Senin, 05 Oktober 2026

Siemens Abruptly Takes Down OpenRadioss, But a Fork is Already Live

opencourant launch banner

The globally recognized tech and engineering company has quietly shut down the OpenRadioss project at the start of this month, keeping the GitHub page around but completely removing the repository.

I sound complainy because usually when an open project is discontinued, the maintainers put it into a read-only, public archive state, which allows other developers to learn and fork off it.

OpenRadioss was the open source release of Radioss, a finite element solver Altair Engineering developed for crash testing, blast response, impact analysis, and other structure loading scenarios.

They had released it in September 2022, drawing in a multinational community of researchers, software developers, and industry contributors who extended the solver and built upon the code.

Siemens, which acquired Altair last year, kept the repo and its contents publicly available for more than a year after the acquisition before abruptly deleting it and redirecting people to its transition page for Simcenter Radioss.

A fork appears

Brian Clemens, the co-founder of Rocky Linux has already got an OpenRadioss fork up and running, which carries the full OpenRadioss commit history, ships under the same GNU AGPLv3 license, and is hosted on GitHub.

It's called OpenCourant, named after mathematician Richard Courant and the Courant-Friedrichs-Lewy (CFL) condition, a stability criterion central to solvers like this one.

In fact, this fork owes its existence to the AGPL. You see, Siemens is legally within its rights to take down the repository, but the license applying to every commit gave anyone the right to fork, distribute, and build on the code.

It's just sad to see how abruptly the takedown was carried out; makes you think they didn't want people to get a heads-up.

Also worth noting is that OpenCourant is an independent community project, and it is actively looking for past OpenRadioss contributors to pitch in.

What's already shipping?

a placeholder image that shows the opencourant download page on its website

Initially, the upstream build pipeline that depended on proprietary Siemens infrastructure could not be transferred. That was rebuilt from scratch, and the results appear promising.

Just days since its inception, the project is already distributing Linux and Windows x86_64 packages.

And before that, a closed-source hm_reader input-reader binary that was never committed to the git history disappeared along with the upstream OpenRadioss repository.

Thankfully, an unnamed community member who had kept a copy came forward, the OpenCourant team independently verified it, and it now ships in every build. Though they are still looking for specific release archives to start work on ARM64 support and improve current platform compatibility.

If you are interested in OpenCourant, then its package options include the Starter and Engine offerings in single and double precision, SMP builds, and converters for animation files and time history data.

You can download the latest builds from the official downloads page.

If you get lost, the INSTALL.md file can be a good resource, though keep in mind it is still the OpenRadioss version, as the OpenCourant team has yet to update it to reflect the new project.



from It's FOSS https://ift.tt/yUl6TpK
via IFTTT

Ubuntu 26.10 Will Have a Rust-based GnuPG Replacement

ubuntu gnupg and sequoia pgp banner

You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, most of the time.

Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG as the default toolchain, though that switch has not happened yet.

What's OpenPGP?

Before getting into Sequoia, it helps to know what OpenPGP actually is. It's not a tool but rather a widely adopted standard.

Phil Zimmermann created the original PGP in 1991, and the IETF now maintains the open version of that work. The specification defines how software should encrypt, decrypt, sign, and verify data so that any two implementations following it can work with each other's data.

On Linux, GnuPG has been the dominant implementation of that standard. Written in C, it implements RFC 4880 and offers the gpg and gpgv commands on the platform. These handle everything from encryption and key management to standalone signature verification.

Sequoia PGP is different

It was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG’s existing codebase.

Sequoia PGP is designed as a library that other software can use directly, rather than a standalone command-line tool. sq sits on top of that for encryption, decryption, signing, and key management, and sqv handles signature verification, filling in for gpg and gpgv in GnuPG.

Sequoia also implements RFC 9580, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard.

What's already in?

Ubuntu 26.10 "Stonking Stingray" already pulls in Sequoia PGP from the main archive (look under rust-sequoia-xx) as part of the default installation. I ran sq and sqv on a development build of 26.10, and both were working correctly.

Here, sq acts as the main interface for encryption, decryption, signing, and key management, while sqv handles signature verification. And typing gpg and gpgv still routes to GnuPG, so these two OpenPGP implementations sit alongside each other.

If Sequoia PGP is made the default, you can expect those commands and other GnuPG ones to route to Sequoia instead, similar to how we saw with sudo-rs.

Still a long way to go

The release notes for Ubuntu 26.10 and a recent announcement clearly mention that Sequoia PGP becoming Ubuntu's default OpenPGP toolchain is a future goal, not something that's already the default experience.

