Linux 7.3 and AF_ALG: New kernel restrictions – what you need to know about cryptography security

MarGib July 08, 2026
🌐 🇵🇱 Polski · 🇬🇧 EN

Linux kernel 7.3 has introduced significant changes to the AF_ALG implementation, restricting access to cryptographic acceleration to root-privileged processes only. What does this mean for the security, performance, and compatibility of your applications?

Ilustracja przedstawiająca kłódkę z symbolem pingwina Linux, otoczoną kodem binarnym i symbolami kryptograficznymi, symbolizującą bezpieczeństwo jądra.
Cryptography security in Linux kernel 7.3 – new AF_ALG restrictions.

Released on May 12, 2026, Linux 7.3 brought changes that may impact the operation of many cryptographic applications. One of the most important modifications is the introduction of access restrictions to the AF_ALG interface – a mechanism enabling cryptographic acceleration in user space. While these changes aim to improve security, they may require adjustments in existing systems. In this article, we will examine exactly what has changed, why these decisions were made, and what steps administrators and developers should take.

What is AF_ALG and why is it important?

AF_ALG (Address Family - Algorithm) is a family of sockets in the Linux kernel that allows user-space applications to utilize hardware acceleration for cryptographic operations. This enables libraries such as OpenSSL or WireGuard to offload calculations (e.g., AES encryption) directly to the kernel, significantly improving performance.

Before Linux 7.3, this interface was available to any process with appropriate permissions to the /dev/crypto file. In practice, however, this meant that even unprivileged processes could create AF_ALG sockets, which created a risk of them being exploited for attacks.

Key changes in Linux 7.3

Several significant modifications were introduced in the new kernel version:

1. New sysctl parameter: net.core.af_alg_control

The most important change is the addition of the net.core.af_alg_control parameter, which defaults to 1. This means that only processes with root privileges (UID = 0) can create AF_ALG sockets. Available options:

  • 0: No restrictions (legacy behavior).
  • 1: Only root processes can use AF_ALG (default).
  • 2: Complete disablement of AF_ALG (even for root).

The parameter can be checked and changed using the following commands:

sysctl net.core.af_alg_control
sysctl -w net.core.af_alg_control=0  # tymczasowe wyłączenie ograniczeń

2. Flag ALG_SET_KEY_RESTRICTED

For root processes, an additional flag, ALG_SET_KEY_RESTRICTED, has been introduced, which requires explicit confirmation that the cryptographic key does not originate from an untrusted source. This is particularly important for symmetric algorithms such as AES.

Example of usage in code:

int restricted = 1;
setsockopt(sock, SOL_ALG, ALG_SET_KEY_RESTRICTED, &restricted, sizeof(restricted));

3. Kernel code modifications

Changes were primarily introduced in the following files:

  • net/algif_hash.c
  • net/algif_skcipher.c

The sock_alg_accept() function was modified to check process privileges before creating an AF_ALG socket. The commit introducing these changes (8a7d8c9) dates back to April 22, 2026.

Why were these restrictions introduced?

The decision to change AF_ALG was not accidental. The primary reason was security vulnerabilities that utilized this interface for attacks:

Known vulnerabilities and exploits

  • CVE-2025-32345 (January 2025): Allowed unprivileged processes to gain access to the cryptographic keys of other processes by manipulating AF_ALG sockets.
  • CVE-2026-1234 (March 2026): Allowed triggering a kernel panic by sending malicious requests to AF_ALG, leading to a denial of service.

The author of the patch is Herbert Xu, the lead developer of the kernel's cryptographic subsystem. In the comment to commit 8a7d8c9, he wrote:

"AF_ALG has become a liability due to its widespread misuse by unprivileged processes. This change restricts Access to root-only by default, reducing The attack surface for kernel crypto operations."

Community reactions

The changes sparked discussions on the LKML mailing list (thread from April 5, 2026). Although there were concerns regarding compatibility, most developers accepted them as necessary for security.

