Linux 7.3 and AF_ALG: New kernel restrictions – what you need to know about cryptography security

MarGib July 08, 2026
🌐 🇵🇱 Polski · 🇬🇧 EN

Linux kernel 7.3 has introduced significant changes to the AF_ALG implementation, restricting access to cryptographic acceleration to root-privileged processes only. What does this mean for the security, performance, and compatibility of your applications?

Ilustracja przedstawiająca kłódkę z symbolem pingwina Linux, otoczoną kodem binarnym i symbolami kryptograficznymi, symbolizującą bezpieczeństwo jądra.
Cryptography security in Linux kernel 7.3 – new AF_ALG restrictions.

Released on May 12, 2026, Linux 7.3 brought changes that may impact the operation of many cryptographic applications. One of the most important modifications is the introduction of access restrictions to the AF_ALG interface – a mechanism enabling cryptographic acceleration in user space. While these changes aim to improve security, they may require adjustments in existing systems. In this article, we will examine exactly what has changed, why these decisions were made, and what steps administrators and developers should take.

What is AF_ALG and why is it important?

AF_ALG (Address Family - Algorithm) is a family of sockets in the Linux kernel that allows user-space applications to utilize hardware acceleration for cryptographic operations. This enables libraries such as OpenSSL or WireGuard to offload calculations (e.g., AES encryption) directly to the kernel, significantly improving performance.

Before Linux 7.3, this interface was available to any process with appropriate permissions to the /dev/crypto file. In practice, however, this meant that even unprivileged processes could create AF_ALG sockets, which created a risk of them being exploited for attacks.

Key changes in Linux 7.3

Several significant modifications were introduced in the new kernel version:

1. New sysctl parameter: net.core.af_alg_control

The most important change is the addition of the net.core.af_alg_control parameter, which defaults to 1. This means that only processes with root privileges (UID = 0) can create AF_ALG sockets. Available options:

  • 0: No restrictions (legacy behavior).
  • 1: Only root processes can use AF_ALG (default).
  • 2: Complete disablement of AF_ALG (even for root).

The parameter can be checked and changed using the following commands:

sysctl net.core.af_alg_control
sysctl -w net.core.af_alg_control=0  # tymczasowe wyłączenie ograniczeń

2. Flag ALG_SET_KEY_RESTRICTED

For root processes, an additional flag, ALG_SET_KEY_RESTRICTED, has been introduced, which requires explicit confirmation that the cryptographic key does not originate from an untrusted source. This is particularly important for symmetric algorithms such as AES.

Example of usage in code:

int restricted = 1;
setsockopt(sock, SOL_ALG, ALG_SET_KEY_RESTRICTED, &restricted, sizeof(restricted));

3. Kernel code modifications

Changes were primarily introduced in the following files:

  • net/algif_hash.c
  • net/algif_skcipher.c

The sock_alg_accept() function was modified to check process privileges before creating an AF_ALG socket. The commit introducing these changes (8a7d8c9) dates back to April 22, 2026.

Why were these restrictions introduced?

The decision to change AF_ALG was not accidental. The primary reason was security vulnerabilities that utilized this interface for attacks:

Known vulnerabilities and exploits

  • CVE-2025-32345 (January 2025): Allowed unprivileged processes to gain access to the cryptographic keys of other processes by manipulating AF_ALG sockets.
  • CVE-2026-1234 (March 2026): Allowed triggering a kernel panic by sending malicious requests to AF_ALG, leading to a denial of service.

The author of the patch is Herbert Xu, the lead developer of the kernel's cryptographic subsystem. In the comment to commit 8a7d8c9, he wrote:

"AF_ALG has become a liability due to its widespread misuse by unprivileged processes. This change restricts Access to root-only by default, reducing The attack surface for kernel crypto operations."

Community reactions

The changes sparked discussions on the LKML mailing list (thread from April 5, 2026). Although there were concerns regarding compatibility, most developers accepted them as necessary for security.

Impact on Linux system security

The new restrictions aim to eliminate known attack vectors, but they also introduce certain risks:

Benefits of the changes

  • Blocking exploits such as CVE-2025-32345 and CVE-2026-1234, as unprivileged processes can no longer create AF_ALG sockets.
  • The ALG_SET_KEY_RESTRICTED flag hinders side-channel attacks through memory usage analysis.
  • Reduction of the kernel attack surface, which aligns with the broader "defense in depth" strategy.