The coreutils transition started in 2025 and only reached 100% with 26.10. The sudo-rs switch was shown off well in advance before it became the default. Each of these components had to earn their place over multiple release cycles before anything changed for users.

Sequoia PGP is at the start of that process. Landing in the main archive is the first milestone. Whether it eventually replaces GnuPG as the default remains to be seen.

Canonical has not shared a specific inclusion timeline. Given how carefully they have moved on every other Rust transition so far, that caution is unlikely to disappear for something as foundational as OpenPGP.



from It's FOSS https://ift.tt/A1XpmIr
via IFTTT

Minggu, 04 Oktober 2026

ORICO X50 Review: A Sleek Thunderbolt 5 SSD Enclosure

A few months back, I reviewed the TerraMaster D1 SSD Plus and liked it for what it offered. A sturdy box that gives a second life to an NVMe SSD lying around (rarity these days).

Now I have the ORICO X50 on my desk, which does the same job but promises twice the bandwidth with Thunderbolt 5.

ORICO X50

I ran the similar set of benchmarks on it on Ubuntu, and I have the numbers to share.

Here's a quick summary of my experience with the device.

✅ Slim, good-looking aluminum body that's easy to carry
✅ Comes with an 80Gbps cable in the box
✅ Works out of the box on Linux, with full NVMe SMART data
✅ Stayed in the 60s °C during a 13-minute sustained write
❎ Only 2280 NVMe SSDs; heatsink SSDs won't fit
❎ Priced well above USB4 enclosures

ORICO X50 Thunderbolt 5 SSD enclosure specifications

Here are the hardware specifications for ORICO X50.

Specification ORICO X50
Interface Thunderbolt 5 (80Gbps), backward compatible with Thunderbolt 4, Thunderbolt 3 and USB4
Rated speed Up to 6000 MB/s read, 5800 MB/s write
Supported SSD M.2 NVMe, 2280 size only (2230 not supported), M Key and B+M Key
Recommended SSD PCIe Gen4 or Gen5
Max capacity 4TB
Cooling Fanless, aluminum unibody with micro fins, thermal film and thermal paste
Material Aluminum alloy
Dimensions 110 × 60 × 18.7 mm
Cable 0.5m USB-C to USB-C, 80Gbps
OS support Windows, macOS, Linux
Price $269.99 for the diskless version

ORICO also sells the X50 with a 512GB or 1TB SSD already installed. I got the empty enclosure, which is what most of you would want if you have an SSD to reuse.

Pay attention to the supported SSD list. Like most enclosures of this kind, the X50 doesn't take everything. It's NVMe only, so your old SATA M.2 drive cannot be used, and it's 2280 only, so the tiny 2230 SSD in your stock won't be of much use either.

Also note that on Thunderbolt 4 hosts, the speed is limited to 40Gbps, and on Thunderbolt 3, it will drop even further.

📋
ORICO sent me this device for review. The views expressed are my own.

Design and build

Orico X50 SSD Enclosure

The X50 is noticeably less bulky than the TerraMaster D1 SSD Plus. It's slim enough to slide into a laptop bag pocket. Although it is not as slim as my Sandisk Extreme portable SSD.

The silver aluminum finish looks good, and I think it would fit right into the Apple ecosystem as it matches the aesthetic.

Flip it over and you'll see fins running along the bottom. These increase the surface area for heat dissipation, and judging by my thermal numbers (more on that later), they seem to do their job. There's no fan, so it's completely silent.

Orico X50 bottom view
Orico X50 bottom view

In the box, you get the enclosure, a fast 80Gbps USB-C cable and thermal paste. No SSD, of course, since I got the diskless version. A good cable matters with devices like these. Good of ORICO to include it in the box.

You can apply the thermal paste directly on the SSD. I did not. I wanted to take the raw numbers in the testing.

SSDs with an attached heatsink, like the Samsung 9100 Pro Heatsink version, won't fit inside the X50. Get the bare version of the SSD if you plan to use it with this enclosure.

The first plug-in experience

For my testing, I used a Crucial P3 Plus 500GB. It's a PCIe Gen4 drive rated at 4700 MB/s read and 1900 MB/s write, and it uses QLC NAND. Keep the QLC part in mind; it matters for the sustained write results.

I tested the X50 on Ubuntu 26.04 with Linux kernel 7.0. It worked out of the box. Plugged it in, and the SSD shows up like any other drive. I formatted it as ext4 and it was mounted automatically. So, no surprises here.

Since it's a Thunderbolt device, it's worth checking with boltctl. It got authorized automatically and showed a 40 Gb/s link (2 lanes × 20 Gb/s). Interestingly, it identifies itself as "DM9002QN" from Shenzhen Dongman Technology rather than ORICO.

