conscious minds seem to disregard, for whatever reason.

At the same time they advise people to not open messages from untrusted senders, and to not install random programs even when they claim to offer security improvements. They even criticize people who fall in such traps, while pushing others to do just that!

Sure, in one case it's possibly an evil anonymous attacker, while in the other it's a well-known active corporation in the enshittocene, thus also evil. Thanks, but no, thanks, I'll take neither.

What these people don't seem to want to understand is that there is a significant risk in granting the vendor (just like to anyone else) a new round of control over your computer, especially over a component that can access pretty much everything you do. The risk is not only for your freedom, but also for your security.

When there is a known, exploitable vulnerability in your computer, plugging that hole with a blob may seem like a lesser risk than leaving it unpatched, even if the blob brings with it unknowns (other security holes), risks (new backdoors, new forms of remote control), limitations (new license restrictions, "improvements" that stop you from doing things on your computer that the vendor doesn't want you to do any more), and known downsides (slowing down your computer).

If they allowed you to inspect the changes, to choose which ones you want and which ones you don't, to make further improvements yourself, to plug holes independently from them, then the conclusion could be very different.

But they don't, because they don't respect your freedom. This means they don't want you to have defenses against their control.

They might even care about your security against others, but clearly not about your security against themselves.

If you have already mitigated the risks from the known holes that the blob purports to plug, then the only effects of the blob on you are negative: exposing you to unknowns, to risks, to limitations, and to its known downsides.

It's a net negative, even security wise.

I suppose the miscreants can't picture someone who mitigates the potential security problems brought about by CPU bugs by not allowing random programs from random third parties to be installed and run on their computers, not even through web browsers, and by only installing programs known to serve their users and from trusted sources. Some of us even audit changes ourselves!

For them, it's probably easier to tick a box and then go about recklessly running nonfree (because they run under control of the remote server) programs on their browsers, or installing and running other pieces of software remotely controlled by third parties, whose behaviors they wish to contain somehow.

But for someone who cares about freedom to the point of meticulously selecting hardware that will run with only free software, allowing such nonfree web blobs to run is undesirable to begin with. Installing nonfree programs that don't permit auditing is also out of the question.

These choices are for freedom purposes, but they are also a form of security in depth that miscreants seem unable to conceive of. That these freedom defenses also mitigate security issues is a welcome bonus.

That misguided security and freedom miscreants egg their own faces by promoting security-risking and freedom-denying blobs, because they can't see that newer blobs bring newer problems, is just priceless.

So blong,


Copyright 2007-2026 Alexandre Oliva

Permission is granted to make and distribute verbatim copies of this entire document worldwide without royalty, provided the copyright notice, the document's official URL, and this permission notice are preserved.

The following licensing terms also apply to all documents and postings in this blog that don't contain a copyright notice of their own, or that contain a notice equivalent to the one above, and whose copyright can be reasonably assumed to be held by Alexandre Oliva.

This work is licensed under the Creative Commons License BY-SA (Attribution ShareAlike) 3.0 Unported. To see a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/ or send a letter to Creative Commons, 444 Castro Street, Suite 900, Mountain View, California, 94041, USA.

Other Recent Tux Machines' Posts

After Europe ditched Windows, China follows suit with its own home-grown Linux distros
As the world wakes up to its reliance on US tech, some countries are doing their best to move away from it
KDE Gear 26.08 Software Suite Is Out with Many Improvements for KDE Apps
KDE Gear 26.08 open-source software suite is now available with improvements to many of your favorite KDE applications. Here’s what’s new!
 