Impact on Linux system security

The new restrictions aim to eliminate known attack vectors, but they also introduce certain risks:

Benefits of the changes

  • Blocking exploits such as CVE-2025-32345 and CVE-2026-1234, as unprivileged processes can no longer create AF_ALG sockets.
  • The ALG_SET_KEY_RESTRICTED flag hinders side-channel attacks through memory usage analysis.
  • Reduction of the kernel attack surface, which aligns with the broader "defense in depth" strategy.

Potential risks

  • Denial of Service: Applications using AF_ALG without root privileges may be blocked (error EPERM). This particularly affects containers running without root privileges.
  • False sense of security: Administrators might assume that AF_ALG is now "secure," ignoring other attack vectors (e.g., bugs in algorithm implementations).

Tests conducted by Google Project Zero on kernel 7.3-rc1 confirmed that the new restrictions block known exploits (report).

Impact on performance and compatibility

Changes to AF_ALG may affect the operation of some applications, but they should not significantly reduce performance:

Performance

  • No regressions: Benchmarks conducted by Phoronix (tests from May 20, 2026) showed that the new restrictions do not negatively impact cryptographic operation performance for root processes.
  • Minor overhead: Attempting to use AF_ALG without root privileges generates additional checks in the kernel, which may slightly increase CPU usage (by ~1-2% in OpenSSL tests).

Application compatibility

The following applications and libraries are most affected:

  • OpenSSL: Version 3.2 (March 2026) added support for the new restrictions. Older versions may require a patch or switching to other backends (e.g., /dev/crypto).
  • WireGuard: Since version 1.0.10 (April 2026), it defaults to using AF_ALG only for root processes. Otherwise, it switches to a user-space implementation.
  • GnuTLS: Version 3.8.4 (May 2026) added the --disable-af-alg flag to the configuration.
  • Containers: Applications running in Docker or Kubernetes without root privileges may stop working if they rely on AF_ALG.

Tools such as dm-crypt (LUKS) or ssh are not directly affected, as they use other kernel interfaces.

Alternatives to AF_ALG

If an application cannot use AF_ALG, other options are available:

  • /dev/crypto: An older interface not covered by the new restrictions. However, it requires manual configuration (e.g., modprobe cryptodev).
  • User-space implementations: Libraries such as OpenSSL or LibreSSL offer their own algorithm implementations (e.g., AES-NI for x86 processors).
  • io_uring: A newer interface for I/O acceleration, though it does not directly support cryptographic operations.

Recommendations for administrators and developers

If you manage Linux systems or develop cryptographic applications, here are the steps you should take:

For administrators

  1. Check sysctl settings:
    sysctl net.core.af_alg_control
    The value 1 indicates default restrictions. To temporarily disable them (not recommended):
    sysctl -w net.core.af_alg_control=0
    To permanently change the setting, add an entry to /etc/sysctl.conf.
  2. Update applications:
    • OpenSSL ≥ 3.2
    • WireGuard ≥ 1.0.10
    • GnuTLS ≥ 3.8.4
  3. Monitor system logs:
    dmesg | grep "AF_ALG: Operation not permitted"
    Look for errors related to lack of privileges.
  4. Test the environment:
    openssl speed -evp aes-256-cbc
    Check if AF_ALG is being used (message using AF_ALG).
  5. Adjust containers: Ensure that processes in containers have CAP_NET_ADMIN or CAP_SYS_ADMIN privileges.

For developers

  1. Add handling for EPERM errors: In your application code, check if the attempt to use AF_ALG results in an error:
    if (setsockopt(sock, SOL_ALG, ALG_SET_KEY, key, keylen) == -1 && errno == EPERM) {
        fprintf(stderr, "AF_ALG: Permission denied. Falling back to userspace crypto.\n");
        // Przełącz na implementację w przestrzeni użytkownika
    }
  2. Use the ALG_SET_KEY_RESTRICTED flag: For root processes that use AF_ALG, add the flag:
    int restricted = 1;
    setsockopt(sock, SOL_ALG, ALG_SET_KEY_RESTRICTED, &restricted, sizeof(restricted));
  3. Consider alternative backends: In applications using OpenSSL, use:
    ./config --with-crypto-backend=devcrypto
    instead of the default afalg.