Orico X50 boltctl result

Because the X50 tunnels PCIe over Thunderbolt, the drive shows up as a native NVMe device (nvme1n1), not a USB disk. That means nvme smart-log works directly and you get full SMART data, including temperature. No need to fiddle with USB bridge flags in smartctl.

This is definitely a plus for Linux users. With many USB enclosures, getting health data out of the SSD is often hit or miss.

Performance: the numbers and the big caveat

Here's the thing. The X50 is a Thunderbolt 5 device, but I don't have a Thunderbolt 5 machine. My laptop is the ASUS Zenbook S14, which has Thunderbolt 4. So the link was capped at 40Gbps, half of what the X50 is designed for.

📋
These tests are limited by the host device. With a Thunderbolt 4 laptop, you are not seeing what the X50 can do at 80Gbps. Treat my numbers as "what you get with a Thunderbolt 4 or USB4 machine", which, honestly, is what most people have today.

This is often the case with storage benchmarks. The weakest link in the chain, be it the port, the cable or the SSD, decides the speed you see. The ORICO's rated 6000 MB/s needs both a Thunderbolt 5 host and a fast Gen4 or Gen5 SSD.

I used fio for simulated tests, plus a couple of real file copy tests. Here are the results from the first run.

Test ORICO X50
Sequential read 3878 MB/s
Sequential write 2810 MB/s
Random read (QD32) 1512 MB/s (369K IOPS)
Random write (QD32) 1175 MB/s (287K IOPS)
Random read (QD1) 59 MB/s (14.4K IOPS, 34 µs latency)
Mixed 70% read / 30% write 1483 MB/s
10GB single file copy 11.8 seconds
5000 small files (4KB) copy 17.5 seconds

The sequential read of 3878 MB/s is pretty much the ceiling of a 40Gbps connection. Pay attention to bits and bytes. The enclosure maxed out what my laptop could offer. The sequential write of 2810 MB/s was well above the Crucial's rated 1900 MB/s, thanks to SLC cache handling the burst.

Orico X50 benchamrking results

I ran the tests a second time to check consistency. The read numbers were pretty much identical. Random write dropped to 978 MB/s and the 10GB copy took 17.8 seconds instead of 11.8. That's because the SSD's cache probably had not fully recovered from the earlier runs.

Thermal performance during sustained writing

To see how the X50 handles heat, I wrote 250GB in one go. It took a little over 13 minutes.

The speed fell from around 2700 MB/s to about 265 MB/s within the first few seconds and stayed there till the end. Before you blame the ORICO enclosure, this is classic QLC behavior.

Once the SLC cache is full, the Crucial P3 Plus writes at its native QLC speed. In the earlier shorter run with a fresh cache, it held about 2700 MB/s for nearly 19 seconds before falling off.

Sustained writing test X50

Let's focus on the temperature. Throughout the 13-minute write, the SSD stayed between 58°C and 68°C, and mostly stayed around 62 to 65°C.

ORICO X50 SSD temperature test

There were no sudden dips in the speed graph that would indicate thermal throttling, at least that's what I would like to think. The fins and the paste seem to be doing their work. The room temperature was around 32°C, I think.

✅
The X50 kept the SSD in the 60 °C range during a 250GB sustained write with no visible throttling. Thermally, it's well built.

ORICO X50 vs TerraMaster D1 SSD Plus

Since I had reviewed the TerraMaster D1 SSD Plus earlier, a comparison was only natural. I ran the same benchmark script on it, on the same Zenbook S14.

The tests are not indentical though because I used a different SSD in each. Crucial P3 Plus 500GB in the ORICO and the WD Blue SN5000 1TB in the TerraMaster. So this is not a pure enclosure vs enclosure comparison. Take the write numbers especially with a pinch of salt.

ORICO X50 TerraMaster D1 SSD Plus
Interface Thunderbolt 5 (80Gbps) USB4 (40Gbps)
Price $269.99 (sale) ~$110
Max capacity 4TB 8TB
Size Slim (110 × 60 × 18.7 mm) Bulkier
SSD in my test Crucial P3 Plus 500GB WD Blue SN5000 1TB
Sequential read 3878 MB/s 3323 MB/s
Sequential write 2810 MB/s 3202 MB/s
Random read (QD32) 1512 MB/s 1588 MB/s
Random write (QD32) 1175 MB/s 1470 MB/s
Random read (QD1) 59 MB/s 64 MB/s
10GB file copy 11.8 s 6.2 s
5000 small files 17.5 s 17.1 s
Sustained write (250GB) ~265 MB/s after cache ~950 MB/s after cache
Peak SSD temperature 68°C (13+ minutes of writing) 59°C (about 3 minutes of writing)

On a 40Gbps connection, both enclosures are in the same league. The ORICO had the better sequential read, which is the best indicator of what the enclosure itself can push. The TerraMaster won on writes, but that's largely down to the WD SSD having a bigger cache and faster post-cache speed than my QLC Crucial.

