<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>bk99.de Blog</title><link>https://www.bk99.de/en/blog/</link><atom:link href="https://www.bk99.de/en/blog/feed.xml" rel="self" type="application/rss+xml"/><description>Linux, networks, open source, DIY and internet history from the Neugier:Lab.</description><language>en</language><lastBuildDate>Sat, 03 Oct 2026 12:00:00 GMT</lastBuildDate><item><title>Mail from the ISS: SSTV images with a Raspberry Pi and a magnetic-base antenna</title><link>https://www.bk99.de/en/blog/2026/iss-sstv-series-33/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/iss-sstv-series-33/</guid><pubDate>Fri, 02 Oct 2026 12:00:00 GMT</pubDate><description>From 2 to 6 October 2026, the International Space Station is transmitting twelve images via SSTV on 437.550 MHz as part of ARISS Series 33. I received them in Meerane with a Raspberry Pi, an RTL-SDR stick, a simple magnetic-base antenna and OpenWebRX+, and on the first usable pass two images came through cleanly. The deciding factor was not the antenna, but a small script that tracks the frequency during the pass and saves the images itself.</description></item><item><title>6,594 emails from my servers: What 20 years of robot mail tell</title><link>https://www.bk99.de/en/blog/2026/zwanzig-jahre-servermails/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/zwanzig-jahre-servermails/</guid><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><description>While building my mail archive, I found a folder with 6,594 emails that servers I was responsible for sent me between 2004 and 2025. Logwatch reports, cron output and warnings show how my server operations changed over twenty years. This post shows what this robot mail reveals, when it became a burden and how I would approach monitoring by email today.</description></item><item><title>USB Killer vs. IBM T22: 1:0 to the stick</title><link>https://www.bk99.de/en/blog/2016/usb-killer-thinkpad-t22/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2016/usb-killer-thinkpad-t22/</guid><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><description>In October 2016 I plugged a USB Killer into a retired but still working IBM ThinkPad T22, and afterwards it was dead. This post explains how the small device takes the energy for its attack from the victim’s USB port and why almost any hardware loses. It also answers the question why you would not simply use 230 volts, and shows what this means for protecting your own devices.</description></item><item><title>Honest Bad Guy: My system prompt against people-pleasing AI</title><link>https://www.bk99.de/en/blog/2025/systemprompt-ehrlicher-bad-guy/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/systemprompt-ehrlicher-bad-guy/</guid><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><description>At the end of 2025 I gave my AI assistants a fixed system prompt because their constant agreement without real criticism annoyed me. It demands checking instead of guessing, contradiction instead of sugarcoating and no claimed tests that never happened. Here it is in full to copy, together with the reasons behind the rules and the places where it gets in its own way.</description></item><item><title>120,314 emails from 26 years: My mailbox moves into its own archive</title><link>https://www.bk99.de/en/blog/2026/mailarchiv-120000-mails/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/mailarchiv-120000-mails/</guid><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><description>In September 2026 I merged Outlook, Thunderbird, Evolution and Cyrus mail from 26 years into a local mail archive running Stalwart and Roundcube. In the end there were 120,314 searchable emails, including more than 11,000 that had long been considered deleted. This post shows why Message-IDs do not detect duplicates, what Thunderbird really does when you delete something and how an archive can stay safe without any cloud.</description></item><item><title>What I learned from 2.9 billion tokens</title><link>https://www.bk99.de/en/blog/2026/ki-stack-september-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/ki-stack-september-2026/</guid><pubDate>Thu, 01 Oct 2026 12:00:00 GMT</pubDate><description>In September I made AI speak locally, got a 35-billion-parameter model running on a single graphics card and, according to OpenAI, used 2.9 billion tokens in the cloud. A present for a friend still did not get finished. This post shows where the waiting time of a voice AI really comes from, why an HTTP 200 can lie and what a token counter reveals about AI agents.