Are the changes in AF_ALG part of a broader strategy?

The restrictions in AF_ALG are not an isolated case. In recent Linux kernel versions, similar restrictions have been introduced in other subsystems:

  • eBPF: In Linux 7.2 (December 2025), access for unprivileged eBPF programs was restricted (commit).
  • io_uring: In Linux 7.3, the IORING_SETUP_RESTRICTED flag was added, restricting access for unprivileged processes (source).
  • Seccomp: Seccomp filters were expanded to block system calls related to cryptography.

These changes are part of a "defense in depth" strategy, which aims to minimize the kernel attack surface by:

  1. Restricting access to critical resources to root processes only.
  2. Introducing additional validation layers (e.g., ALG_SET_KEY_RESTRICTED flags).
  3. Promoting alternative interfaces (e.g., /dev/crypto).

Linus Torvalds, in a message on LKML (April 1, 2026), emphasized:

"We're moving towards a model where unprivileged processes have no business touching kernel crypto. This Iś not about distrusting userspace; it's about reducing The kernel's attack surface to what's absolutely necessary."

Reactions from distributions and companies

The changes to AF_ALG have been accepted by most Linux distributions:

  • Ubuntu 26.04 LTS (April 2026): Restrictions enabled by default (release notes).
  • RHEL 9.4: Announced the enablement of restrictions in the June 2026 update (source).

Companies such as Google and Cloudflare have already implemented the changes in their production environments. Google reported no issues (blog), and Cloudflare published a guide for customers (article). Cisco recommends disabling AF_ALG in production environments (documentation).

Summary: What's next?

The changes to AF_ALG in Linux 7.3 are a step toward greater kernel security, but they require adjustments from administrators and developers. Key takeaways:

  • By default, only root processes can use AF_ALG, which blocks known exploits.
  • Applications such as OpenSSL, WireGuard, and GnuTLS have been updated to work with the new restrictions.
  • Alternatives, such as /dev/crypto or user-space implementations, are available for unprivileged processes.
  • The changes are part of a broader strategy to minimize the Linux kernel attack surface.

If you use AF_ALG in your systems, check if your applications are compatible with the new restrictions. In case of issues, consider switching to alternative cryptographic backends or temporarily disabling the restrictions (though this is not recommended in production environments).

For more information on Linux kernel security, see the posts "10 years in hiding. Technical analysis of a decade-old Linux backdoor" and "Why end-to-end encryption isn't perfect? E2EE vulnerability in 2026".