Basically, on a Thunderbolt 4 or USB4 laptop, you won't see much practical difference between the two. The ORICO's extra money buys you a slimmer design and headroom for Thunderbolt 5. That also keeps you future proof for the next few years.

Is ORICO X50 worth it?

If you have NVMe SSDs lying around and want to use them as fast external storage, the X50 is a good device. It's slim, looks good, stays cool, and works on Linux without any tinkering. The native NVMe access is a nice touch for those of us who like to check drive health from the terminal.

The 2280 only support is limiting. If you have a 2230 or 2242 SSD from an older laptop or a handheld, you can't use it here. And with no SATA support, older M.2 drives are out of the picture as well.

If you have a Thunderbolt 5 machine, or you are planning to buy one in the next year or two, the X50 is a future-proof pick. Pair it with a fast Gen4 or Gen5 TLC SSD to actually get near the advertised 6000 MB/s.

I could not test it at full Thunderbolt 5 speed. If you have a Thunderbolt 5 machine and use the X50, I'd love to hear your numbers in the comments.



from It's FOSS https://ift.tt/XE4kivO
via IFTTT

DigitalOcean Quietly Ends Open Source Credits Program

If some Reddit posts are to be believed, Digital Ocean is ending its Open Source Credits program quietly:

DigitalOcean has decided to sunset the Open Source Credits Program. As part of this change, we are no longer accepting new credit applications or approving credit renewals, extensions, or additional credit requests.

All this is based on a GitHub issue where the maintainers of the Node.js project received an email from Digital Ocean notifying them about the sunset of the Open Source Credits program.

What was the Open Source Credits program?

Digital Ocean is a cloud server infrastructure provider. It ran this "Open Source Credits" program and under this scheme, they gave approved open-source projects cloud credits to cover infrastructure costs. This helped project maintainers run their projects without paying the hosting bill.

For example, Node.js used DigitalOcean infrastructure for its build operations, including virtual servers, storage, snapshots and backups.

For years, Digital Ocean promoted this program and invited projects to apply to this program by sending them a message via opensource@digitalocean.com.

This seems to have changed now.

Sunsetting the Open Source Credits program?

Note that there is no official announcement on DigitalOcean's blog or social media handles.

From what I see, there is a GitHub issue where Node.js maintainers discuss this email.

Digital Ocean ending its Open Source Credit Program

There is also a Reddit thread, but the OP doesn't mention if they received the email themselves or which open source project they maintained.

I have scanned Reddit, X and some other social media platform but have't picked up any signals from other open source projects, yet.

Node.js is a big project and discussion is real. So, we can safely say that Digital Ocean is indeed working on ending this program.

Projects in the program won't receive new credits. The will have to manage with whatever credits that have been issued so far. After that, either they pay to Digital Ocean or move their projects to some other platform provider.

The mail also mentions that new projects will no longer be accepted in the program and the inbox (opensource@digitalocean.com) dedicated for this task will no longer be monitored. That closes the door for new applicants.

A mutual partnership

Programs such as this are a mutually beneficial arrangement. When DigitalOcean offered credits, these projects spun up their CI runners, their documentation sites, their release mirrors, and their testing environments on DigitalOcean infrastructure.

In return, they mentioned Digital Ocean in the project website and documentation. Thousands of developers learned about DigitalOcean's platform through these projects. Some become paying customers individually, whereas some bring it into the companies they worked for.

Both involved parties get something positive from Open Source Credits like programs.

Digital Ocean has been reducing its free offering

This is not the first time DigitalOcean has trimmed its community-facing programs without a clear announcement.

Earlier this year, the GitHub Student Pack credits were removed from DigitalOcean's offerings too. Students trying to redeem the standard $200 in free credits found they were no longer receiving them. Again, there were no formal announcements (because it is a bad outlook). So all you will find is community questions by confused users.

Digital Ocean offers $100 free credit (our partner link) to every new user. This program still runs today (so far). Not sure how long this will be offered, though.

Node got Digital Ocean support back

In the same GitHub issue, Node developers discussed their exit strategy. It then led to a discussion of removing Digital Ocean from the homepage, README and partners page.

