bk99.de entertain the web since 1997

Blog 2026

41 posts

Projects, Linux, networks, systems, finds and internet standards from 2026.

Mail from the ISS: SSTV images with a Raspberry Pi and a magnetic-base antenna

From 2 to 6 October 2026, the International Space Station is transmitting twelve images via SSTV on 437.550 MHz as part of ARISS Series 33. I received them in Meerane with a Raspberry Pi, an RTL-SDR stick, a simple magnetic-base antenna and OpenWebRX+, and on the first usable pass two images came through cleanly. The deciding factor was not the antenna, but a small script that tracks the frequency during the pass and saves the images itself.

Read the full post

What I learned from 2.9 billion tokens

In September I made AI speak locally, got a 35-billion-parameter model running on a single graphics card and, according to OpenAI, used 2.9 billion tokens in the cloud. A present for a friend still did not get finished. This post shows where the waiting time of a voice AI really comes from, why an HTTP 200 can lie and what a token counter reveals about AI agents.

Read the full post

120,314 emails from 26 years: My mailbox moves into its own archive

In September 2026 I merged Outlook, Thunderbird, Evolution and Cyrus mail from 26 years into a local mail archive running Stalwart and Roundcube. In the end there were 120,314 searchable emails, including more than 11,000 that had long been considered deleted. This post shows why Message-IDs do not detect duplicates, what Thunderbird really does when you delete something and how an archive can stay safe without any cloud.

Read the full post

The security coprocessor in many CPUs is insecure

In August 2026 two holes became known in the Trusted Computing Group’s reference code for firmware TPMs (fTPM 2.0), which AMD and Intel adopt in their BIOS versions. CVE-2026-6727 is a timing side channel in RSA-OAEP; CVE-2026-6726 allows discarded keys to be replaced by false ones. They can only be exploited with local, privileged access and are mainly relevant for company devices.

Read the full post

iX workshop: hardening Linux servers with encryption and access control

In 2026 heise again advertised the five-day iX workshop “Hardening Linux servers” with Florian Winkler of B1 Systems, this time with dates in September and November. Topics range from physical security through encryption, two-factor authentication and SELinux/AppArmor to logging, monitoring and intrusion detection. The target group is Linux administrators and security officers who want to secure their servers systematically.

Read the full post

Why humanity may never leave the solar system

KG takes stock of the distances, energy, radiation, dust collisions and communication limits that make interstellar travel difficult even for advanced civilisations. The universe can be full of life, even though physical barriers almost prevent direct contact. A reachable home world gains value when escaping to other stars remains unrealistic.

Read the full post

Security incident at Hugging Face in July 2026

Hugging Face describes a break-in in which an autonomous agent combined a prepared data source with insecure execution paths. Internal data sets and credentials were reached; according to what was known at the time, public Hub artefacts were not manipulated. The attack combined a malicious data set with remote code execution and template injection.

Read the full post

Moving GitHub CI to Hugging Face Jobs

The guide moves compute-intensive CI steps from GitHub Actions to Hugging Face Jobs. GitHub remains the trigger and status interface, while specialised hardware runs externally. Hugging Face Jobs can run GPU and CPU tasks from GitHub workflows.

Read the full post

Asynchrony in continuous batching

The article extends continuous batching with asynchronous preparation and output so that CPU work blocks the GPU scheduler less. Overlapping pipeline phases increase utilisation with many simultaneous requests. Tokenisation, scheduling and output can be overlapped with GPU computation.

Read the full post

Why open AI matters for cybersecurity

The article argues that open models give defenders tools they can inspect and adapt. At the same time, it acknowledges that the same capabilities are available to attackers. Open weights allow local analysis without handing sensitive data to an API provider.

Read the full post

Mutable storage buckets in the Hub

Storage buckets add S3-like object storage for checkpoints, logs and intermediate states to the version-oriented repositories. The data remains accessible via browser, script and command line. Buckets are S3-like and are backed by the Xet storage layer.

Read the full post

RFC 9849: TLS Encrypted ClientHello

RFC 9849 encrypts most of the TLS ClientHello and thereby protects destination and negotiation data that used to be visible. Content encryption alone does not hide all metadata of a connection. More privacy changes troubleshooting and network filtering.

Read the full post

GGML and llama.cpp join Hugging Face

GGML and llama.cpp become part of Hugging Face to develop local inference and open model formats further in the long term. The collaboration ties the Hub more closely to CPU and edge execution. GGML forms the technical basis of many quantised local models.

Read the full post

Broadcom hole lets attackers knock out entire Wi-Fi networks

In January 2026 researchers from Black Duck found a hole in Broadcom Wi-Fi chipsets through which an attacker within radio range can knock out a 5 GHz network with a single packet, without logging in and regardless of WPA2 or WPA3. All clients lose their connection until the router is restarted, and the attack can be repeated immediately. Testing was done on an Asus RT-BE86U; Broadcom had already patched, but how far manufacturers had passed this on remained unclear.

Read the full post

Wi-Fi 7 routers disappoint so far

In 2026 the magazine Rtings found none among 25 tested Wi-Fi 7 routers that implemented the standard satisfactorily. Multi-Link Operation (MLO) in particular was neglected: no model used true simultaneous MLO, and only one supported EMLSR as a fallback. In addition, manufacturers cause confusion with names such as “Wifi” without a hyphen, which are not subject to the Wi-Fi Alliance’s certification.

Read the full post

Ongoing attacks endanger 10,000 firewalls

At the end of 2025 Fortinet warned of ongoing attacks on a FortiOS hole patched since July 2020 (CVE-2020-12812), which according to Shadowserver was still exploitable on around 10,000 firewalls. Attackers use it to bypass two-factor login via FortiToken by changing the upper and lower case of the user name. Local users authenticated via LDAP and assigned to a group are affected.

Read the full post