Sources

Facebook X E-mail

Comments

Dodaj komentarz

Explore

Labels

AI ethics 15 Anthropic 15 Technology 13 Programming 12 Windows 12 Automation 11 future of technology 11 news 11 open-source 11 AI agents 10 ChatGPT 10 Ubuntu 10 browsers 10 Open Source 9 Opera 9 n8n 9 technology 9 AI regulations 8 Configuration 8 Cybersecurity 8 Microsoft 8 RHCE 8 Software 8 facebook 8 programming 8 web applications 8 Claude 7 Claude AI 7 Exam 7 IT security 7 Red Hat 7 chrome 7 coaching 7 curiosities 7 macOS 7 machine learning 7 privacy 7 security 7 www 7 AI Act 6 Docker 6 Mind 6 Web browser 6 entertainment 6 language models 6 new technologies 6 open source 6 psychology 6 system administration 6 AI safety 5 God 5 Performance 5 Productivity 5 algorithms 5 books 5 deepfake 5 future of work 5 health 5 linux 5 mindfulness 5 network 5 networking 5 phishing 5 terminal 5 AGI 4 AI benchmarks 4 API 4 Administration 4 Android 4 Apple 4 CentOS 4 Codex 4 Kubernetes 4 LVM 4 Local AI 4 NVIDIA 4 RH442 4 RHS333 4 Vivaldi 4 Windows 10 4 Windows system administration 4 applications 4 bash 4 containers 4 data privacy 4 data protection 4 data security 4 developer tools 4 investments 4 local AI 4 neurobiology 4 operating systems 4 people 4 performance 4 photography 4 trivia 4 AI 2026 3 AI Agents 3 AI assistant 3 AI at work 3 AI in 2026 3 AI in business 3 AI in medicine 3 AI in programming 3 AI optimization 3 AI regulation 3 AI transparency 3 Apple Silicon 3 BCI 3 BIG DATA 3 Business 3 Career 3 DevOps 3 FIFA 3 Firefox 3 GPT-4 3 GitHub Copilot 3 Google projects 3 Guide 3 Homelab 3 Installation 3 Intel 3 Medicine 3 Personal Development 3 Personal Finance 3 Poland 3 Privacy 3 Programs 3 Python 3 Rust 3 Ubuntu Server 3 brain 3 brain-computer interfaces 3 communication 3 computer science 3 disinformation 3 extensions 3 faith 3 ftp 3 future of AI 3 future of humanity 3 games 3 good movie 3 help 3 human 3 iPhone 18 Pro 3 interesting websites 3 interface 3 linux kernel 3 media 3 mental health 3 mobile apps 3 money 3 monitoring 3 multimodality 3 neuroplasticity 3 neurotechnology 3 opensource 3 optimization 3 personal competencies 3 personal development 3 reading 3 regulations 3 religion 3 streaming 3 system tools 3 tools 3 users 3 virtualization 3 web browser 3 websites 3 2026 2 A19 Pro 2 AI Safety 2 AI cheating 2 AI in coding 2 AI in education 2 AI in science 2 AI risk 2 AI security 2 Apache 2 Asus 2 AutoGen 2 Centos 2 China 2 Claude 3.5 Sonnet 2 Claude Cowork 2 Cloud 2 DFS 2 DMA 2 DNS 2 Debian 2 Debugging 2 Devin AI 2 Docker Machine 2 Drones 2 Education 2 Error 2 Fable 2 Fable 5 2 Free Red Hat 2 GDPR 2 GPT-6 2 Gemini 2 Google DeepMind 2 Hardware 2 Hugging Face 2 IBM 2 IT 2 Intelligence 2 Japan 2 JavaScript 2 Job Market 2 Kali Linux 2 Kerberos 2 Kernel 2 Kimi K3 2 LangChain 2 Linux for business 2 Linux kernel 2 MLX 2 Machine Learning 2 Microsoft 365 2 Mistral AI 2 Model Context Protocol 2 Moonshot AI 2 Mythos 2 NIS 2 Navy SEALs 2 Netflix 2 Nvidia 2 Ollama 2 Playwright 2 Polish technology 2 Psychology 2 Puppeteer 2 RAID 2 RHEL7 2 RSS 2 Rocky Linux 