And as soon as that happened, Digita Ocean reached out with olive branch.

Notice the use of "what version 2.0 of the program looks like" line? This is either a coverup strategy or an actual revamp of the existing program that will be more selective about which projects will be allowed in the program.

The GitHub issue was then promptly renamed from "Transitioning off of Digital Ocean" to "Solidify Digital Ocean Partnership".

Other open source projects might not be lucky

Node.js is a big project popular with developers of all kinds. Getting their name and link removed when their competitors, like Vercel, are still mentioned on Node.js homepage is something Digital Ocean could not afford.

But not all open source projects are going to get that kind of happy ending. If the closure of the program is indeed true, the smaller projects are going to think about infrastructure bills and move.

When maintainers are already drowning in AI slop pull requests and bug reports, this is going to put additional strain on the maintainers.

Hopefully, some newer infrastructure providers will come up with similar programs. No harm in thinking positive.

If you are an open source project maintainer who got this Open Source Credits program closure email, please reach out to us.



from It's FOSS https://ift.tt/8IjHWZU
via IFTTT

Sabtu, 03 Oktober 2026

We View Consumer Data as Toxic Waste

Obscura VPN's Carl Dong

The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.

For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.

Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.

The person behind it is Carl Dong, a former top-5 Bitcoin Core contributor who signs off his own website as "head-janitor" and "I fight for the users." I sent him a set of questions around Obscura. Here's the conversation.

Obscura team

You went from being a top contributor to Bitcoin Core to founding a VPN company. What convinced you the VPN space needed rebuilding rather than just improving?

"Don't Trust, Verify" is a cornerstone of the cypherpunk principles I grew up with. I see this Trust Minimization as crucial when building human-centric, security- and privacy-critical technologies. Yet the VPN industry is riddled with scandals (e.g., Onavo), broken promises, and "no-log" pinky promises. This never sat right with me.

When I saw what Apple's iCloud Private Relay was doing under the hood, I saw what the next generation of VPNs would look like: VPNs that are verifiably private and that outsmart internet censorship. I wanted to make this a reality outside of Apple's walled garden. The world doesn't need another VPN company; it needs a totally new approach to privacy.

Your whole pitch takes direct aim at the "no-logs" model everyone else uses. Why has that promise become inadequate?

The VPN industry is living in the past. Three conglomerates dominate and give the illusion of choice, while betraying their users' trust and operating a payola scheme using media cut-outs to push their talking points. The no-logs pinky-promise has never been adequate for software that can access the entirety of your internet traffic, and verges on being useless in 2026 when LLM-driven cyberattacks run rampant.

At the end of the day, even honest VPN providers who abide by their no-logs policy can be hacked. Users are waking up to this, and there's been an increasing call within the cybersecurity community to stop using VPNs altogether. Obscura is a direct answer to this: you no longer have to trust any single company's word for your internet privacy. That's the way it should have always been.

Walk our readers through the two-party relay in plain terms. How does it actually change the trust model compared to a normal multi-hop VPN?

When you use a traditional VPN, a single company sees your identity (via your connecting IP + your payment information) and your internet traffic. Using a multi-hop option doesn't change the fact that it's still a single company, and oftentimes just adds additional latency for no good reason.

With Obscura's Two-Party Relay, we use a fully independent company (Mullvad) as our second exit hop, with Obscura as the first hop. All of your internet traffic is encrypted to a key controlled by Mullvad's servers, and only relayed through Obscura's servers. That way, Obscura's relay servers never see your actual internet traffic, and Mullvad's exit servers never see your identity (connecting IP or payment information).

For those familiar with Tor, it's like if Tor only had 2 hops, but the hops were dedicated, high-performance hops optimized for maximum speed and reliability.

A skeptic could say you've just moved the trust problem around. Now users trust two companies instead of one, and the two of you could collude or be compelled together. How do you respond?

Obscura 2 hops

I'd first lightheartedly point out that using traditional VPNs is just moving trust from your (possibly regulated) ISP to a single wholly unregulated private company. 😆

In all seriousness though, our goal with Obscura is to make sure there's no single party that can jeopardize your internet privacy. No one entity should have that power. With Obscura, as long as either Obscura or Mullvad isn't compromised, no one can correlate your personal identity with your internet activity. This is strictly better than trusting either your ISP or a traditional VPN's pinky-promise.

Let's get technical. Your stealth protocol is built on QUIC to mimic HTTP/3 traffic. Why QUIC specifically, and how does it hold up against serious censorship?