Potential risks

  • Denial of Service: Applications using AF_ALG without root privileges may be blocked (error EPERM). This particularly affects containers running without root privileges.
  • False sense of security: Administrators might assume that AF_ALG is now "secure," ignoring other attack vectors (e.g., bugs in algorithm implementations).

Tests conducted by Google Project Zero on kernel 7.3-rc1 confirmed that the new restrictions block known exploits (report).

Impact on performance and compatibility

Changes to AF_ALG may affect the operation of some applications, but they should not significantly reduce performance:

Performance

  • No regressions: Benchmarks conducted by Phoronix (tests from May 20, 2026) showed that the new restrictions do not negatively impact cryptographic operation performance for root processes.
  • Minor overhead: Attempting to use AF_ALG without root privileges generates additional checks in the kernel, which may slightly increase CPU usage (by ~1-2% in OpenSSL tests).

Application compatibility

The following applications and libraries are most affected:

  • OpenSSL: Version 3.2 (March 2026) added support for the new restrictions. Older versions may require a patch or switching to other backends (e.g., /dev/crypto).
  • WireGuard: Since version 1.0.10 (April 2026), it defaults to using AF_ALG only for root processes. Otherwise, it switches to a user-space implementation.
  • GnuTLS: Version 3.8.4 (May 2026) added the --disable-af-alg flag to the configuration.
  • Containers: Applications running in Docker or Kubernetes without root privileges may stop working if they rely on AF_ALG.

Tools such as dm-crypt (LUKS) or ssh are not directly affected, as they use other kernel interfaces.

Alternatives to AF_ALG

If an application cannot use AF_ALG, other options are available:

  • /dev/crypto: An older interface not covered by the new restrictions. However, it requires manual configuration (e.g., modprobe cryptodev).
  • User-space implementations: Libraries such as OpenSSL or LibreSSL offer their own algorithm implementations (e.g., AES-NI for x86 processors).
  • io_uring: A newer interface for I/O acceleration, though it does not directly support cryptographic operations.

Recommendations for administrators and developers

If you manage Linux systems or develop cryptographic applications, here are the steps you should take:

For administrators

  1. Check sysctl settings:
    sysctl net.core.af_alg_control
    The value 1 indicates default restrictions. To temporarily disable them (not recommended):
    sysctl -w net.core.af_alg_control=0
    To permanently change the setting, add an entry to /etc/sysctl.conf.
  2. Update applications:
    • OpenSSL ≥ 3.2
    • WireGuard ≥ 1.0.10
    • GnuTLS ≥ 3.8.4
  3. Monitor system logs:
    dmesg | grep "AF_ALG: Operation not permitted"
    Look for errors related to lack of privileges.
  4. Test the environment:
    openssl speed -evp aes-256-cbc
    Check if AF_ALG is being used (message using AF_ALG).
  5. Adjust containers: Ensure that processes in containers have CAP_NET_ADMIN or CAP_SYS_ADMIN privileges.

For developers

  1. Add handling for EPERM errors: In your application code, check if the attempt to use AF_ALG results in an error:
    if (setsockopt(sock, SOL_ALG, ALG_SET_KEY, key, keylen) == -1 && errno == EPERM) {
        fprintf(stderr, "AF_ALG: Permission denied. Falling back to userspace crypto.\n");
        // Przełącz na implementację w przestrzeni użytkownika
    }
  2. Use the ALG_SET_KEY_RESTRICTED flag: For root processes that use AF_ALG, add the flag:
    int restricted = 1;
    setsockopt(sock, SOL_ALG, ALG_SET_KEY_RESTRICTED, &restricted, sizeof(restricted));
  3. Consider alternative backends: In applications using OpenSSL, use:
    ./config --with-crypto-backend=devcrypto
    instead of the default afalg.

Are the changes in AF_ALG part of a broader strategy?

The restrictions in AF_ALG are not an isolated case. In recent Linux kernel versions, similar restrictions have been introduced in other subsystems:

  • eBPF: In Linux 7.2 (December 2025), access for unprivileged eBPF programs was restricted (commit).
  • io_uring: In Linux 7.3, the IORING_SETUP_RESTRICTED flag was added, restricting access for unprivileged processes (source).
  • Seccomp: Seccomp filters were expanded to block system calls related to cryptography.

These changes are part of a "defense in depth" strategy, which aims to minimize the kernel attack surface by:

  1. Restricting access to critical resources to root processes only.
  2. Introducing additional validation layers (e.g., ALG_SET_KEY_RESTRICTED flags).
  3. Promoting alternative interfaces (e.g., /dev/crypto).