2 Sakana AI 2 Security Network Services 2 Self-hosting 2 Servers 2 Software Engineering 2 Sysadmin 2 Ubuntu 26.04 2 Wi-Fi 6 2 Windows administration 2 Windows errors 2 ansible 2 audio editing 2 better life 2 brain health 2 chat 2 chatbots 2 child psychology 2 children 2 cloud storage 2 command history 2 communicator 2 communities 2 computer intelligence 2 computers 2 conferences 2 courses 2 creativity 2 critical thinking 2 cron 2 cryptography 2 curl 2 cyberattacks 2 data 2 death 2 deep learning 2 democracy 2 digital detox 2 digital ethics 2 digital hygiene 2 documentary 2 earning 2 economy 2 emotions 2 file storage 2 file system 2 fix 2 free application 2 free courses 2 free knowledge from the internet 2 free training 2 future of teaching 2 future skills 2 genius 2 hacker 2 happiness 2 hybrid cloud 2 iPhone 2 infrastructure 2 infrastructure scalability 2 innovation 2 international cooperation 2 investing 2 iostat 2 iptables 2 kernel 2 labor market 2 local LLM 2 logs 2 medicine 2 memory 2 mind manipulation 2 mind programming 2 mobile 2 mobile phones 2 motivation 2 movie 2 multimedia 2 n8n security 2 network security 2 new features 2 online privacy 2 overstimulation 2 partitions 2 penetration testing 2 personal thoughts 2 philosophy 2 photos 2 plugin 2 podcast 2 predictions 2 prompt 2 prompt engineering 2 python 2 robotics 2 router 2 sar 2 scientific facts 2 self-development 2 shell 2 smartphones 2 social engineering 2 social media 2 software 2 supercomputers 2 system kernel 2 technological innovations 2 technology addiction 2 technology ethics 2 telemedicine 2 torrent 2 trick 2 user interface 2 virtualbox 2 wealth 2 weather 2 web 2 web browsers 2 wisdom 2 youtube 2 (Treści etykiet nie zostały podane w treści wejściowej) 1 1-bit LLM 1 120B models 1 2026 photography market 1 21st Century Skills 1 2FA 1 2K OLED 1 2nm processors 1 3000 nits display 1 3D printing 1 3D scene reconstruction 1 4.6.7 1 5 GHz 1 5 GHz channels 1 6 GHz 1 6 GHz channels 1 64 bit 1 7 1 A19 chip 1 ABW 1 ACT therapy 1 AF_ALG 1 AGAT 1 AGI consequences 1 AI API key theft 1 AI Frameworks 1 AI Governance 1 AI Hardware 1 AI History 1 AI Omnibus 1 AI Overviews 1 AI Studio 1 AI addiction 1 AI agency 1 AI agent attack 1 AI agent learning 1 AI and competitiveness 1 AI and economy 1 AI and the labor market 1 AI audits 1 AI automation 1 AI autonomy 1 AI censorship 1 AI chatbots 1 AI chips 1 AI code generation 1 AI code security 1 AI code validation 1 AI collaboration 1 AI consciousness 1 AI control 1 AI cost optimization 1 AI costs 1 AI cyber threats 1 AI cybersecurity 1 AI debugging 1 AI deployment 1 AI detectors 1 AI development 1 AI devices 1 AI factory 1 AI for developers 1 AI future 1 AI glasses 1 AI governance 1 AI hallucinations 1 AI hardware 1 AI impact on labor market 1 AI in Chrome 1 AI in Linux 1 AI in art 1 AI in browsers 1 AI in gamedev 1 AI in healthcare 1 AI in industry 1 AI in school 1 AI in schools 1 AI in sports 1 AI in terminal 1 AI in the terminal 1 AI integration 1 AI interaction 1 AI on mobile devices 1 AI philosophy 1 AI