From 2 to 6 October 2026, the International Space Station is transmitting twelve images via SSTV on 437.550 MHz as part of ARISS Series 33. I received them in Meerane with a Raspberry Pi, an RTL-SDR stick, a simple magnetic-base antenna and OpenWebRX+, and on the first usable pass two images came through cleanly. The deciding factor was not the antenna, but a small script that tracks the frequency during the pass and saves the images itself.
In September I made AI speak locally, got a 35-billion-parameter model running on a single graphics card and, according to OpenAI, used 2.9 billion tokens in the cloud. A present for a friend still did not get finished. This post shows where the waiting time of a voice AI really comes from, why an HTTP 200 can lie and what a token counter reveals about AI agents.
Christian Stankowic and CodeSalat show how MeshCore and Meshtastic enable independent text networks and custom mesh bots with inexpensive LoRa hardware. Both projects build decentralised text networks on LoRa radio technology. Under suitable conditions, messages can cover many kilometres across several nodes.
Maya Posch tries out an old Intel Atom PC as an open router and shows how driver choice, installation and reliable measurements decide success. The Intel D2500CC board uses an Atom processor with two 1.8 GHz cores and initially two gigabytes of DDR3. OpenWrt’s generic x86 image did contain e1000, but not the required kmod-e1000e package.
While building my mail archive, I found a folder with 6,594 emails that servers I was responsible for sent me between 2004 and 2025. Logwatch reports, cron output and warnings show how my server operations changed over twenty years. This post shows what this robot mail reveals, when it became a burden and how I would approach monitoring by email today.
In September 2026 I merged Outlook, Thunderbird, Evolution and Cyrus mail from 26 years into a local mail archive running Stalwart and Roundcube. In the end there were 120,314 searchable emails, including more than 11,000 that had long been considered deleted. This post shows why Message-IDs do not detect duplicates, what Thunderbird really does when you delete something and how an archive can stay safe without any cloud.
Andrew Gabbitas describes how Let’s Encrypt wants to enable post-quantum authentication with Merkle Tree Certificates without slowing down TLS connections with large individual signatures. An ML-DSA-44 signature is about 2,420 bytes. A current ECDSA P-256 signature, by contrast, needs 64 bytes.
Johannes Findeisen criticises systemd as a complex, tightly coupled Linux suite and contrasts it with OpenRC, runit and s6 as more modular alternatives. The version examined was last updated on 25 July 2026. systemd uses units and cgroups for service and resource management.
The Wikipedia article explains Occam’s razor as an economical rule of research that removes unnecessary assumptions without confusing simplicity with truth. Occam’s razor is a heuristic principle in the philosophy of science. It is not considered a criterion of truth in its own right.
hAudio 0.03 is a permanently running audio system for the Raspberry Pi: it mixes the signals of two computers onto one wireless headset and routes the headset microphone independently to PC 1, PC 2, both or neither.
Hackaday presents Multikernel Linux, in which a host kernel divides up the hardware and starts further independent Linux kernels directly on bare metal. The project is called Multikernel Linux. It is not the historical microkernel-based MkLinux.
Linux stands for curiosity, self-determination and the freedom to understand technology and shape it the way you want. That makes me all the more pleased about my membership in the LPI.
Hackaday compares classic FTP clients with NcFTP for old servers, retro computers and unencrypted file transfers that are still necessary. FTP normally transmits credentials unencrypted. NcFTP has existed for many years.
In August 2026 Palo Alto Networks closed numerous holes, most of them in the Chromium-based enterprise browser Prisma Browser. There, memory bugs could lead to code execution; version 150.49.8.187 was fixed. Further holes affected the GlobalProtect VPN client on Android, macOS and Windows, including a privilege escalation (CVE-2026-0299).
In August 2026 two holes became known in the Trusted Computing Group’s reference code for firmware TPMs (fTPM 2.0), which AMD and Intel adopt in their BIOS versions. CVE-2026-6727 is a timing side channel in RSA-OAEP; CVE-2026-6726 allows discarded keys to be replaced by false ones. They can only be exploited with local, privileged access and are mainly relevant for company devices.
Hackaday describes the multitude of distribution packages, language managers, third-party sources, AppImage and Flatpak as a burden for application authors. The Fresh editor serves as a concrete example. APT, AUR, Homebrew, AppImage and Flatpak are named.
In 2026 heise again advertised the five-day iX workshop “Hardening Linux servers” with Florian Winkler of B1 Systems, this time with dates in September and November. Topics range from physical security through encryption, two-factor authentication and SELinux/AppArmor to logging, monitoring and intrusion detection. The target group is Linux administrators and security officers who want to secure their servers systematically.
KG takes stock of the distances, energy, radiation, dust collisions and communication limits that make interstellar travel difficult even for advanced civilisations. The universe can be full of life, even though physical barriers almost prevent direct contact. A reachable home world gains value when escaping to other stars remains unrealistic.