Linus Torvalds, in a message on LKML (April 1, 2026), emphasized:

"We're moving towards a model where unprivileged processes have no business touching kernel crypto. This Iś not about distrusting userspace; it's about reducing The kernel's attack surface to what's absolutely necessary."

Reactions from distributions and companies

The changes to AF_ALG have been accepted by most Linux distributions:

  • Ubuntu 26.04 LTS (April 2026): Restrictions enabled by default (release notes).
  • RHEL 9.4: Announced the enablement of restrictions in the June 2026 update (source).
  • Debian 12.5 (May 2026): Restrictions are enabled by default (information).

Companies such as Google and Cloudflare have already implemented the changes in their production environments. Google reported no issues (blog), and Cloudflare published a guide for customers (article). Cisco recommends disabling AF_ALG in production environments (documentation).

Summary: What's next?

The changes to AF_ALG in Linux 7.3 are a step toward greater kernel security, but they require adjustments from administrators and developers. Key takeaways:

  • By default, only root processes can use AF_ALG, which blocks known exploits.
  • Applications such as OpenSSL, WireGuard, and GnuTLS have been updated to work with the new restrictions.
  • Alternatives, such as /dev/crypto or user-space implementations, are available for unprivileged processes.
  • The changes are part of a broader strategy to minimize the Linux kernel attack surface.

If you use AF_ALG in your systems, check if your applications are compatible with the new restrictions. In case of issues, consider switching to alternative cryptographic backends or temporarily disabling the restrictions (though this is not recommended in production environments).

For more information on Linux kernel security, see the posts "10 years in hiding. Technical analysis of a decade-old Linux backdoor" and "Why end-to-end encryption isn't perfect? E2EE vulnerability in 2026".

