Tux Machines

Do you waddle the waddle?

Other Sites

Tor Project blog

New Release: Tails 7.8

Follow our installation instructions:

9to5Linux

AlmaLinux to Unveil Media & Entertainment Edition at AlmaLinux Day on July 18th

AlmaLinux Day will take place on Saturday, July 18th, 2026, from 10:00 AM to 5:00 PM at the E-Central DTLA Hotel in downtown Los Angeles, covering hot topics like cloud rendering economics, GPU pipelines, Linux infrastructure, and the use of open-source within the professional visual effects, animation, and post-production industries.

openSUSE Releases Agama 21 Installer with Better Network Management

Highlights of Agama 21 include the ability to reuse existing LVM volume groups and logical volumes, support the systemd-boot bootloader to adhere to the UAPI Boot Loader Specification, and the ability to detect if you’re installing openSUSE Tumbleweed, openSUSE Slowroll, or openSUSE Leap 16.1 without a desktop environment.

Nitrux 6.1 Is Now Available for Download, Powered by Linux Kernel 7.0

Powered by the latest and greatest Linux 7.0 kernel series, patched against the Copy Fail, Dirty Frag, Fragnesia, and ssh-keysign-pwn vulnerabilities, and featuring CachyOS patches, Nitrux 6.1 ships with Hyprland 0.55.1 featuring Lua-based configuration, the Vicinae Raycast-inspired focused launcher, and updates to Waybar, Hyprlock, and Wlogout.

Tails 7.8 Anonymous Linux OS Patches Recent Kernel Flaws, Removes Thunderbird

Coming almost a month after Tails 7.7, the Tails 7.8 release is a small update but an important one, as it ships with an updated Debian kernel patched against recent security vulnerabilities that could allow an application in Tails to gain administrative privileges, such as Copy Fail, Dirty Frag, or Fragnesia.

Firefox 152 Enters Public Beta Testing with Many Changes and Improvements

Firefox 152 continues to modernize the Firefox settings by adding icons in front of each subcategory, renaming the Home section to “Home and startup”, and moving the Sync section under the General section.

HP Linux Imaging and Printing (HPLIP) 3.26.4 Drivers Add Support for New Printers

HPLIP 3.26.4 adds support for new printers, including HP LaserJet Pro MFP 3106sdw and HP LaserJet Pro MFP 3105sdw, HP Envy 6500e series and HP Envy 6500 series, as well as HP OfficeJet Pro 9730, HP OfficeJet Pro 9730e, HP OfficeJet Pro 9720, HP OfficeJet Pro 9720e, HP OfficeJet Pro 8130e All-in-One, and HP OfficeJet Pro 8130 All-in-One series.

Red Hat Enterprise Linux 10.2 Released with Optional Command-Line AI Assistant

Highlights of Red Hat Enterprise Linux 10.2 include an optional command-line AI assistant called goose that can be installed from the extensions repository for faster and more responsive access to insights and commands, color output support to the RHEL command-line assistant, and customer-controlled security in image mode.

HP Is the Latest to Sponsor the Linux Vendor Firmware Service (LVFS)

This comes as great news after Dell and Lenovo announced earlier this month their support for the Linux Vendor Firmware Service (LVFS), which provides a portal for device firmware updating on Linux-based operating system via the fwupd software.

Internet Society

On Global Accessibility Awareness Day, An Internet for Everyone Must Include Everyone

Today, 21 May, marks the 15th Global Accessibility Awareness Day (GAAD)—a day dedicated to getting everyone talking, thinking, and learning about digital access and inclusion for people with disabilities.

LinuxGizmos.com

MeshToad V3 turns Linux systems into Meshtastic nodes

The NULLHOP MeshToad V3 is a Meshtastic-compatible LoRa radio module for Linux systems that allows computers to operate as Meshtastic nodes using meshtasticd. The device connects over USB and supports platforms ranging from Raspberry Pi boards to mini PCs and other Linux hosts.