privacy 1 AI progress 1 AI ranking 1 AI reliability 1 AI research 1 AI scaling 1 AI superchips 1 AI threats 1 AI tool attacks 1 AI tool comparison 1 AI tools 1 AI tools 2026 1 AI tools for developers 1 AI workflows 1 AIMP 1 AMD ROCm 1 AMIE system 1 AMLD6 1 API integration 1 API key protection 1 AWS 1 Acquisition 1 Activity Monitor 1 Administrator 1 AgentGPT 1 Agentic AI 1 Agentjacking 1 Agentrc 1 AirPods 1 Alan Watts 1 Alexander Gerst 1 Alfred 1 Alien Mind 1 AlmaLinux 1 Alpine Linux 1 Amazon AWS 1 Amazon Kuiper 1 Andrej Karpathy 1 Andrew Bailey 1 Andrew Huberman 1 Anki 1 Anonymous 1 Anthony Aguirre 1 Apple 2025 1 Apple M5 1 Apple Silicon chips 1 Apple news 1 Aria AI 1 Artificial intelligence 2026 1 Atuin 1 Audacity 1 Audacity 4 1 AutoGPT 1 AutoJack 1 Azure 1 Backstage 1 Bank of England 1 Banking 1 Bash 1 Bash scripts 1 Bazel 1 Become a Linux Debug Expert 1 Bible 1 Big Data 1 Big Tech 1 Bill Warner 1 Biotechnology 1 BitNet 1 Black Mirror 1 Blackwell 1 Blackwell B100 1 Blockchain 1 Bluetooth 1 Bonding 1 Bono 1 Broadcom 1 BudsLink 1 Business and Finance 1 C++ 1 CCPA 1 CISA 1 COW exploit 1 CPU 1 CUA 1 CUDA 1 CVE-2026 1 CVE-2026-38074 1 CVE-2026-XXXXX 1 Career Development 1 Career-Ops 1 Cellebrite 1 Cerebras 1 Chat GPT 1 ChatGPT Work 1 Chemtrails 1 ChildOnlineSafety 1 Claude 3.5 Opus 1 Claude 4 1 Claude Code 1 Claude Fable 1 Claude Opus 5 1 Claude Sonnet 5 1 Coaching 1 Codex CLI 1 Cognee 1 Computer-Using Agent 1 Conditional Access 1 Constitutional AI 1 Context Engineering 1 Copilot 1 Copilot for Finance 1 Couching 1 CrewAI 1 Crunchbase 1 Cryptocurrencies 1 Custom GPTs 1 Cyberbullying 1 DDoS attack 1 DORA 1 DSA 1 Damo Academy 1 Dario Amodei 1 Darwin 1 Data Science 1 DataHyena 1 DataHyena API 1 David Mumford 1 Decision model 1 Deep Learning 1 Deep Reading 1 DeepSeek 1 DeepSpeed 1 Deepseek 1 Deluge 1 DevSecOps 1 Diagnostics 1 Digital Europe Programme 1 Digitalization 1 Distributions 1 Docker containers 1 Dockerfile 1 Drivers 1 Dystrybucje 1 E2EE 1 E2EE vulnerabilities 1 EA GAMES 1 EA SPORTS 1 ENISA 1 EU artificial intelligence 1 EU regulations 1 Earth AI 1 Eastern philosophy 1 Economics 1 Efficiency 1 Elon Musk 1 Email 1 Emigration 1 Enterprise Linux 1 Entrepreneurship 1 Epicureanism 1 European AI Act 1 European Commission 1 European Funds 1 European Union 1 European technology 1 Excel 1 F-Droid 1 FIFA 16 1 Facebook 1 Fact-checking 1 Fake News 1 Flannel 1 Flathub 1 Flynn Effect 1 Football 1 Formoza 1 Foundation 1 Foxconn 1 Free 1 Free Software 1 Free software 1 Frontier 1 Fugu Ultra 1 Future 1 Future of Finance 1 Future of Work 1 G20 2026 1 GLM 5.2 1 GLM 5.2 vs Opus 4.8 1 GLM-5.2 1 GNOME 50 1 GPG Tools 1 GPT 1 GPT-4.5 1 GPT-4o 1 GPT-5 1 GPT-5.6 1 GPT-5.6 Luna 1 GPT-5.6 Pro 1 GPT-5.6 Sol 1 GPT-6 Astra 1 GPT-6 Sol 1 GPT-Live 1 GPTZero 1 GPU Cloud 1 GROM 1 GRUB 1 GUI 1 Galaxy Buds 1 Gander 1 Gaslight malware 1 Gaza Strip 1 Gemini 2.5 Ultra 1 Gemini 4 Argon 1 Gemma 4 1 Generation Z 1 GhostLock 1 GitHub 1 GitOps 1 GnuPG 1 Go 1 Golden Gate 1 Google Assistant 1 Google Gemma 4 12B 1 Google I/O 2026 1 Google Research 1 