Tux Machines

Do you waddle the waddle?

Other Sites

Tor Project blog

Paskoocheh: When you need a tool to reach the tool

Due to heavy information controls, people in Iran face significant barriers to accessing the Internet. Authorities have actively blocked numerous websites and apps, including conventional circumvention and digital security tools such as VPNs, social media platforms, and the app stores themselves. This creates a "chicken-and-egg" problem: users need a VPN to download a VPN.

LinuxGizmos.com

M5Stack LLM-8850 Kit delivers 24 TOPS AI acceleration in M.2 form factor

The LLM-8850 Kit is an M.2-based AI accelerator designed for edge AI, embedded inference, video analytics, and multimodal large-model workloads. It combines the LLM-8850 Card, a compact M.2 M-Key 2242 module based on the Axera AX8850 SoC, with a PiHat adapter board for the Raspberry Pi 5.

youyeetoo updates R1 SBC and lists K1 N100-based x86 computer

youyeetoo has updated its R1 single-board computer to version 3.0 and has also listed the K1, a palm-sized x86 edge computer based on Intel’s Alder Lake-N N100 processor. The two systems are aimed at compact AIoT, embedded, industrial, and edge computing applications, but use different processor platforms and expansion layouts.

AM62x PRU Academy goes live for BeaglePlay and PocketBeagle 2

Texas Instruments and BeagleBoard.org have announced that the AM62x and AM26x PRU Academy is now available, adding new learning material for developers working with BeaglePlay and PocketBeagle 2.

9to5Linux

KDE Frameworks 6.27 Is Out to Improve KRunner, Breeze Icons, and More

The KDE Frameworks 6.27 release is here to improve the display of disk sizes shown in various places across the Plasma desktop to fully respect your preference regarding storage units, and switching between light and dark Global Themes to prevent various Plasma UI elements from changing their colors halfway.

Audacity 3.7.8 Audio Editor Improves Support for HiDPI Displays on Linux

Coming six months after Audacity 3.7.7, which was a hotfix release addressing broken waveform scrolling and selection for some users introduced in Audacity 3.7.6, the Audacity 3.7.8 release promises to improve support for HiDPI displays on Linux/wxGTK and introduce Podcast 2.0 chapters JSON export for label tracks.

COSMIC 1.0.16 Desktop Adds OpenRC Support for Bluetooth Service Management

Coming only a week after COSMIC 1.0.15, the COSMIC 1.0.16 release updates the COSMIC Settings with OpenRC support for Bluetooth service management and passkey/pin display dialogs for Bluetooth keyboard pairing, as well as improved search.

Fwupd 2.1.5 Linux Firmware Updater Released with Support for Elan Touchscreens

Coming only two weeks after fwupd 2.1.4, the fwupd 2.1.5 release introduces support for updating the firmware on Elan touchscreens, adds support for installing the database updates on broken hardware with new firmware, and adds support for overriding the detected CPU vendor to allow more self-tests.

news

Security and blobs, by Alex Oliva (GNU Linux-Libre)

posted by Roy Schestowitz on Feb 23, 2026,
updated Feb 23, 2026

Alexandre Oliva

Reprinted with permission from Alex Oliva.

Linux-libre turned 18 recently, and I'm told there are still some people who try to pass as security experts who disapprove of the refusal to load binary blobs that claim to fix security problems.

I kind of understand the appeal of security bug fixes, but delivering them in the form of binary blobs mean that the one who accepts them has to trust them blindly and to give up any pretense of security from the vendor, and that seems to be a problem that many pretense security conscious minds seem to disregard, for whatever reason.

At the same time they advise people to not open messages from untrusted senders, and to not install random programs even when they claim to offer security improvements. They even criticize people who fall in such traps, while pushing others to do just that!

Sure, in one case it's possibly an evil anonymous attacker, while in the other it's a well-known active corporation in the enshittocene, thus also evil. Thanks, but no, thanks, I'll take neither.

What these people don't seem to want to understand is that there is a significant risk in granting the vendor (just like to anyone else) a new round of control over your computer, especially over a component that can access pretty much everything you do. The risk is not only for your freedom, but also for your security.

When there is a known, exploitable vulnerability in your computer, plugging that hole with a blob may seem like a lesser risk than leaving it unpatched, even if the blob brings with it unknowns (other security holes), risks (new backdoors, new forms of remote control), limitations (new license restrictions, "improvements" that stop you from doing things on your computer that the vendor doesn't want you to do any more), and known downsides (slowing down your computer).

If they allowed you to inspect the changes, to choose which ones you want and which ones you don't, to make further improvements yourself, to plug holes independently from them, then the conclusion could be very different.

But they don't, because they don't respect your freedom. This means they don't want you to have defenses against their control.

They might even care about your security against others, but clearly not about your security against themselves.

If you have already mitigated the risks from the known holes that the blob purports to plug, then the only effects of the blob on you are negative: exposing you to unknowns, to risks, to limitations, and to its known downsides.