ODROID-H5 is a low-power x86 SBC with 10GbE and four M.2 slots

Hardkernel has introduced the ODROID-H5, a new x86 single-board computer based on Intel’s Core i3-N300 processor. The board updates the ODROID H-series with onboard 10GbE networking, four M.2 expansion slots, DDR5 memory support, and a revised HSIO configuration intended for storage, networking, and accelerator expansion.

news

Security and blobs, by Alex Oliva (GNU Linux-Libre)

posted by Roy Schestowitz on Feb 23, 2026,
updated Feb 23, 2026

Alexandre Oliva

Reprinted with permission from Alex Oliva.

Linux-libre turned 18 recently, and I'm told there are still some people who try to pass as security experts who disapprove of the refusal to load binary blobs that claim to fix security problems.

I kind of understand the appeal of security bug fixes, but delivering them in the form of binary blobs mean that the one who accepts them has to trust them blindly and to give up any pretense of security from the vendor, and that seems to be a problem that many pretense security conscious minds seem to disregard, for whatever reason.

At the same time they advise people to not open messages from untrusted senders, and to not install random programs even when they claim to offer security improvements. They even criticize people who fall in such traps, while pushing others to do just that!

Sure, in one case it's possibly an evil anonymous attacker, while in the other it's a well-known active corporation in the enshittocene, thus also evil. Thanks, but no, thanks, I'll take neither.

What these people don't seem to want to understand is that there is a significant risk in granting the vendor (just like to anyone else) a new round of control over your computer, especially over a component that can access pretty much everything you do. The risk is not only for your freedom, but also for your security.

When there is a known, exploitable vulnerability in your computer, plugging that hole with a blob may seem like a lesser risk than leaving it unpatched, even if the blob brings with it unknowns (other security holes), risks (new backdoors, new forms of remote control), limitations (new license restrictions, "improvements" that stop you from doing things on your computer that the vendor doesn't want you to do any more), and known downsides (slowing down your computer).

If they allowed you to inspect the changes, to choose which ones you want and which ones you don't, to make further improvements yourself, to plug holes independently from them, then the conclusion could be very different.

But they don't, because they don't respect your freedom. This means they don't want you to have defenses against their control.

They might even care about your security against others, but clearly not about your security against themselves.

If you have already mitigated the risks from the known holes that the blob purports to plug, then the only effects of the blob on you are negative: exposing you to unknowns, to risks, to limitations, and to its known downsides.

It's a net negative, even security wise.

I suppose the miscreants can't picture someone who mitigates the potential security problems brought about by CPU bugs by not allowing random programs from random third parties to be installed and run on their computers, not even through web browsers, and by only installing programs known to serve their users and from trusted sources. Some of us even audit changes ourselves!

For them, it's probably easier to tick a box and then go about recklessly running nonfree (because they run under control of the remote server) programs on their browsers, or installing and running other pieces of software remotely controlled by third parties, whose behaviors they wish to contain somehow.

But for someone who cares about freedom to the point of meticulously selecting hardware that will run with only free software, allowing such nonfree web blobs to run is undesirable to begin with. Installing nonfree programs that don't permit auditing is also out of the question.

These choices are for freedom purposes, but they are also a form of security in depth that miscreants seem unable to conceive of. That these freedom defenses also mitigate security issues is a welcome bonus.

That misguided security and freedom miscreants egg their own faces by promoting security-risking and freedom-denying blobs, because they can't see that newer blobs bring newer problems, is just priceless.

So blong,


Copyright 2007-2026 Alexandre Oliva

Permission is granted to make and distribute verbatim copies of this entire document worldwide without royalty, provided the copyright notice, the document's official URL, and this permission notice are preserved.

The following licensing terms also apply to all documents and postings in this blog that don't contain a copyright notice of their own, or that contain a notice equivalent to the one above, and whose copyright can be reasonably assumed to be held by Alexandre Oliva.

This work is licensed under the Creative Commons License BY-SA (Attribution ShareAlike) 3.0 Unported. To see a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/ or send a letter to Creative Commons, 444 Castro Street, Suite 900, Mountain View, California, 94041, USA.