</description></item><item><title>UEFI Secure Boot: Why signed firmware could lock out Linux</title><link>https://www.bk99.de/en/blog/2011/mjg59-uefi-secure-boot/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2011/mjg59-uefi-secure-boot/</guid><pubDate>Tue, 29 Sep 2026 12:00:00 GMT</pubDate><description>Shortly before Windows 8, Matthew Garrett explains the key model of UEFI Secure Boot and warns that computers with only OEM and Microsoft keys will no longer boot a generic Linux. According to Garrett’s analysis, signed Linux versions fail because of GPL bootloaders, self-built kernels and the lack of a central signing authority. The assessment: it is too early to panic, but not too early to be concerned.</description></item><item><title>Secure Boot in practice: How firmware bugs undermine the protection</title><link>https://www.bk99.de/en/blog/2014/mjg59-secure-boot-angriffe/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2014/mjg59-secure-boot-angriffe/</guid><pubDate>Tue, 29 Sep 2026 12:00:00 GMT</pubDate><description>Matthew Garrett summarises MITRE’s research from SyScan 2014: on many computers, Secure Boot can be bypassed from within the running operating system. The cause is not the cryptography but wrongly stored policies and missing lock bits in the chipset. Garrett still considers Secure Boot a real security gain whose obvious flaws will only disappear over several hardware generations.</description></item><item><title>MeshCore on 868 MHz: A decentralised radio network without the internet</title><link>https://www.bk99.de/en/blog/2026/ccc-meshcore-868-mhz/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/ccc-meshcore-868-mhz/</guid><pubDate>Wed, 23 Sep 2026 12:00:00 GMT</pubDate><description>Christian Stankowic and CodeSalat show how MeshCore and Meshtastic enable independent text networks and custom mesh bots with inexpensive LoRa hardware. Both projects build decentralised text networks on LoRa radio technology. Under suitable conditions, messages can cover many kilometres across several nodes.</description></item><item><title>E-waste turned router: OpenWrt and OPNsense on old x86 hardware</title><link>https://www.bk99.de/en/blog/2026/hackaday-diy-router-opnsense/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hackaday-diy-router-opnsense/</guid><pubDate>Tue, 22 Sep 2026 12:00:00 GMT</pubDate><description>Maya Posch tries out an old Intel Atom PC as an open router and shows how driver choice, installation and reliable measurements decide success. The Intel D2500CC board uses an Atom processor with two 1.8 GHz cores and initially two gigabytes of DDR3. OpenWrt’s generic x86 image did contain e1000, but not the required kmod-e1000e package.</description></item><item><title>Post-quantum certificates with Merkle trees</title><link>https://www.bk99.de/en/blog/2026/letsencrypt-post-quanten-zertifikate/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/letsencrypt-post-quanten-zertifikate/</guid><pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate><description>Andrew Gabbitas describes how Let’s Encrypt wants to enable post-quantum authentication with Merkle Tree Certificates without slowing down TLS connections with large individual signatures. An ML-DSA-44 signature is about 2,420 bytes. A current ECDSA P-256 signature, by contrast, needs 64 bytes.</description></item><item><title>systemd between integration and the Unix philosophy</title><link>https://www.bk99.de/en/blog/2026/hanez-systemd-kritik/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hanez-systemd-kritik/</guid><pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate><description>Johannes Findeisen criticises systemd as a complex, tightly coupled Linux suite and contrasts it with OpenRC, runit and s6 as more modular alternatives. The version examined was last updated on 25 July 2026. systemd uses units and cgroups for service and resource management.</description></item><item><title>Occam’s razor: Explaining simply without oversimplifying</title><link>https://www.bk99.de/en/blog/2026/ockhams-rasiermesser/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/ockhams-rasiermesser/</guid><pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate><description>The Wikipedia article explains Occam’s razor as an economical rule of research that removes unnecessary assumptions without confusing simplicity with truth. Occam’s razor is a heuristic principle in the philosophy of science. It is not considered a criterion of truth in its own right.</description></item><item><title>Linux kernel approaches 2,000 CVEs per release</title><link>https://www.bk99.de/en/blog/2026/slashdot-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/slashdot-2026/</guid><pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate><description>Linux CVE assignment is approaching 2,000 entries per kernel release, which changes how meaningful they are in practice.</description></item><item><title>hAudio 0.03: Audio routing for two computers</title><link>https://www.bk99.de/en/blog/2026/haudio/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/haudio/</guid><pubDate>Sat, 29 Aug 2026 12:00:00 GMT</pubDate><description>hAudio 0.03 is a permanently running audio system for the Raspberry Pi: it mixes the signals of two computers onto one wireless headset and routes the headset microphone independently to PC 1, PC 2, both or neither.