DIYP recovers memory and other components from damaged equipment and builds usable computers from them again. The original video has the ID 7FStfdGjAwc. Repair knowledge counters rising parts prices and growing electronic waste at the same time.
Hugging Face describes a break-in in which an autonomous agent combined a prepared data source with insecure execution paths. Internal data sets and credentials were reached; according to what was known at the time, public Hub artefacts were not manipulated. The attack combined a malicious data set with remote code execution and template injection.
David Kan combines SIGFINN and VIVALLA stands into a sculptural stereo speaker whose thin bamboo surfaces deliberately resonate. The project is called Cremona Duetto. Three IKEA stands are used.
Manuel Schmitt explains why he switches off almost all smartphone notifications and prefers to fetch information on his own terms. Manuel has permanently disabled push notifications, popovers and almost all other alerts. As a result, he sometimes only answers messages after hours.
RFC 9846 replaces RFC 8446 and consolidates TLS 1.3 with the corrections and updates published up to then. Security standards occasionally need a consolidated new edition instead of many scattered updates. Superseding the document changes the reference, not the goal of a smaller, secure protocol.
The guide moves compute-intensive CI steps from GitHub Actions to Hugging Face Jobs. GitHub remains the trigger and status interface, while specialised hardware runs externally. Hugging Face Jobs can run GPU and CPU tasks from GitHub workflows.
RFC 9958 explains to engineers the properties, transition risks and deployment patterns of post-quantum cryptography. Cryptographic migration starts long before quantum attacks are practically available. Harvest-now-decrypt-later makes data that must stay confidential for a long time relevant today.
RFC 10008 defines the HTTP method QUERY for complex, safe and idempotent queries with request content. New methods close gaps when established semantics do not fit cleanly. Explicit semantics are better than misused POST requests.
The article extends continuous batching with asynchronous preparation and output so that CPU work blocks the GPU scheduler less. Overlapping pipeline phases increase utilisation with many simultaneous requests. Tokenisation, scheduling and output can be overlapped with GPU computation.
RFC 9989 updates DMARC for policies, alignment and reports based on SPF and DKIM. Email authentication is an interplay of several DNS and signature mechanisms. Strict policies first need reliable observation.
The article argues that open models give defenders tools they can inspect and adapt. At the same time, it acknowledges that the same capabilities are available to attackers. Open weights allow local analysis without handing sensitive data to an API provider.
davd delivers a reality check on running your own mail server and explains why DNS, deliverability, spam defence and reputation are harder than the actual server software. With email, self-hosting fails more often because of social trust than because of SMTP. Decentralisation only survives if small operators can achieve deliverability in practice.
Storage buckets add S3-like object storage for checkpoints, logs and intermediate states to the version-oriented repositories. The data remains accessible via browser, script and command line. Buckets are S3-like and are backed by the Xet storage layer.
RFC 9849 encrypts most of the TLS ClientHello and thereby protects destination and negotiation data that used to be visible. Content encryption alone does not hide all metadata of a connection. More privacy changes troubleshooting and network filtering.
GGML and llama.cpp become part of Hugging Face to develop local inference and open model formats further in the long term. The collaboration ties the Hub more closely to CPU and edge execution. GGML forms the technical basis of many quantised local models.
Lutz Donnerhacke intercepts misrouted customer traffic to private addresses and examines safe responses that calm faulty devices and make misconfigurations visible. Among other things, DNS, LDAP, ICMP and solar inverter control traffic was observed. The provider network itself used 100.64.0.0/10 for its customers.
After five months of intensive work, Johannes Findeisen releases the first version of his programming language Fun. The released version carries the number 0.37.62. Johannes had worked intensively on the implementation for five months beforehand.
Open Responses describes an open schema for model responses, tool calls and agentic workflows. Applications are meant to be able to switch providers without rebuilding every integration layer. The specification models text, tools and other output elements in one response structure.
In January 2026 researchers from Black Duck found a hole in Broadcom Wi-Fi chipsets through which an attacker within radio range can knock out a 5 GHz network with a single packet, without logging in and regardless of WPA2 or WPA3. All clients lose their connection until the router is restarted, and the attack can be repeated immediately. Testing was done on an Asus RT-BE86U; Broadcom had already patched, but how far manufacturers had passed this on remained unclear.
In 2026 the magazine Rtings found none among 25 tested Wi-Fi 7 routers that implemented the standard satisfactorily. Multi-Link Operation (MLO) in particular was neglected: no model used true simultaneous MLO, and only one supported EMLSR as a fallback. In addition, manufacturers cause confusion with names such as “Wifi” without a hyphen, which are not subject to the Wi-Fi Alliance’s certification.
At the end of 2025 Fortinet warned of ongoing attacks on a FortiOS hole patched since July 2020 (CVE-2020-12812), which according to Shadowserver was still exploitable on around 10,000 firewalls. Attackers use it to bypass two-factor login via FortiToken by changing the upper and lower case of the user name. Local users authenticated via LDAP and assigned to a group are affected.