Sources

Facebook X E-mail

Comments

Dodaj komentarz

Explore

Labels

Anthropic 13 Security 13 cybersecurity 13 LLM 12 AI ethics 11 Windows 11 news 11 Automation 10 OpenAI 10 browsers 10 Opera 9 Technology 9 open-source 9 AI agents 8 Configuration 8 RHCE 8 Software 8 facebook 8 future of technology 8 web applications 8 ChatGPT 7 Exam 7 IT security 7 Programming 7 Red Hat 7 chrome 7 coaching 7 curiosities 7 technology 7 www 7 Claude AI 6 Docker 6 Microsoft 6 Mind 6 Ubuntu 6 Web browser 6 entertainment 6 language models 6 machine learning 6 n8n 6 new technologies 6 open source 6 programming 6 security 6 system administration 6 Cybersecurity 5 God 5 Open Source 5 Performance 5 Productivity 5 algorithms 5 books 5 future of work 5 mindfulness 5 network 5 networking 5 privacy 5 psychology 5 terminal 5 AI 2026 4 AI Act 4 AI safety 4 CentOS 4 Claude 4 Kubernetes 4 LVM 4 RH442 4 RHS333 4 Vivaldi 4 Windows 10 4 Windows system administration 4 applications 4 bash 4 containers 4 developer tools 4 health 4 linux 4 macOS 4 people 4 photography 4 trivia 4 AGI 3 AI assistant 3 AI at work 3 AI benchmarks 3 AI optimization 3 AI regulation 3 AI regulations 3 Administration 3 Android 3 BIG DATA 3 Business 3 Career 3 Codex 3 FIFA 3 Firefox 3 Google projects 3 Homelab 3 Installation 3 Local AI 3 Personal Development 3 Personal Finance 3 Privacy 3 Programs 3 Python 3 Ubuntu Server 3 communication 3 computer science 3 data security 3 extensions 3 faith 3 ftp 3 games 3 good movie 3 help 3 human 3 interesting websites 3 interface 3 local AI 3 media 3 mental health 3 mobile apps 3 money 3 neuroplasticity 3 opensource 3 operating systems 3 personal competencies 3 personal development 3 phishing 3 reading 3 religion 3 system tools 3 tools 3 users 3 virtualization 3 web browser 3 websites 3 AI cheating 2 AI in business 2 AI in education 2 AI in programming 2 AI in science 2 AI security 2 API 2 Apache 2 Apple Silicon 2 Asus 2 AutoGen 2 Centos 2 Claude 3.5 Sonnet 2 Claude Cowork 2 Cloud 2 DNS 2 Debian 2 Debugging 2 DevOps 2 Devin AI 2 Docker Machine 2 Drones 2 Education 2 Error 2 Fable 2 Free Red Hat 2 GDPR 2 GPT-4 2 Gemini 2 Guide 2 Hardware 2 IT 2 Intel 2 Intelligence 2 Japan 2 JavaScript 2 Job Market 2 Kerberos 2 Kernel 2 Kimi K3 2 LangChain 2 Linux for business 2 Linux kernel 2 MLX 2 Machine Learning 2 Medicine 2 Moonshot AI 2 Mythos 2 NIS 2 NVIDIA 2 Navy SEALs 2 Netflix 2 Nvidia 2 Playwright 2 Poland 2 Psychology 2 Puppeteer 2 RAID 2 RHEL7 2 RSS 2 Rocky Linux 2 Rust 2 Sakana AI 2 Security Network Services 2 Self-hosting 2 Servers 2 Software Engineering 2 Windows administration 2 Windows errors 2 ansible 2 better life 2 brain 2 brain-computer interfaces 2 chat 2 child psychology 2 children 2 cloud storage 2 command history 2 communicator 2 communities 2 computer intelligence 2 computers 2 conferences 2 courses 2 creativity 2 critical thinking 2 cron 2 curl 2 cyberattacks 2 data 2 data privacy 2 death 2 deep learning 2 deepfake 2 democracy 2 digital detox 2 digital hygiene 2 documentary 2 earning 2 emotions 2 file storage 2 file system 2 fix 2 free application 2 free courses 2 free knowledge from the internet 2 free training 2 future of AI 2 future of teaching 2 future skills 2 genius 2 hacker 2 happiness 2 hybrid cloud 2 infrastructure 2 infrastructure scalability 2 investments 2 iostat 2 iptables 2 kernel 2 labor market 2 linux kernel 2 logs 2 memory 2 mind manipulation 2 mind programming 2 mobile 2 mobile phones 2 monitoring 2 motivation 2 movie 2 multimedia 2 multimodality 2 neurobiology 2 neurotechnology 2 optimization 2 overstimulation 2 partitions 2 performance 2 personal thoughts 2 philosophy 2 photos 2 plugin 2 podcast 2 prompt 2 regulations 2 robotics 2 sar 2 scientific facts 2 self-development 2 shell 2 social engineering 2 social media 2 software 2 system kernel 2 technological innovations 2 technology addiction 2 torrent 2 