It's a net negative, even security wise.

I suppose the miscreants can't picture someone who mitigates the potential security problems brought about by CPU bugs by not allowing random programs from random third parties to be installed and run on their computers, not even through web browsers, and by only installing programs known to serve their users and from trusted sources. Some of us even audit changes ourselves!

For them, it's probably easier to tick a box and then go about recklessly running nonfree (because they run under control of the remote server) programs on their browsers, or installing and running other pieces of software remotely controlled by third parties, whose behaviors they wish to contain somehow.

But for someone who cares about freedom to the point of meticulously selecting hardware that will run with only free software, allowing such nonfree web blobs to run is undesirable to begin with. Installing nonfree programs that don't permit auditing is also out of the question.

These choices are for freedom purposes, but they are also a form of security in depth that miscreants seem unable to conceive of. That these freedom defenses also mitigate security issues is a welcome bonus.

That misguided security and freedom miscreants egg their own faces by promoting security-risking and freedom-denying blobs, because they can't see that newer blobs bring newer problems, is just priceless.

So blong,


Copyright 2007-2026 Alexandre Oliva

Permission is granted to make and distribute verbatim copies of this entire document worldwide without royalty, provided the copyright notice, the document's official URL, and this permission notice are preserved.

The following licensing terms also apply to all documents and postings in this blog that don't contain a copyright notice of their own, or that contain a notice equivalent to the one above, and whose copyright can be reasonably assumed to be held by Alexandre Oliva.

This work is licensed under the Creative Commons License BY-SA (Attribution ShareAlike) 3.0 Unported. To see a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/ or send a letter to Creative Commons, 444 Castro Street, Suite 900, Mountain View, California, 94041, USA.

Other Recent Tux Machines' Posts

KDE Frameworks 6.27 Is Out to Improve KRunner, Breeze Icons, and More
KDE Frameworks 6.27 open-source software suite is out now with various improvements and bug fixes for KDE apps and the Plasma desktop environment. Here’s what’s new!
EasyOS gtk2-ng, FlatOrange, and EasyCast screen recorder
Some EasyOS updates
Gert Wollny Pushing LLM Slop Into Linux Kernel
one of many
CVE-2026-23111 Impacting nf_tables
Linux bug
Linux Lite 8.0 “Hematite” Launches with Linux Kernel 7.0, Ubuntu 26.04 LTS Base
Linux Lite 8.0 distribution is now available for download based on Ubuntu 26.04 LTS (Resolute Raccoon) and powered by the Linux 7.0 kernel series. Here’s what’s new!
 