We chose QUIC not only because it looks like HTTP/3, but also because its Unreliable Datagram extension allows us to avoid the TCP-over-TCP meltdown problem that plagues TCP-based VPNs. I'd encourage folks to read this for more details.

As for outsmarting censorship, QUIC has been notably harder for middleboxes to do Deep Packet Inspection on. QUIC allows messages to be fragmented and shuffled across UDP datagrams, which means censorship systems have to reassemble them, making it far more costly. I don't know of any QUIC censorship system currently deployed that does reassembly. More information can be found here.

You accept Monero and Bitcoin over Lightning, need no email, and log in with just a random account number. But Obscura still sees the user's connecting IP. How anonymous can a user really be, and where's the honest limit?

Obscura payment methods

We view consumer data as toxic waste. We don't want it, don't need it, and do as much as possible to make sure you don't have to give us any. Aside from what you mentioned, our website is also accessible over Tor.

But you're absolutely right. We can still see the user's connecting IP address. That will not change unless humanity completely rethinks the OSI stack, which will make the IPv6 transition look like a walk in the park. 😆

The fact that we can't avoid seeing your connecting IP address is the point of Obscura though: if we have to see it, then the most private thing to do is to completely decouple that information from your internet traffic. That's what our Two-Party Relay does.

You've open-sourced the client and talk a lot about reproducible builds, clearly something you carried over from Bitcoin Core. For a non-developer, why do reproducible builds matter for a VPN?

I did a lot of reproducible builds work for Bitcoin Core, so this is near and dear to my heart. I believe that reproducible builds matter for any piece of open-source security-critical software. Even if the published source code is not malicious, that says nothing about the app you download. It essentially answers this question: does the app that I download correspond to the source code that is on GitHub (or whatever other forge you may use).

For Bitcoin Core, a malicious app could mean loss/theft of funds. For VPNs, a malicious app has access to the entirety of your internet traffic and can leak that regardless of the security of your VPN provider.

At Obscura, we of course take reproducible builds seriously. We already have a prototype for Android reproducible builds, and are looking to make other platforms work as well.

Obscura is $8/month, and reviewers note that stacking two providers can cost more than one. Beyond the privacy story, how do you make the economics work as a small team without VC pressure to monetize users?

First, we have no user data to monetize. Second, I think in the tech world we've vastly overcomplicated our businesses. For a business to work, you need your costs to be lower than your revenue over time. That's it. We aren't going to construct a massive data center. We aren't going to put tens of millions into R&D in a lab in Switzerland. We're a small group of six people, working remotely, charging fair prices. As long as we keep our customers happy, we don't have anything to worry about. My goal was never to compare yachts with Bezos.

There's a classic tension between maximum privacy and everyday usability, with Tor as the usual cautionary tale. Where do you draw that line?

The goal is for my mom to use Obscura, and she does! (Hopefully not just because I'm her son.)

I don't think that tension between privacy and usability is always inherent: a VPN doesn't have to be complicated. You should flip a switch and it should just work and you should forget you have it on. The goal is to be seamless. Power users and technical folks who want more should always have the ability to tinker, and we offer that, but the goal is to build a product so good that both feel right at home.

Oftentimes we've also found that giving users a choice is the way to go: while cryptocurrencies may be the most private way to pay for Obscura, my mom is likely to want a credit card option. 😄

Looking at the next few years, with encryption under legislative pressure and tracking everywhere, what worries you most about online privacy?

Every day there is another story about a country or international body proposing new rules that jeopardize the open and free internet we all love. Sometimes these are well-meaning protections that legislators don't fully grasp the ramifications of; other times their motivations are less noble.

What all these scenarios have in common is that, somewhere along the way, behavior that was once considered odd and Orwellian became normalized. You go grab a coffee and you give them your phone number, then you download an app (and allow location permissions), and before you know it companies know every aspect of your life.

Then when you read about how the government can legally purchase this data from data brokers, you start to appreciate just how much of your life can be reconstructed to where you essentially have given away every aspect of your privacy for a free coffee on your birthday. (I'm as guilty as anyone.) So what really worries me is our own complicity in trading privacy for convenience. And I hope with Obscura and other smaller privacy-focused start-ups we can make an easier, simpler to use tech that helps protect people and allows them to make better privacy decisions where there is no trade-off between convenience and privacy.

Finally, a fun one. Your site has a "Cursed Knowledge" page. What's the most cursed thing you've learned about how the internet actually works since starting Obscura?

I think the TLS SNI extension has gotta be one of the most cursed things about how the internet works.

Most people assume that if a connection is encrypted by TLS, then it's fully encrypted. What they don't know is that there's a part of every TLS connection called the SNI where the server's domain name is in plaintext, completely unencrypted! In fact, ISPs and middleboxes often use this as a way to enact internet censorship, since it's a much more reliable mechanism than trying to match connections with DNS requests.