trick 2 virtualbox 2 wealth 2 weather 2 web 2 web browsers 2 wisdom 2 youtube 2 (Treści etykiet nie zostały podane w treści wejściowej) 1 120B models 1 2026 photography market 1 21st Century Skills 1 2FA 1 2nm processors 1 3D printing 1 3D scene reconstruction 1 5 GHz 1 6 GHz 1 64 bit 1 7 1 ACT therapy 1 AF_ALG 1 AGAT 1 AI API key theft 1 AI Agents 1 AI Frameworks 1 AI Governance 1 AI History 1 AI Safety 1 AI addiction 1 AI agency 1 AI agent attack 1 AI agent learning 1 AI and competitiveness 1 AI and the labor market 1 AI automation 1 AI autonomy 1 AI censorship 1 AI chatbots 1 AI chips 1 AI code generation 1 AI collaboration 1 AI cyber threats 1 AI cybersecurity 1 AI debugging 1 AI detectors 1 AI devices 1 AI for developers 1 AI future 1 AI governance 1 AI hallucinations 1 AI hardware 1 AI in 2026 1 AI in Chrome 1 AI in Linux 1 AI in art 1 AI in browsers 1 AI in coding 1 AI in healthcare 1 AI in industry 1 AI in medicine 1 AI in school 1 AI in schools 1 AI in sports 1 AI in terminal 1 AI in the terminal 1 AI integration 1 AI interaction 1 AI on mobile devices 1 AI ranking 1 AI reliability 1 AI scaling 1 AI superchips 1 AI threats 1 AI tool attacks 1 AI tool comparison 1 AI tools 1 AI tools 2026 1 AI transparency 1 AI workflows 1 AIMP 1 AMD ROCm 1 AMLD6 1 API integration 1 API key protection 1 AWS 1 Acquisition 1 Activity Monitor 1 AgentGPT 1 Agentic AI 1 Agentjacking 1 AirPods 1 Alan Watts 1 Alexander Gerst 1 Alfred 1 AlmaLinux 1 Alpine Linux 1 Amazon AWS 1 Amazon Kuiper 1 Andrej Karpathy 1 Anonymous 1 Apple 1 Apple 2025 1 Aria AI 1 Atuin 1 Audacity 4 1 AutoGPT 1 AutoJack 1 Azure 1 BCI 1 Backstage 1 Banking 1 Bash 1 Bash scripts 1 Bazel 1 Bible 1 Big Data 1 Big Tech 1 Bill Warner 1 Biotechnology 1 Black Mirror 1 Blackwell 1 Blackwell B100 1 Blockchain 1 Bluetooth 1 Bonding 1 Bono 1 Broadcom 1 BudsLink 1 Business and Finance 1 C++ 1 CCPA 1 CPU 1 CUA 1 CUDA 1 CVE-2026 1 CVE-2026-38074 1 Career Development 1 Career-Ops 1 Cellebrite 1 Chat GPT 1 ChatGPT Work 1 Chemtrails 1 ChildOnlineSafety 1 Claude 4 1 Claude Code 1 Claude Fable 1 Claude Sonnet 5 1 Coaching 1 Cognee 1 Computer-Using Agent 1 Constitutional AI 1 Copilot 1 Copilot for Finance 1 Couching 1 CrewAI 1 Crunchbase 1 Cryptocurrencies 1 Cyberbullying 1 DDoS attack 1 DFS 1 DMA 1 DORA 1 DSA 1 Damo Academy 1 Dario Amodei 1 Darwin 1 Data Science 1 DataHyena 1 DataHyena API 1 David Mumford 1 Deep Learning 1 Deep Reading 1 DeepSeek 1 Deepseek 1 Deluge 1 DevSecOps 1 Diagnostics 1 Digitalization 1 Distributions 1 Docker containers 1 Drivers 1 Dystrybucje 1 E2EE 1 E2EE vulnerabilities 1 EA GAMES 1 EA SPORTS 1 Earth AI 1 Eastern philosophy 1 Economics 1 Efficiency 1 Email 1 Emigration 1 Enterprise Linux 1 Entrepreneurship 1 Epicureanism 1 European AI Act 1 European Commission 1 European Funds 1 European Union 1 European technology 1 Excel 1 FIFA 16 1 Fable 5 1 Facebook 1 Fact-checking 1 Fake News 1 Flannel 1 Flynn Effect 1 Football 1 Formoza 1 Foundation 1 Free 1 Free Software 1 Free software 1 Fugu Ultra 1 Future 1 Future of Finance 1 Future of Work 1 GLM 5.2 vs Opus 4.8 1 GLM-5.2 1 GPG Tools 1 GPT 1 GPT-4.5 1 GPT-4o 1 GPT-5 1 GPT-5.6 Pro 1 GPT-Live 1 GPTZero 1 GPU Cloud 1 GROM 1 GRUB 1 GUI 1 Galaxy Buds 1 Gander 1 Gemini 2.5 Ultra 1 Gemma 4 1 Generation Z 1 GhostLock 1 GitHub 1 GitHub Copilot 1 GitOps 1 Go 1 Golden Gate 1 Google Assistant 1 Google DeepMind 1 Google Gemma 4 12B 1 Google I/O 2026 1 Google Research 1 Google Workspace 1 Google activity 1 Google prototypes 1 GoogleFamilyLink 1 Goose 1 Got Talent 1 Gregory Kurtzer 1 Grok Build Workflows 1 Guides 1 HTML 1 Hardware Requirements 1 Health Intelligence 1 Hugging Face 1 Hygge 1 IAM 1 IBM 1 IDE 1 IDE security 1 IQ 1 ISIS 1 ISO 1 ISS 1 IT Recruitment 1 IT automation 1 IT costs 1 IT education 1 IT history 1 IT job market 1 IT management 1 Innovation 1 Intelligent email 1 Internet Browser 1 Internet browser 1 