Other Recent Tux Machines' Posts

Anbernic RG DS gets a brand new Linux OS, and you don't need to uninstall Android
Anbernic has released a Linux-based OS for its RG DS dual-screen handheld which ships with Android
Red Hat Enterprise Linux 10.2 Released with Optional Command-Line AI Assistant
Red Hat Enterprise Linux 10.2 operating system is now available with optional command-line AI assistant, image mode enhancements, as well as updated components. Here’s what’s new!
The new Flipper One is a pocket-sized Linux computer
The hardware’s not finalized, but the more powerful Flipper One won’t be a replacement for the Flipper Zero
Canonical Launches Ubuntu Core 26 with Live Kernel Patching, Optimized Updates
Ubuntu Core 26 is now available for download as a major update to this fully containerized variant of Ubuntu 26.04 LTS for IoT, edge, and embedded devices. Here’s what’s new!
Mageia 10 RC1
You may have noticed that Mageia 10 RC1 was released a few days ago
Fedora Pulls the Plug on Deepin Over Security and Maintenance Failures
After months of no responses and packages being left in disrepair
Android Leftovers
Google’s Android Upgrade—Why You Need A New Phone In 2026
Today in Techrights
Some of the latest articles
 
Today in Techrights
Some of the latest articles
AlmaLinux to Unveil Media & Entertainment Edition at AlmaLinux Day on July 18th
The AlmaLinux OS Foundation will be hosting AlmaLinux Day on July 18th, 2026, at the E-Central DTLA Hotel in downtown Los Angeles, unveiling a new AlmaLinux edition for creatives.
GNU/Linux Leftovers
GNU/Linux news
Kernel Space: Bugs and New Features
Linux leftovers
Linux-centric Devices and Open Hardware
hardware leftovers
Free, Libre, and Open Source Software Leftovers
New WordPress release and more
Scanner in Browser and Firefox Development Reports
WWW stuff
Programming Leftovers
Development news
Windows TCO/Back Doors and Microsoft GitHub Breach
GitHub is toast
Security Leftovers
Security patches and more
today's howtos
Instructionals/Technical leftovers
KDE and Qt: Kirigami and More
KDE leftovers
Games: Paralives, Proton 11 Beta 5, and Much More
gaming news
Android Leftovers
Android 16 VPN bug turns apps installed on your phone into a leaky sink
Linux power users have been doing this for years—Windows just caught up
So it is for the new Grab and Move feature on Windows, which is a favorite of power users of Linux
Free and Open Source Software
This is free and open source software
Tux Machines Subjected to Cyberattacks [original]
In the past I spoke to the cybercrime unit of British Police. Maybe it's time to do so again.
openSUSE Releases Agama 21 Installer with Better Network Management
openSUSE releases Agama 21 installer for Tumbleweed and Slowroll with systemd-boot support, better network management, as well as numerous new features and improvements. Here’s what’s new!
In the Red Hat Official Site About 80% of Blog Posts Are Selling Slop, Not Linux
really terrible!
Free and Open Source Software, howtos and Installations
The WO4 ships with 16GB of DDR4-3200 memory and a 512GB PCIe 3.0 SSD
Solara – Arch-based rolling release Linux distribution
Solara is an Arch-based rolling release Linux distribution that focuses on offering a polished desktop experience out of the box
Android Leftovers
These settings fix 90% of Android Auto's problems
Free and Open Source Software, and Benchmark
This is free and open source software
Debian-based TileOS 2.0 arrives with multiple changes
TileOS 2.0 also sports multiple package updates and substitutions
I tested KDE Plasma 6.7 beta, and it's easily my new Linux desktop of choice
I took a look at how KDE Plasma 6.7 is coming along
B1ackOS Linux is a Debian-based operating system
B1ackOS GNU/Linux is a Debian-based operating system designed to provide a simple, privacy-conscious Linux environment with an emphasis on security-related tools
CookieOS – Debian-based Linux distribution
CookieOS is a Debian-based distribution with a playful cookie-themed presentation
Nitrux 6.1 Is Now Available for Download, Powered by Linux Kernel 7.0
Nitrux 6.1 immutable, systemd-free GNU/Linux distribution is now available for download with Linux kernel 7.0, Hyprland 0.55.1, Maui Apps 4.0.3, Calamares 3.4.2 installer, and more.