</description></item><item><title>Several Linux kernels run without a hypervisor</title><link>https://www.bk99.de/en/blog/2026/hackaday-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hackaday-2026/</guid><pubDate>Thu, 27 Aug 2026 12:00:00 GMT</pubDate><description>Hackaday presents Multikernel Linux, in which a host kernel divides up the hardware and starts further independent Linux kernels directly on bare metal. The project is called Multikernel Linux. It is not the historical microkernel-based MkLinux.</description></item><item><title>Member of the Linux Professional Institute</title><link>https://www.bk99.de/en/blog/2026/lpi-membership/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/lpi-membership/</guid><pubDate>Wed, 26 Aug 2026 12:00:00 GMT</pubDate><description>Linux stands for curiosity, self-determination and the freedom to understand technology and shape it the way you want. That makes me all the more pleased about my membership in the LPI.</description></item><item><title>Making FTP more bearable with modern command-line tools</title><link>https://www.bk99.de/en/blog/2026/hackaday-2026-2/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hackaday-2026-2/</guid><pubDate>Mon, 17 Aug 2026 12:00:00 GMT</pubDate><description>Hackaday compares classic FTP clients with NcFTP for old servers, retro computers and unencrypted file transfers that are still necessary. FTP normally transmits credentials unencrypted. NcFTP has existed for many years.</description></item><item><title>Palo Alto Networks: numerous security holes in Prisma Browser closed</title><link>https://www.bk99.de/en/blog/2026/heise-2026-1/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/heise-2026-1/</guid><pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate><description>In August 2026 Palo Alto Networks closed numerous holes, most of them in the Chromium-based enterprise browser Prisma Browser. There, memory bugs could lead to code execution; version 150.49.8.187 was fixed. Further holes affected the GlobalProtect VPN client on Android, macOS and Windows, including a privilege escalation (CVE-2026-0299).</description></item><item><title>The security coprocessor in many CPUs is insecure</title><link>https://www.bk99.de/en/blog/2026/heise-2026-2/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/heise-2026-2/</guid><pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate><description>In August 2026 two holes became known in the Trusted Computing Group’s reference code for firmware TPMs (fTPM 2.0), which AMD and Intel adopt in their BIOS versions. CVE-2026-6727 is a timing side channel in RSA-OAEP; CVE-2026-6726 allows discarded keys to be replaced by false ones. They can only be exploited with local, privileged access and are mainly relevant for company devices.</description></item><item><title>Why Linux applications are hard to distribute</title><link>https://www.bk99.de/en/blog/2026/hackaday-2026-3/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hackaday-2026-3/</guid><pubDate>Wed, 12 Aug 2026 12:00:00 GMT</pubDate><description>Hackaday describes the multitude of distribution packages, language managers, third-party sources, AppImage and Flatpak as a burden for application authors. The Fresh editor serves as a concrete example. APT, AUR, Homebrew, AppImage and Flatpak are named.</description></item><item><title>iX workshop: hardening Linux servers with encryption and access control</title><link>https://www.bk99.de/en/blog/2026/heise-2026-3/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/heise-2026-3/</guid><pubDate>Mon, 10 Aug 2026 12:00:00 GMT</pubDate><description>In 2026 heise again advertised the five-day iX workshop “Hardening Linux servers” with Florian Winkler of B1 Systems, this time with dates in September and November. Topics range from physical security through encryption, two-factor authentication and SELinux/AppArmor to logging, monitoring and intrusion detection. The target group is Linux administrators and security officers who want to secure their servers systematically.</description></item><item><title>Why humanity may never leave the solar system</title><link>https://www.bk99.de/en/blog/2026/kurzgesagt-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/kurzgesagt-2026/</guid><pubDate>Tue, 04 Aug 2026 12:00:00 GMT</pubDate><description>KG takes stock of the distances, energy, radiation, dust collisions and communication limits that make interstellar travel difficult even for advanced civilisations. The universe can be full of life, even though physical barriers almost prevent direct contact. A reachable home world gains value when escaping to other stars remains unrealistic.