Systemd-Free Peppermint OS Devuan Is Now Based on Devuan 6 Excalibur
Peppermint OS Devuan distribution has been updated today to Devuan 6 (Excalibur), based on the Debian 13 (Trixie) operating system series but without the systemd init system.
Games: Videogames, Proton-CachyOS, Proton Experimental, and More
gaming picks
Android Leftovers
Onyx BOOX Go 6 (Gen II) brings pen support to an Android-powered eReader
Today in Techrights
Some of the latest articles
Richard Stallman (RMS) Talk Tomorrow in Bern, Switzerland [original]
Tomorrow the founder of the FSF and the Free software community will give a public talk at SBB
Security Leftovers
Security picks
Free, Libre, and Open Source Software Leftovers
FOSS and more
Events/Education: Linux App Summit 2026 and SouthEast LinuxFest
2 new reports
Debian and Ubuntu: Development report and Transmission issues and workarounds on (K)Ubuntu 26.04
fixes and more
Desktop Environments, KDE, and GNOME
GNU/Linux interfaces
Collabora's CODE 26.04, ONLYOFFICE Slop, and LibreOffice Recap
LibreOffice and more
Web Browsers and Web Clients
Web Browsers and more
Programming Leftovers
Development related picks
Open Hardware: Raspberry Pi, RISC-V, Arduino, and More
Linux picks
Fedora, AlmaLinux, Red Hat, and More
IBM and RHEL
Audiocasts/Shows: Linux Matters, LINUX Unplugged, FLOSS Weekly, and More
new episodes
Linux Hardware and Graphics: Vivante GPUs ASUS ROG Maximus Z790 Extreme
2 news picks regarding rendering and more
5 package managers and 7 Linux wellness apps to take better care of myself in 2026
some software news
Mike Gabriel: Voxit 1.0; Future of libayatana-appindicator (v0.6.0 released today)
Work and released by him
Proton releases Proton Drive CLI, GNU/Linux Supported
2 links
today's howtos
Instructionals/Technical posts
Kernel: Reconsidering x32, Buildroot, FreeBSD
Linux and BSD
Asahi Linux Issues Warning About Apple
Asahi Linux 3 links
Android Leftovers
/e/OS 4.0 is here: Murena's Android fork makes it even easier to escape Google's clutches
NanoPi M6V2 RK3588S SBC gains support for dual analog microphone input
FriendlyELEC provides a long list of supported operating systems based on Linux 6.1
Free and Open Source Software
This is free and open source software
Audacity 3.7.8 Audio Editor Improves Support for HiDPI Displays on Linux
Audacity 3.7.8 open-source digital audio editor and recording software is now available for download with improves support for HiDPI displays on Linux, new options to choose where silence is truncated, and more.
Ubuntu MATE Will Quite Possibly Have 26.10 Release
Ubuntu MATE, the official Ubuntu flavor features MATE desktop environment
Android Leftovers
Your Pixel Watch’s next big Wear OS update is almost here
Alpine Linux is a crazy-fast distro for your desktop - with just one caveat
Alpine Linux isn't always considered for traditional desktop use
Open Hardware/Modding: Raspberry Pi, ESP32, and Lots More
Hardware leftovers
piBrick PocketCM5 – An open-source handheld Linux computer kit for Raspberry Pi CM5
Designed by Indonesian maker Ahmad Amarullah (amarullz), the piBrick PocketCM5 is an open-source hardware handheld Linux computer kit built around the Raspberry Pi CM5
Free and Open Source Software
This is free and open source software
Today in Techrights
Some of the latest articles
Games: Mouthwashing, Theropods, and More
Latest from GamingOnLinux
Red Hat on Robotics, Slop, and ANL4
latest from redhat.com
LWN coverage from the 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit
latest articles
GNU/Linux Leftovers
GNU/Linux picks
Free, Libre, and Open Source Software, Sovereignty, and Standards
FOSS and more
Trying Vivaldi, The Decline of Search Engines, and VPN From (or Via) Mozilla
WWW news
Firebird and PostgreSQL News
3 picks
Programming Leftovers
Development news
Android Leftovers
Honor Magic V6 Review: The Android foldable to beat in 2026
Recent Shows and Videos About GNU/Linux
via Invidious
Games: DELTARUNE, FINAL FANTASY RESONANCE, and More
9 articles from GamingOnLinux
Why I'm sticking with systemd-based Linux distros
Over 10 years since its introduction, systemd can still get some Linux users riled up
Juno Tab 4 is a Linux tablet with Intel Core i3-N300 and Core Ultra 5 115U options
Linux PC vendor Juno Computers sells laptops
Alpine Linux 3.24 Released with GNOME 50, KDE Plasma 6.6, and COSMIC Desktops
Alpine Linux 3.24 distribution is now available for download with GNOME 50, KDE Plasma 6.6, COSMIC desktop, and Linux kernel 6.18 LTS. Here’s what’s new!
IPFire 2.29 - Core Update 203 is available for testing
This is the release announcement for IPFire 2.29 – Core Update 203, which is now available for testing
HandBrake 1.11.2 Video Transcoder Adds WebM MIME Type Support on Linux
HandBrake 1.11.2 open-source video transcoder is now available for download with WebM MIME type support on Linux, improvements to Core Audio AAC encoder 7.1 channel layout, and bug fixes.
Free and Open Source Software
This is free and open source software
KaOS Releases First Dinit-Based ISO, but It's Not Ditching Systemd Entirely
The distro ditches systemd as the init system while keeping some key components around
My brief encounter with Google Pixel 8 Pro
Android 16 is annoying
AM62x PRU Academy goes live for BeaglePlay and PocketBeagle 2
Linux interrupt configuration works
COSMIC 1.0.16 Desktop Adds OpenRC Support for Bluetooth Service Management
COSMIC 1.0.16 desktop environment is now available with improvements across COSMIC Files, COSMIC Panel, COSMIC Settings, COSMIC Player, COSMIC Greeter, and COSMIC Launcher.
Fwupd 2.1.5 Linux Firmware Updater Released with Support for Elan Touchscreens
Fwupd 2.1.5 Linux firmware updater is now available for download with support for Elan touchscreens, support for installing the database updates on broken hardware with new firmware, as well as various other improvements.
Almost Half a Decade of Geminispace [original]
Geminispace was a side benefit of the transition we had planned for years
Up North [original]
On Friday RMS is giving a talk in Bern
I've used Linux for 30 years - 4 frustrations remain, including 2 that push me back to MacOS
For decades, I've recommended the open-source OS to new and experienced computer users alike
This overlooked Linux distro will give your laptop a new life
Ubuntu isn’t your only option for reviving old PCs through Linux
I turned my Linux terminal into a walkie-talkie that no one can track
But the idea of turning a Linux terminal into a push-to-talk voice and text messenger that works over the Tor network was just too interesting not to want to try to get it working
Today in Techrights
Some of the latest articles
Firefox Android Play Integrity check hits custom ROMs
Mozilla has added support for Google’s Play Integrity API
Free and Open Source Software
This is free and open source software
A Data Layer for GTK applications
In this iteration we have GomSession. It is your standard identity-map layer with transaction-scoping
Liquid Glass for Linux? PearOS makes another Mac move - how it looks now
I've been keeping an eye on PearOS for some time. I covered PearOS before