Last year, Obscura was erroneously blocked by a few US ISPs, and SNI was exactly what they used. Of course, using a VPN protects you against that, but it's still quite cursed that TLS has this at all. Hopefully Encrypted Client Hello gets adopted soon so that we can have actual secure TLS!


Whether Obscura's split-trust model is right for you is up to you to decide, but it's definitely a different approach to a problem the VPN world has glossed over for years. The client is open source, so you don't have to take any of this on faith. You can read the code, check your exit hop's key against Mullvad's published list, and verify the claims yourself.

You can learn more at obscura.com, and the source is up on GitHub.



from It's FOSS https://ift.tt/bUS7XtK
via IFTTT

Kamis, 01 Oktober 2026

YT-DLP is Being Treated as a Piracy Tool By The IFPI

yt-dlp has over 195,000 stars on GitHub, supports thousands of platforms, and is actively maintained by a global developer community. Unfortunately, the IFPI would like to see it on the EU's piracy watchlist.

Just so you know, the International Federation of the Phonographic Industry (IFPI) represents around 8,000 music labels across 70 countries.

In its submission to the EU's Counterfeit and Piracy Watch List consultation, the group calls yt-dlp "a major problem for the music industry" and names four of its maintainers by their GitHub handles.

A Piracy Watch List?

eu's public consultation on the counterfeit and piracy watch list webpage showing some key details

Run by the European Commission's Directorate-General for Trade and Economic Security, the Watch List identifies online services and physical marketplaces outside the EU reported to engage in or facilitate copyright infringement.

While it sounds serious, the undertaking isn't meant to gather legal findings and does not mandate any form of direct action. It's closer to a naming exercise intended to pressure operators and governments outside the EU into addressing the identified services.

The 2027 edition is being compiled from submissions received through September 2026, with the final list expected in Q2 2027.

What does their submission say?

IFPI's submission covers a wide range of copyright enforcement concerns, from AI music generators and cyberlockers to streaming fraud services and domain registrars. yt-dlp appears under the "stream ripping" section, grouped with commercial websites like Y2mate and Savefrom.

They describe the tool as an application that retrieves content by parsing web page data and interacting with platform playback endpoints, with GitHub serving as the primary delivery method for its source code, pre-compiled binaries, and installation instructions.

IFPI names four of the project's maintainers by their GitHub handles: pukkandan, who founded the project and led it between 2021 and 2024, and some core maintainers mentioned in the project's Maintainers.md file, like coletdjnz, bashonly, and Grub4K.

The same submission also flags X, Discord, Telegram, and Vimeo as platforms facilitating copyright infringement at scale.

It's a tool, not a service

the yt-dlp github repo

The Watch List, as described by the European Commission, targets online service providers and physical marketplaces located outside the EU. yt-dlp fits neither description in any conventional sense.

IFPI acknowledges this by noting that the project's open source nature, its Unlicense licensing, and an extensive international developer community make it "difficult to contain and/or remove."

From their point of view, there's no central domain to block, no payment processor to cut off, and no hosting provider to strongarm into complying with a takedown request.

The source code is distributed globally and can be compiled by anyone with the skills to do so. But that doesn't mean yt-dlp is a piracy platform.

It's a command-line tool for downloading audio and video content, and categorizing it alongside dedicated ripping or piracy websites conflates a general-purpose downloader with services whose primary purpose is facilitating unauthorized copying.

Closing thoughts

The Watch List has been used in connection with enforcement against commercial stream-ripping platforms before.

Y2mate.com and eleven other stream-ripping sites were shut down in Vietnam in 2025, and Y2mate had previously appeared on the list.

Before that, in 2024, a German court held the host provider for youtube-dl.org liable in connection with facilitating circumvention. This shows that grouping an open source command-line tool with those commercial services in the same breath does not, by itself, make the tool one of those.

Via: TorrentFreak



from It's FOSS https://ift.tt/4dlrbqc
via IFTTT

FOSS Weekly #26.40: NixOS is European Choice, Firefox Nova and Features, Free Terminal Course, Homelab Improvements and More

FOSS Weekly

Canonical is moving Ubuntu's kernel update cycle from four weeks to two, with the expected result being a kernel release landing every week due to cycle overlap. They did this because AI-assisted vulnerability hunting is causing CVEs to land faster than the old timeline could respond to.

They have also enabled upgrades from Ubuntu 24.04 LTS to Ubuntu 26.04.1. And the delayed beta release of Ubuntu 26.10 should arrive today.