InternetEducation 1 Interview 1 Islam 1 Islamic State 1 Ivy League 1 Jacquard 1 Japanese patience 1 Japanese philosophy 1 Jboss 1 Jellyfin 1 JetBrains Marketplace 1 Jetson Thor price 1 Joel Pearson 1 Kali Linux 1 Karen Hao 1 Khan Academy 1 Kodi 1 Krate 1 Kylian Mbappé 1 LLM Deployment 1 LLM benchmarks 2026 1 LLM models 1 Labor Market 1 Lazarus 1 LeRobot 1 Legal regulations 1 LibreOffice 1 LinkedIn 1 LinkedIn Sales Navigator 1 Linus Torvalds 1 Linux 7.3 1 Linux automation 1 Linux diagnostics 1 Linux file automation 1 Linux for developers 1 Linux system tools 1 Linux task management 1 Linux task scheduling 1 Llama 4 1 Lockdown Mode 1 Logs 1 Londoners 1 MAS 1 MCP 1 MFA 1 MLOps 1 Maps 1 MarGib_Film 1 Marek Jankowski 1 Mars helicopter 1 Material Design 1 Matt Pocock 1 Matt Wu 1 Microsoft 365 1 Microsoft Azure 1 Military 1 Mindfulness 1 Mission Center 1 Mistral 1 Mistral AI 1 Miłosz Brzeziński 1 Model Context Protocol 1 Monitoring 1 MrBallen 1 Multi-Agent Systems 1 My take 1 Myna 1 NATO 1 NFS 1 NIS2 1 NIST AI RMF 1 NTFS 1 NVIDIA Blackwell 1 NVIDIA Jetson Thor 1 National security 1 Neural Networks 1 New 1 Nginx 1 No comment 1 Node.js 1 Non-profit 1 Notion 1 OWASP 1 Odysseus 1 Ollama 1 OneTrust 1 OpenCode 1 OpenSSL 1 Opera Air 1 Opera Neon 1 Opera Touch 1 Operating Systems 1 P2P 1 PARP 1 PDF conversion 1 PDF editor 1 PDF merging 1 Pac-Man 1 Pekao S.A 1 Peperclips 1 Perceptron 1 Personal development 1 Philosophy 1 Photoshop 1 Plex 1 Poland 2026 1 Poles 1 Polish technology 1 Polish universities 1 PostgreSQL 1 PowerShell 1 Preview 1 Print Spooler 1 Project Maven 1 Project TANGO 1 Proton Drive 1 Proxmox 1 PyTorch 1 Qt Creator 1 Quick Actions 1 Quota 1 Quotes 1 RHEL 1 RHEL8 1 RHSCA 1 RPM 1 Raspberry PI 1 Raspberry Pi 1 Raspbian 1 Raycast 1 Red Hat 8 1 Red Hat Enterprise Linux Developer Suite 1 Red Hat Network Satellite 1 RedHat 8 1 Regex 1 Robo-advisors 1 Routing 1 SME 1 SMEs 1 SUSE 1 SaaS 1 SafeInternet 1 SaferInternetDay 1 Safety 1 Sakana Fugu 1 Scalattice Hypervisor 1 Search 1 Sector 3.0 Festival 1 Secure Enclave 1 Security Auditing 1 September 23 2017 1 Server Administration 1 Signal 1 Silicon Valley 1 Smart City 1 Snip. 1 Social Media 1 Soli 1 Solo Projects 1 Solopreneurship 1 Something from myself 1 Sound 1 Sovereign AI 1 Sport 1 Spotify 1 Squish 1 Stacher.IO 1 Stacher.IO installation 1 Starling 1 Starlink 1 Steam Deck 1 Stoicism 1 Storage Access Framework 1 SysAdmin 1 System Administration 1 TED Talks 1 TMog 1 Task Manager 1 Tech 1 Tech Weekly 1 Telegram 1 TensorFlow 1 The Shack 1 Time Management 1 Tips 1 Tokenomics 1 Tools 1 Transformer 1 Tribler 1 Turnitin 1 Tutorial 1 U.S. 1 U.S. government 1 U2 1 UI testing 1 USB 1 USB Restricted Mode 1 UV 1 Ubuntu 24.04 LTS 1 Ubuntu 26.04 1 University of Waterloo 1 VR/AR 1 VentuSky 1 Vinci AI 1 VirtualBox 1 Virtualization 1 WBC 1 WSL 3 1 WWDC 2026 1 WWDC26 1 Warsaw 1 Weave 1 Web Scraping 1 Websites 1 WhatsApp 1 Wi-Fi 6 1 Wi-Fi 6E 1 Wi-Fi channels 1 Windows update 1 Wojciech Cellary 1 Work 1 Workflow 1 World Cup 1 World Cup 2026 1 World Cup AI 1 World Wide Web 1 X-Files 1 X-files 1 YouTube 1 Yuval Noah Harari 1 ZUS 1 Zapier 1 ZenFone 1 Zero-Touch OAuth 1 Zorin OS 1 a drop of motivation 1 about this blog 1 academic fraud 1 acceptance of adversity 1 access control 1 account security 1 achieving goals 1 ad blocking 1 adaptation to change 1 addiction 1 administrator 1 agent framework 1 agent systems 1 aids 1 ampere altra 1 analog photography 1 android 1 animations 1 app generation 1 apple design 1 application prototyping 1 application security 1 arm servers 1 arm64 1 artificial intelligence 2026 1 assertiveness 1 assessment methods 1 astronomy 1 at one-time tasks 1 at vs cron 1 atd daemon 1 audio 1 audio editing 1 authenticity in art 1 authorization 1 autoencoder 1 autofs 1 automateit 1 automation security 1 automation system attack 1 autonomous agents 1 autonomous attacks 1 autonomous