</description></item><item><title>Saving PC parts through consistent recycling</title><link>https://www.bk99.de/en/blog/2026/diyperks-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/diyperks-2026/</guid><pubDate>Fri, 17 Jul 2026 12:00:00 GMT</pubDate><description>DIYP recovers memory and other components from damaged equipment and builds usable computers from them again. The original video has the ID 7FStfdGjAwc. Repair knowledge counters rising parts prices and growing electronic waste at the same time.</description></item><item><title>Security incident at Hugging Face in July 2026</title><link>https://www.bk99.de/en/blog/2026/hf-security-incident-july-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-security-incident-july-2026/</guid><pubDate>Thu, 16 Jul 2026 12:00:00 GMT</pubDate><description>Hugging Face describes a break-in in which an autonomous agent combined a prepared data source with insecure execution paths. Internal data sets and credentials were reached; according to what was known at the time, public Hub artefacts were not manipulated. The attack combined a malicious data set with remote code execution and template injection.</description></item><item><title>IKEA bamboo stands become a resonance speaker</title><link>https://www.bk99.de/en/blog/2026/ikea-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/ikea-2026/</guid><pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate><description>David Kan combines SIGFINN and VIVALLA stands into a sculptural stereo speaker whose thin bamboo surfaces deliberately resonate. The project is called Cremona Duetto. Three IKEA stands are used.</description></item><item><title>Switching off notifications as digital sovereignty</title><link>https://www.bk99.de/en/blog/2026/hostblogger-benachrichtigungen-digitale-souveraenitaet/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hostblogger-benachrichtigungen-digitale-souveraenitaet/</guid><pubDate>Tue, 07 Jul 2026 12:00:00 GMT</pubDate><description>Manuel Schmitt explains why he switches off almost all smartphone notifications and prefers to fetch information on his own terms. Manuel has permanently disabled push notifications, popovers and almost all other alerts. As a result, he sometimes only answers messages after hours.</description></item><item><title>RFC 9846: TLS 1.3: The consolidated current specification</title><link>https://www.bk99.de/en/blog/2026/rfc-9846/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/rfc-9846/</guid><pubDate>Wed, 01 Jul 2026 12:00:00 GMT</pubDate><description>RFC 9846 replaces RFC 8446 and consolidates TLS 1.3 with the corrections and updates published up to then. Security standards occasionally need a consolidated new edition instead of many scattered updates. Superseding the document changes the reference, not the goal of a smaller, secure protocol.</description></item><item><title>Moving GitHub CI to Hugging Face Jobs</title><link>https://www.bk99.de/en/blog/2026/hf-github-ci-hf-jobs/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-github-ci-hf-jobs/</guid><pubDate>Tue, 09 Jun 2026 12:00:00 GMT</pubDate><description>The guide moves compute-intensive CI steps from GitHub Actions to Hugging Face Jobs. GitHub remains the trigger and status interface, while specialised hardware runs externally. Hugging Face Jobs can run GPU and CPU tasks from GitHub workflows.</description></item><item><title>RFC 9958: Post-quantum cryptography for practitioners</title><link>https://www.bk99.de/en/blog/2026/rfc-9958/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/rfc-9958/</guid><pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate><description>RFC 9958 explains to engineers the properties, transition risks and deployment patterns of post-quantum cryptography. Cryptographic migration starts long before quantum attacks are practically available. Harvest-now-decrypt-later makes data that must stay confidential for a long time relevant today.</description></item><item><title>RFC 10008: HTTP QUERY: Safe, idempotent queries with content</title><link>https://www.bk99.de/en/blog/2026/rfc-10008/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/rfc-10008/</guid><pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate><description>RFC 10008 defines the HTTP method QUERY for complex, safe and idempotent queries with request content. New methods close gaps when established semantics do not fit cleanly. Explicit semantics are better than misused POST requests.</description></item><item><title>Asynchrony in continuous batching</title><link>https://www.bk99.de/en/blog/2026/hf-continuous-async/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-continuous-async/</guid><pubDate>Thu, 14 May 2026 12:00:00 GMT</pubDate><description>The article extends continuous batching with asynchronous preparation and output so that CPU work blocks the GPU scheduler less. Overlapping pipeline phases increase utilisation with many simultaneous requests. Tokenisation, scheduling and output can be overlapped with GPU computation.