bk99.de entertain the web since 1997

Blog 2025

32 posts

Projects, Linux, networks, systems, finds and internet standards from 2025.

Honest Bad Guy: My system prompt against people-pleasing AI

At the end of 2025 I gave my AI assistants a fixed system prompt because their constant agreement without real criticism annoyed me. It demands checking instead of guessing, contradiction instead of sugarcoating and no claimed tests that never happened. Here it is in full to copy, together with the reasons behind the rules and the places where it gets in its own way.

Read the full post

Continuous batching explained from scratch

The article builds a scheduler that adds new requests to running batches between individual decoding steps. This keeps accelerators better utilised despite answers of different lengths. Continuous batching schedules requests at token level instead of per fully completed batch.

Read the full post

Google Chrome: critical security hole in web browser

In August 2025 Google closed a critical hole in Chrome (CVE-2025-9478), a use-after-free bug in the WebGL backend ANGLE. Attackers could exploit the memory bug via prepared websites, which usually leads to the execution of malicious code. The hole was fixed in Chrome 139.0.7258.154/155; Chromium-based browsers such as Edge are likely to be affected as well.

Read the full post

Developing production-ready CUDA kernels

The guide leads from a simple CUDA kernel to tests, benchmarks, variants and automated delivery. It treats kernel work as a software product rather than a one-off speed hack. The workflow covers implementation, tests, benchmarks and publication.

Read the full post

iX workshop: securing Linux servers effectively and comprehensively

In 2025 heise advertised a five-day iX workshop on hardening Linux servers with trainer Florian Winkler of B1 Systems. Topics were encryption, securing network services, two-factor authentication, SELinux and AppArmor, as well as log analysis and intrusion detection. There was also an introduction to penetration testing and practical exercises via SSH in a training environment.

Read the full post

Content-defined blocks for Parquet

The article adapts content-defined chunking to the internal structure of Parquet files. Similar table versions can therefore share blocks, even though file offsets have changed. Parquet organises data in column chunks and row groups.

Read the full post

Reusing GPU kernels via the Hub

The Kernel Hub distributes optimised GPU operators as versionable artefacts and loads suitable variants at runtime. This allows specialised kernels to be used without building them into every package. HF Kernels provides pre-built and custom GPU kernels via the Hub.

Read the full post

OpenSSH: the new stuff

leyrer presents newer OpenSSH features beyond keys, jump hosts and port forwarding and assesses their benefit for current Linux systems. A familiar standard tool deserves regular reassessment instead of a configuration that never changes. Security gains often come from consistently using new features that are already there.

Read the full post

17,000 Linux servers vulnerable to critical rsync hole

In January 2025 six holes in rsync became known, including the critical CVE-2024-12084, which in combination allows servers with only anonymous read access to be taken over. According to Shadowserver, 17,475 freely reachable rsync servers worldwide were vulnerable on 16 January, with Germany in fifth place with 956. All versions up to 3.3.0 were affected; the fixes came in 3.4.0 and 3.4.1.

Read the full post

Skylo offers SMS on smartphones even without a mobile network

At CES 2025 Skylo Technologies put its satellite network for SMS on normal smartphones into international operation. Unlike Apple’s emergency service via Globalstar, Skylo relies on 3GPP standards (Release 17) and uses spectrum from satellite operators such as Viasat and EchoStar instead of its own satellites. In November 2024, together with Telekom and Qualcomm, Skylo had transmitted an SMS via a geostationary satellite into the network of the Telekom subsidiary Cosmote.

Read the full post

Partly critical router holes endanger industrial networks

In January 2025 the industrial network equipment supplier Moxa warned of two holes in routers and security appliances used, among other places, in energy facilities. CVE-2024-9138 is based on hard-coded credentials and gives authenticated attackers root privileges; the critical CVE-2024-9140 allows system commands to be injected. Firmware updates were available for several model series, while for others there were only workarounds or a referral to support.

Read the full post