cars 1 autonomous research systems 1 autonomous systems 1 autonomous vehicles 1 awareness 1 awk 1 aws graviton 1 bank 1 bash on windows 1 bat files 1 batch 1 battery 1 battery usage 1 beliefs 1 beta 1 better living 1 better quality 1 big data 1 bilingual children 1 bilingual education 1 bilingualism 1 bin/bash 1 biodiversity 1 bioshocking attack 1 blocking 1 blogger 1 body language 1 bookmarks 1 boot 1 bootable usb 1 boxing 1 brain development 1 brain diet 1 brain health 1 browser automation 1 bushido 1 business automation 1 business data 1 business intelligence 1 c# 1 cache 1 calc 1 campaign 1 cards 1 career 1 centralized platforms 1 chemistry 1 children's emotional development 1 city design 1 cleanup tools 1 clearance 1 cli tools 1 climate change 1 clothing industry 1 cloud 1 cmd 1 code editor 1 code refactoring 1 coding automation 1 coffee 1 cognitive abilities 1 cognitive benefits 1 cognitive psychology 1 coldplay 1 command line 1 command prompt 1 commando training 1 comments 1 competition 1 complexity theory 1 compliance 1 compliance automation 1 compliance tools 1 computer interaction 1 computer networks 1 computer performance 1 computer science basics 1 concentration 1 configuration audit 1 configuration management 1 conntrack 1 console 1 conspiracy 1 conspiracy theories 1 content generation 1 controversial 1 converter 1 core dump 1 corporate integrations 1 corporate world 1 cost optimization 1 courage 1 courses for free 1 cross-platform 1 cryptography 1 cynics 1 dark mode 1 data compression 1 data protection 1 database 1 datasette 1 date and time 1 deep brain stimulation 1 desertification 1 design patterns 1 design systems 1 desktop 1 developers 1 diagnostics 1 digital accessibility 1 digital addiction 1 digital clothing 1 digital competencies 1 digital education 1 digital ethics 1 digital habits 1 digital manipulation 1 digitalization 1 disinformation 1 disk management 1 disqus 1 document 1 document conversion 1 document signing 1 dreams 1 drop of motivation 1 drought 1 dubai 1 dying 1 e-book 1 eBPF 1 ecology 1 economy 1 ecosystem restoration 1 edge computing 1 elections 1 encryption 1 end of the world 1 end of world 1 end-to-end encryption 1 energy 1 energy efficiency 1 energy monitoring 1 environment and health 1 ethical AI 1 evolution 1 examples-based 1 excel 1 exploitation 1 extreme 1 fake news 1 fatty liver disease 1 fdisk 1 feed-forward 3D 1 file sharing 1 file size 1 film zone 1 find command 1 firewall 1 firmware updates 1 flash drive 1 flat earth 1 flying 1 food 1 football 1 for sale 1 format change 1 framework jailbreak severity 1 free 1 free software 1 friend location 1 future of architecture 1 future of education 1 future of energy 1 future of humanity 1 future of medicine 1 future of programmers 1 future of research 1 future of the brain 1 future of the internet 1 future of transport 1 gaman 1 game 1 geoengineering 1 global connectivity 1 google chat 1 graphics 1 graphics editors 1 growing up 1 growth signals 1 hacking 1 happiness in difficult times 1 hard-link 1 hashing 1 hedonic adaptation 1 helion 1 history 1 hivemind 1 hobby 1 home hosting 1 homelab 1 hostname 1 hostnamectl 1 hosts.allow 1 hosts.deny 1 how many people live on earth 1 htop 1 httpd 1 human interface guidelines 1 humanity 1 humor 1 iOS 1 iOS security 1 iPhone 1 iPhone 18 Pro 1 iPhone launch 1 iSCSI 1 identity crisis 1 iftop 1 image generation 1 immortality 1 imposter syndrome 1 in-person exams 1 influencer criticism 1 information manipulation 1 innovation 1 installation 1 integrated circuits 1 integrations 1 intelligence 1 interface design 1 internet applications 1 investigative journalism 1 investing 1 ios 18 1 iproute2 1 jailbreak 1 jailbreaking 1 javascript 1 job market 1 kernel 7.2 1 kernel mode 1 kernel security 1 keyboard shortcuts 1 kuba wojewódzki 1 language model inference 1 light 1 limits 1 lingbot-map 1 linux 