</description></item><item><title>RFC 9989: DMARC: Domain-based email authentication</title><link>https://www.bk99.de/en/blog/2026/rfc-9989/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/rfc-9989/</guid><pubDate>Fri, 01 May 2026 12:00:00 GMT</pubDate><description>RFC 9989 updates DMARC for policies, alignment and reports based on SPF and DKIM. Email authentication is an interplay of several DNS and signature mechanisms. Strict policies first need reliable observation.</description></item><item><title>Why open AI matters for cybersecurity</title><link>https://www.bk99.de/en/blog/2026/hf-cybersecurity-openness/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-cybersecurity-openness/</guid><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><description>The article argues that open models give defenders tools they can inspect and adapt. At the same time, it acknowledges that the same capabilities are available to attackers. Open weights allow local analysis without handing sensitive data to an API provider.</description></item><item><title>Self-hosting email: DNS, spam filters and reputation</title><link>https://www.bk99.de/en/blog/2026/ccc-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/ccc-2026/</guid><pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate><description>davd delivers a reality check on running your own mail server and explains why DNS, deliverability, spam defence and reputation are harder than the actual server software. With email, self-hosting fails more often because of social trust than because of SMTP. Decentralisation only survives if small operators can achieve deliverability in practice.</description></item><item><title>Vanilla Linux on a 100 Gbit/s router</title><link>https://www.bk99.de/en/blog/2026/clt-2026/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/clt-2026/</guid><pubDate>Sat, 28 Mar 2026 12:00:00 GMT</pubDate><description>With suitable hardware and packet processing, standard Linux can run a 100 Gbit/s router.</description></item><item><title>Mutable storage buckets in the Hub</title><link>https://www.bk99.de/en/blog/2026/hf-storage-buckets/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-storage-buckets/</guid><pubDate>Tue, 10 Mar 2026 12:00:00 GMT</pubDate><description>Storage buckets add S3-like object storage for checkpoints, logs and intermediate states to the version-oriented repositories. The data remains accessible via browser, script and command line. Buckets are S3-like and are backed by the Xet storage layer.</description></item><item><title>RFC 9849: TLS Encrypted ClientHello</title><link>https://www.bk99.de/en/blog/2026/rfc-9849/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/rfc-9849/</guid><pubDate>Sun, 01 Mar 2026 12:00:00 GMT</pubDate><description>RFC 9849 encrypts most of the TLS ClientHello and thereby protects destination and negotiation data that used to be visible. Content encryption alone does not hide all metadata of a connection. More privacy changes troubleshooting and network filtering.</description></item><item><title>GGML and llama.cpp join Hugging Face</title><link>https://www.bk99.de/en/blog/2026/hf-ggml-joins-hf/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-ggml-joins-hf/</guid><pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate><description>GGML and llama.cpp become part of Hugging Face to develop local inference and open model formats further in the long term. The collaboration ties the Hub more closely to CPU and edge execution. GGML forms the technical basis of many quantised local models.</description></item><item><title>Misconfiguration as a Service: Answering undeliverable traffic sensibly</title><link>https://www.bk99.de/en/blog/2026/donnerhacke-fehlkonfig-service/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/donnerhacke-fehlkonfig-service/</guid><pubDate>Wed, 04 Feb 2026 12:00:00 GMT</pubDate><description>Lutz Donnerhacke intercepts misrouted customer traffic to private addresses and examines safe responses that calm faulty devices and make misconfigurations visible. Among other things, DNS, LDAP, ICMP and solar inverter control traffic was observed. The provider network itself used 100.64.0.0/10 for its customers.</description></item><item><title>Fun 0.37.62: First release of a programming language of his own</title><link>https://www.bk99.de/en/blog/2026/hanez-fun-0-37-62/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hanez-fun-0-37-62/</guid><pubDate>Wed, 28 Jan 2026 12:00:00 GMT</pubDate><description>After five months of intensive work, Johannes Findeisen releases the first version of his programming language Fun. The released version carries the number 0.37.62. Johannes had worked intensively on the implementation for five months beforehand.