Explaining Who and What We Are (for Our 22nd Anniversary) [original]
We've already received some feedback from the community and improved it accordingly
Open Source ONLYOFFICE Docs 9.4 Brings Dark Spreadsheets, Smarter Forms, and a Licensing Cleanup
ONLYOFFICE has been putting out fairly consistent updates to its open source office suite
LWN: Coverage From The 2026 Linux Storage, Filesystem, Memory Management, and BPF Summit
some recent talks
Friction in Fedora over [Slop] developer desktop initiative
a last-minute change to vote against the proposal by council member Justin Wheeler has (at least temporarily) sent it back to the drawing board
Tackling Abusive Traffic [original]
We are closely monitoring the situation and doing our best to mitigate
Tails 7.8 Anonymous Linux OS Patches Recent Kernel Flaws, Removes Thunderbird
Tails 7.8 anonymous Linux distribution is now available for download with an updated kernel patched against recent security vulnerabilities, Tor Browser 15.0.14, and other changes.
Summer Comes Early [original]
We're still in May
Free, Libre, and Open Source Software, Openwashing, and Standards
mostly FOSS leftovers
Web Browsers, Dead Web, and Making Sites Better
Web related picks
today's leftovers
GNU/Linux and BSD mostly
Audiocasts/Shows: What’s in the SOSS?, LINUX Unplugged, Raspberry Pi on BBC, and More
a few more shows
Latest From Red Hat's redhat.com (After Red Hat Summit 2026)
3 more today
Linux Devices and Open Hardware: 8-bit Web Server, RISC-V, Raspberry Pi, and More
hardware picks
PSQL Database: pgBackRest Update, Barman 3.18.0, and plpgsql_wrap v1.0
postgres news
Mozilla is Subverting Firefox Into Slop-Pushing Plagiarism-Excusing 'App', Tor Browser 15.0.14 and Firefox 151.0 in the News
Firefox gone weird
Kernel Space Bugs: Still a Lot of Coverage About Local Privilege Escalation
some exaggerate it
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
He then pointed kernelistas to the project’s documentation
today's howtos
Instructionals/Technical leftovers
Security Leftovers and Windows/Microsoft TCO
bugs, breaches, Windows/Microsoft TCO
Games: Godot, DRM and More
gaming picks
Forza Horizon 6 is out, Valve update Proton Hotfix for Linux
bugs reported
Programming Leftovers
Ruby 4.0.5 and more
Anti-Lag 2 in Linux
Graphics improvements
Firefox 152 Enters Public Beta Testing with Many Changes and Improvements
Firefox 152 open-source web browser is now available for public beta testing with new “Send to Mobile” options, HDR support on Windows, improved settings, and new features for web developers.
HP Linux Imaging and Printing (HPLIP) 3.26.4 Drivers Add Support for New Printers
HP Linux Imaging and Printing (HPLIP) 3.26.4 drivers are now available for download with support for new HP printers.
OpenBSD 7.9 released
OpenBSD 7.9 RELEASED - Theo de Raadt
HP Is the Latest to Sponsor the Linux Vendor Firmware Service (LVFS)
Linux Vendor Firmware Service creator Richard Hughes announced that HP has also agreed to become a premier sponsor for the LVFS.
888 [original]
Linux is secure
Pigeon: A Love Story - A catcalling game
The menus were a bit laggy, but otherwise worked well on Linux
Microsoft should be terrified of SteamOS, even if Windows owns the Steam charts
Over the past few years, Valve has quietly managed to make Linux gaming feel legitimate
Linux Vs. Windows: Which Is Better For Your PC?
Meanwhile, Linux is seeing an increase in users as Microsoft continues to bungle Windows
Free and Open Source Software
This is free and open source software
Zenclora – Debian-based desktop Linux distribution
Zenclora is a Debian-based desktop Linux distribution designed for stability, daily use, gaming, and productivity
Planet KDE: Smoke tests for fun and profit
Smoking is bad for you. Testing software is good for you though
Kubuntu vs. Fedora KDE: Which KDE Plasma distro is right for you?
These two Linux distributions take different approaches to the desktop
The Glass Half Full [original]
we've noticed a large increase in volume of news about "Linux"
Today in Techrights
Some of the latest articles