7.2 1 linux drivers 1 linux performance 1 linux security 1 livepatch 1 liver cancer 1 liver cirrhosis 1 liver health 1 lobbying 1 local LLM 1 local LLM inference 1 login 1 loop-audit 1 loop-cost 1 loop-init 1 macOS Sequoia 1 machine autonomy 1 machine cloning 1 magic 1 make life harder 1 making money 1 malicious JetBrains plugins 1 malware in IDE 1 manipulation 1 markdown 1 markitdown 1 material design 1 meaning of life 1 media streaming 1 medicine 1 meditation 1 mental resilience 1 mental well-being 1 message security 1 messenger 1 meteorology 1 microsoft 1 microtargeting 1 military ethics 1 mobile applications 1 mobile photography 1 model interpretability 1 model optimization 1 modern technologies 1 monorepo 1 mounting 1 mounting image 1 mp3 player 1 mpstat 1 multi-agent systems 1 multimedia tools 1 music 1 music player 1 mysteries 1 n8n security 1 national defense 1 nature conservation 1 net use 1 net-tools 1 nethogs 1 network cards 1 network monitoring 1 network resources 1 network security 1 neuroenhancement 1 neuropsychology 1 new life 1 new player 1 new things 1 nftables 1 office 1 onboarding 1 one-time cron 1 onestep4red 1 online 1 online courses 1 online privacy 1 open AI weights 1 open weights 1 openai 1 operating system 1 outage 1 package manager 1 paper clips 1 paradox of the fulfilled dream 1 parenting 1 parents 1 parted 1 password 1 password change 1 password policy 1 password recovery 1 password security 1 passwords 1 pdf 1 penetration testing 1 performance optimization 1 perseverance 1 persistent memory 1 personal data 1 php 1 plagiarism 1 plagiarism detection 1 plague 1 player 1 poison 1 police 1 politics 1 predictions 1 prefix caching 1 privilege escalation 1 processes 1 productivity 1 productivity tools 1 professional burnout 1 professional future 1 promissory notes 1 prompt engineering 1 prompt injection 1 protection 1 ps 1 python 1 questions 1 radar 1 raspberry pi 5 1 real-time AI 1 red 1 redeploying 1 relationships 1 relax 1 relaxation 1 remote work 1 renewable energy sources 1 reportage 1 rest 1 risk 1 robotaxi 1 root 1 router 1 routing 1 rules-based 1 runlevel 1 satellite data 1 satellite internet 1 science 1 scientific breakthroughs 1 scientific research 1 scientific research 2026 1 scraping 1 screen 1 screenshot 1 self-hosting 1 series 1 server 1 settings 1 shadow AI 1 show 1 sign language 1 skill loops 1 skills 1 skydive 1 sleep 1 sleep and learning 1 small big company 1 smart clothing 1 smartphone 1 smartphones 1 society 1 software engineering 1 space 1 space technology 1 special forces 1 sport 1 sports 1 spreadsheet 1 sqlite 1 stale data 1 stalking 1 startups 1 statistics 1 streaming 1 sub-millimeter sensor 1 success 1 superconductors 1 swiftui 1 symbolic link 1 syngrapha 1 sysctl 1 syslog 1 system acceleration 1 system bugs 1 system diagnostics 1 system logs 1 system optimization 1 systemd 1 tablet 1 talk show 1 tcpdump 1 teaching ethics 1 technical documentation 1 technological innovation 1 technology 2026 1 technology ethics 1 technology future 1 technology regulations 1 television 1 terrorism 1 testing 1 text humanization 1 the world in numbers 1 theology and science 1 theoretical computer science 1 threats 1 time management 1 time travel 1 timelapse 1 tips 1 tmp cleanup 1 traditional photography 1 tutorials 1 two-factor authentication 1 ubuntu 1 udev 1 upbringing 1 updates 1 user interface 1 user mode 1 ux/ui 1 vLLM 1 video conversion 1 violence in the military 1 viral 1 visionos 2.0 1 voice control 1 vulnerable dependencies 1 walking 1 walking meetings 1 watch 1 water retention 1 weather forecasting 1 webmaster 1 wellbeing 1 wind energy 1 wind turbine optimization 1 windows automation 1 wireless network 1 word processing 1 work 1 work automation 1 world 1 world cup 2026 1 world wide web 1 xAI 1 you are a miracle 1 yum 1 zeitgeist 1 zero-day 1

Blog archive

Table of contents