</description></item><item><title>Open Responses as an open agent interface</title><link>https://www.bk99.de/en/blog/2026/hf-open-responses/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/hf-open-responses/</guid><pubDate>Thu, 15 Jan 2026 12:00:00 GMT</pubDate><description>Open Responses describes an open schema for model responses, tool calls and agentic workflows. Applications are meant to be able to switch providers without rebuilding every integration layer. The specification models text, tools and other output elements in one response structure.</description></item><item><title>Broadcom hole lets attackers knock out entire Wi-Fi networks</title><link>https://www.bk99.de/en/blog/2026/golem-2026-1/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/golem-2026-1/</guid><pubDate>Wed, 14 Jan 2026 12:00:00 GMT</pubDate><description>In January 2026 researchers from Black Duck found a hole in Broadcom Wi-Fi chipsets through which an attacker within radio range can knock out a 5 GHz network with a single packet, without logging in and regardless of WPA2 or WPA3. All clients lose their connection until the router is restarted, and the attack can be repeated immediately. Testing was done on an Asus RT-BE86U; Broadcom had already patched, but how far manufacturers had passed this on remained unclear.</description></item><item><title>Wi-Fi 7 routers disappoint so far</title><link>https://www.bk99.de/en/blog/2026/golem-2026-2/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/golem-2026-2/</guid><pubDate>Tue, 13 Jan 2026 12:00:00 GMT</pubDate><description>In 2026 the magazine Rtings found none among 25 tested Wi-Fi 7 routers that implemented the standard satisfactorily. Multi-Link Operation (MLO) in particular was neglected: no model used true simultaneous MLO, and only one supported EMLSR as a fallback. In addition, manufacturers cause confusion with names such as “Wifi” without a hyphen, which are not subject to the Wi-Fi Alliance’s certification.</description></item><item><title>Ongoing attacks endanger 10,000 firewalls</title><link>https://www.bk99.de/en/blog/2026/golem-2026-3/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2026/golem-2026-3/</guid><pubDate>Mon, 05 Jan 2026 12:00:00 GMT</pubDate><description>At the end of 2025 Fortinet warned of ongoing attacks on a FortiOS hole patched since July 2020 (CVE-2020-12812), which according to Shadowserver was still exploitable on around 10,000 firewalls. Attackers use it to bypass two-factor login via FortiToken by changing the upper and lower case of the user name. Local users authenticated via LDAP and assigned to a group are affected.</description></item><item><title>Cloudflare hits the limits of the Linux network stack</title><link>https://www.bk99.de/en/blog/2025/hackaday-2025/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/hackaday-2025/</guid><pubDate>Wed, 31 Dec 2025 12:00:00 GMT</pubDate><description>Hackaday describes Cloudflare’s attempt to redirect TCP connections for soft unicast and why a simple local proxy ultimately proved more robust. Cloudflare uses anycast extensively for its services. TCP_REPAIR is normally used to migrate connections.</description></item><item><title>Meta uses the Steam Deck scheduler on its servers</title><link>https://www.bk99.de/en/blog/2025/slashdot-2025/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/slashdot-2025/</guid><pubDate>Tue, 23 Dec 2025 12:00:00 GMT</pubDate><description>Meta also used a Linux scheduler originally developed for the Steam Deck on its servers.</description></item><item><title>A modern Linux kernel still fits on a floppy disk</title><link>https://www.bk99.de/en/blog/2025/hackaday-2025-2/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/hackaday-2025-2/</guid><pubDate>Sat, 20 Dec 2025 12:00:00 GMT</pubDate><description>Action Retro trims Linux 6.14 and BusyBox down so far that a bootable system runs from a 1.44 megabyte floppy disk. The kernel used comes from Linux 6.14. The target medium holds about 1.44 megabytes.</description></item><item><title>Transformers v5 simplifies model definitions</title><link>https://www.bk99.de/en/blog/2025/hf-transformers-v5/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/hf-transformers-v5/</guid><pubDate>Mon, 01 Dec 2025 12:00:00 GMT</pubDate><description>Transformers v5 aligns model definitions more closely with readable PyTorch code and reusable components. New architectures are meant to be integrated faster without making the library incomprehensible. Version 5 revises central patterns for defining models.</description></item><item><title>Migrating procmail rules to Sieve with a real parser</title><link>https://www.bk99.de/en/blog/2025/hostblogger-procmail-zu-sieve-parser/</link><guid isPermaLink="true">https://www.bk99.de/en/blog/2025/hostblogger-procmail-zu-sieve-parser/</guid><pubDate>Wed, 26 Nov 2025 12:00:00 GMT</pubDate><description>Manuel Schmitt replaces an unreliable procmail-to-Sieve converter with his own parser with a deliberately limited scope. The earlier converter was partly based on free scripts, including earlier work from Dovecot. The new converter was rewritten completely in-house.</description></item></channel></rss>