Clownflare Numbers: GNU/Linux Reaching 13% in China This Weekend [original]
There was significant increase lately
today's leftovers
Linux and more
Distributions and Operating Systems: TRON/ITRON, Six Distros, and Bazzite
3 news picks
Web Browsers/Web Servers Leftovers
Web and Net news
Standards and Flukes
Standards related stories
Dan Langille and FreeBSD Foundation on FreeBSD
FreeBSD leftovers
OpenSUSE Planet News Roundup and Tumbleweed's Review of the Week
OpenSUSE news
Programming Leftovers
Development related picks
Fedora and Red Hat Leftovers
mostly from Red Hat's official site
Open Hardware/Modding: ESP32, GrapheneOS, and More
gadgets, mobile, and more stories
Christian Hergert on GNOME After IBM Red Hat
3 parts in series
KDE: Tellico 4.2.2 Released and KDE Plasma-based KDE Linux
KDE leftovers
Security Leftovers and Microsoft Breaches/TCO
Security leftovers
Games: Soup Raiders, Proton 11.0-2, and More
gaming related leftovers
today's howtos
Instructionals/Technical posts
Proprietary: Zoho W, Proton VPN, and Microsoft's Plagiarism
misc. stories
Wine 11.16
The Wine development release 11.16 is now available.
Clownflare: At Certain Times of the Day (or Night) GNU/Linux Exceeds 1 in 10 Globally [original]
GNU/Linux is growing up fast
Free and Open Source Software
This is free and open source software
Clownflare: GNU/Linux Peaking at Around 10% in Canada [original]
Last night Clownflare measured GNU/Linux at 10% in Canada
MakowiecOS – Debian-based Linux distribution
MakowiecOS is a Debian-based Linux distribution designed with performance
One month with my new Murena GS6 Pro: finally a Murena phone that checks all my boxes
Recently I decided to change my Murena smartphone because its battery was really dying
KDE Linux experiences
I daily drove KDE Linux for almost a year and I liked it, but I'm also switching back to Fedora KDE
This Week in Plasma: UI and Performance Improvements
This week was heavy on improvements for both the user interface and also performance
Today in Techrights
Some of the latest articles
PrismLinux Reborn 1.0 Is Here
PrismLinux Reborn 1.0 introduces a native redesigned installer, smarter driver handling, improved Btrfs support, four focused desktop options, and broad system refinements
Introducing FydeOS v23
the release of FydeOS v23
Proton 11.0-2 Brings Support for AsteroidsHD, Portal Worlds, and Plain Sight
Proton 11.0-2 is now available with support for AsteroidsHD, Portal Worlds, Plain Sight, Warhammer: Dark Omen (Classic), Heroes of the Three Kingdoms 7, and many other Windows games.
Security Patches and Incidents
Security leftovers
Education, Sharing, and More
today's leftovers
Web Browsers/Web Servers: WebAudio, Automattic/WordCamp/WordPress Become Slopfest, Looking at "geolocation" in HTML
WWW related leftovers
GNU: GNUnet 0.29.0 is released, phone turned into emacs interface
GNU picks
PostgreSQL: LibreDB Studio introduced, poisoned Postgres connection pools
psql bits for today
IBM: Red Hat Selling Mindless Slop (as Usual), RPM 6.1.0 is Ready
Red Hat leftovers
Btrfs Snapshot Integration in KDE and GSoC Journey in KDE
a pair of KDE picks
"Chrome-Plated Turd" and "Google Chrome web browser for 64-bit Arm Linux and tested on Pi 5"
Chromium and more
Firefox Add-ons and Mozilla Still Goes on About Openwashing and LLM Slop (Pyramid Scheme, Hype)
Mozilla is meh
Programming Leftovers
Development and Python aplenty
Rust Gets Security Black Eye, Releases New Version
Rust sucks?
Raspberry Pi, Homebrew 68K Machine, and Android Devices
hardware and gizmos in the news
GNOME: Security, Extensions, and Liferea News Reader 2.0
GNOME leftovers
Trying Out Garuda Linux
Eventually settled on Garuda Linux
BSD: OpenZFS Mastery and NetBSD 11's Support for 64-bit RISC-V Hardware
BSD picks
SNES Games, Nostalgia, and New Titles for GNU/Linux
gaming picks
today's howtos
Instructionals/Technical posts
Audiocasts/Shows: Emacs, DNS, and BSDs
3 new episodes
Linux Kernel Space: Apple Foolishness and Change to Scheduler Boosts FPS for Low-Power Hardware
4 picks for today
Framework Laptop 12 gets Fedora KDE Linux on pre-builts, along with new Intel Core Series 3 processors
Nice to see an expansion of Linux on devices, with the Framework Laptop 12 getting support for pre-builts to ship with Fedora KDE 44 and Intel Core Series 3
PINE64 Calls Time on the Linux Hardware Market, Ceases Production Until the AI Bubble Bursts
Open hardware specialist PINE64 has announced that it is exiting the Linux single-board computer, phone...
Linux Kernel 7.2 Officially Released, This Is What’s New
Linux kernel 7.2 is now available for download with new features, enhanced hardware support through new and updated drivers, improvements to filesystems and networking, and much more.
NetworkManager 1.58.1 Improves Support for Private Connections and Fixes Bugs
NetworkManager 1.58.1 open-source network connection manager is now available for download with improved support for private connections and fixes various bugs.
Today in the United States GNU/Linux Measured at 15% on Desktops/Laptops [original]
Is this the "new normal"?
Android Leftovers
Android's new sideloading option is finally out - here's how it works
GIMP 3.4 Promises New Project File Format, PSD Support Improvements, and More
GIMP 3.4 open-source image editor is under development promising many new features and enhancements. Here’s what to expect!
Free and Open Source Software, Benchmark, and Review
This is free and open source software
Mainstream OS – Arch Linux-based distribution
It provides graphical tools for configuring monitors, themes, key bindings, networking, software and updates
In South Korea, GNU/Linux Grew From 3.5% to 5.1% in the Past 12 Months (According to Cloudflare) [original]
seeing that GNU/Linux is growing in South Korea is highly encouraging
Anniversaries [original]
No anniversary would be complete without some balloons and decoration
Today in Techrights
Some of the latest articles