AlmaLinux now has software certification, which means publishers can list products and users can confirm what runs on their hardware, with everything going into a public catalog with a free read-only API facilitating bulk data export.

GhostBSD's lead developer is building a new desktop called Mocka to eventually replace MATE. It is built from scratch with no shared code from the MATE project, and the name comes from a typo.

postmarketOS is now Nura. The rename has been in the works since March 2025, drew over 300 community submissions, and went through a trademark review and a vote before it was finalized. On the same note, F-Droid has a major revamp. In case you did not know, F-Droid is the FOSS alternative to Google Play Store.

openSUSE is consolidating its distro lineup. Leap Micro, the separate immutable flavor for container and edge workloads, is going away, and Leap 16.1 absorbs its functionality via an optional installer mode.

This edition of FOSS Weekly is supported by Dawarich, an open source alternative to Google Timeline.

Dawarich is a private alternative to Google Timeline.

Google killed browser Timeline and is limiting data retention. You can import your entire location history into Dawarich in minutes. It is private and encrypted. No ads. No data selling.

It is open source and can also be self-hosted. Or, you can opt for their encrypted service.

Try Dawarich Today

🧠 What We’re Thinking About

The Netherlands is building a NixOS-powered work environment after watching Microsoft cut off ICC access in 2025. Though it turns out France's digital agency had beat them to it, already running their own version of NixOS on internal workstations.

🐧 Tuxdle is rising

Last week I shared my weekend project, Tuxdle. It's a word game where you have to guess the Linux term within six attempts. The game has gained good popularity. We are getting more than 500 plays every day. A good number for a game that is less than a week old.

I have made some enhancements to the game. You can see your stats and you can also see stats on the day's puzzle. That tells you how many people played the game and how many people actually solved it. Streak badges have also been added.

Want more fun and challenges? On Linux Handbook, we have created a fun Capture the Flag game. You have 10 levels to solve. When you solve a level, the next level gets unlocked. The challenges run in custom docker containers. Everything on your system really. No sign up is needed.

🧮 Linux Tips, Tutorials, and Learnings

I am also enhancing the user experience on the It's FOSS website. One of the first things I did was organize the series/courses in a proper format.

If you visit the terminal course or bash scripting course, you will see the chapters in the series in the left sidebar. This will give you easier navigation.

There are many Linux distros that don't provide a dock by default, and if you want one, there's no dearth of options: Latte for KDE users, Cairo for old-school animations, and Dash to Dock for GNOME users; there's something for every taste and desktop setup.

You've seen "upstream" and "downstream" in patch notes, bug trackers, and forum replies without it ever being fully explained. We have already tackled what the terms actually mean, both for the kernel and for applications, and why it matters when you're deciding where to file a bug report.

👷 AI, Homelab and Hardware Corner

One of the biggest annoyances of homelab is accessing services by using IP address and port number. I fixed this by giving a custom domain name to every service I run. I used AdGuard as DNS and Nginx Proxy Manager for reverse proxy. And the end result is that I can use Jellyfin by typing jellyfin.internal instead of typing 192.168.0.23:8097.

Most SBC projects end with your drawer filling up with HATs for different use cases. Vicharak's Axon-Lite tries a different approach where it offers swappable interface modules for voice, vision, sensing, and AI data.

✨ Apps and Projects Highlights

Firefox's Nova redesign is finally here, and it looks good! There's also a neat toggle for anyone who doesn't prefer it's pill-shapedness.

📽️ Videos for You

And here's 21 useful Firefox features to give you a reminder why this browser keeps coming back, even after the wrong turns it has taken these past few years.

💡 Quick Handy Tip

0:00
/0:16

In KDE Plasma, you can copy a wide range of time/date formats to the clipboard by right-clicking on the Clock widget in the panel.

All you have to do is right-click on the digital clock in the panel, hover your mouse cursor over the "Copy to Clipboard" option, and click on the format you want copied.

Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content.

If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.

Join It's FOSS Plus

🎋 Fun in the FOSSverse

Sharpen your networking command knowledge by completing this crossword!

Linux is for power users. 💪

linux sudo meme

🗓️ Tech Trivia: On September 27, 1983, Richard Stallman announced the GNU Project, an effort to build a completely free Unix-compatible operating system. It helped spark the free software movement and popularize copyleft through the GPL, shaping how software is shared, modified, and built collaboratively.

🧑‍🤝‍🧑 From the Community: Neville is making the case for small, well-written programs; do you have an opposing view to present?



from It's FOSS https://ift.tt/YE2FRXz
via IFTTT