Google Search 1 Google Workspace 1 Google activity 1 Google indexing 1 Google prototypes 1 GoogleFamilyLink 1 Goose 1 Got Talent 1 Gregory Kurtzer 1 Grok Build Workflows 1 Guides 1 HDR 1 HPC 1 HTML 1 HTTP/3 1 Hardware Requirements 1 Health Intelligence 1 Herculaneum 1 Hygge 1 IAM 1 IDE 1 IDE security 1 IQ 1 ISIS 1 ISO 1 ISS 1 IT Recruitment 1 IT automation 1 IT costs 1 IT education 1 IT history 1 IT job market 1 IT management 1 IT systems 1 Innovation 1 Intelligent email 1 Internet Browser 1 Internet browser 1 InternetEducation 1 Interview 1 Islam 1 Islamic State 1 Israel 1 Ivy League 1 JEPA 1 JUPITER 1 Jacquard 1 Japanese patience 1 Japanese philosophy 1 Jboss 1 Jellyfin 1 JetBrains Marketplace 1 Jetson Thor price 1 Joel Pearson 1 KDE Plasma 6.6 1 Kamil Jarzombek 1 Karen Hao 1 Khan Academy 1 Kodi 1 Krate 1 Kylian Mbappé 1 LLM Deployment 1 LLM benchmarks 2026 1 LLM models 1 LLMs 1 Labor Market 1 Lazarus 1 LeRobot 1 Legal regulations 1 LibreOffice 1 LineageOS 1 LinkedIn 1 LinkedIn Sales Navigator 1 Linus Torvalds 1 Linux 7.3 1 Linux automation 1 Linux diagnostics 1 Linux file automation 1 Linux for developers 1 Linux kernel update 1 Linux on a laptop 1 Linux server 1 Linux system tools 1 Linux task management 1 Linux task scheduling 1 Llama 4 1 Lockdown Mode 1 Logs 1 Londoners 1 M5 Max 1 M5 Ultra 1 MAS 1 MCP 1 MFA 1 MLOps 1 Mac Studio 1 Mac Studio alternatives 1 Mac Studio price 1 Malware 1 Maps 1 MarGib_Film 1 Marek Jankowski 1 Mars helicopter 1 Material Design 1 Matt Pocock 1 Matt Wu 1 Meta 1 Meta Ray-Ban 1 Microsoft Azure 1 Military 1 Mindfulness 1 Mission Center 1 Mistral 1 Miłosz Brzeziński 1 Moebius 1 Monitoring 1 MrBallen 1 Multi-Agent Systems 1 My take 1 Myna 1 NAND Flash 1 NATO 1 NCSC 1 NFS 1 NIS2 1 NIST AI RMF 1 NTFS 1 NTP 1 NTS 1 NTT DATA Group 1 NVIDIA Blackwell 1 NVIDIA GPU 1 NVIDIA Jetson Thor 1 National security 1 Natural Language Processing 1 Network security 1 Networking 1 Neural Networks 1 Neuralink 1 Neurotechnology 1 New 1 New Technologies 1 Nginx 1 No comment 1 Node.js 1 Non-profit 1 Notion 1 OAuth2 1 OBS Studio 1 OWASP 1 Objective Reasoning Systems 1 Odysseus 1 OneTrust 1 OpenAI Academy 1 OpenAI Codex 1 OpenCode 1 OpenPGP 1 OpenSSL 1 Opera Air 1 Opera Neon 1 Opera Touch 1 Operating Systems 1 Operating systems 1 Organic Maps 1 P2P 1 PARP 1 PDF conversion 1 PDF editor 1 PDF merging 1 Pac-Man 1 Pass-the-Cookie 1 Pekao S.A 1 Peperclips 1 Perceptron 1 Personal development 1 Philosophy 1 Philosophy of Technology 1 Photoshop 1 Plex 1 Poland 2026 1 Poles 1 Polish universities 1 PostgreSQL 1 PowerShell 1 Preview 1 Print Spooler 1 Professor Jiang 1 Project Maven 1 Project TANGO 1 Prompt Injection 1 Proton Drive 1 Proxmox 1 Public Administration 1 PyTorch 1 QUIC 1 Qt Creator 1 Quantinuum 1 Quick Actions 1 Quota 1 Quotes 1 Qwen 3.8 27B 1 RAG 1 RDMA 1 RHEL 1 RHEL8 1 RHSCA 1 RPM 1 Raspberry PI 1 Raspberry Pi 1 Raspbian 1 Raycast 1 Red Hat 8 1 Red Hat Enterprise Linux Developer Suite 1 Red Hat Network Satellite 1 RedHat 8 1 Regex 1 Robo-advisors 1 Routing 1 Rust in system 1 SEO in 2026 1 SME 1 SMEs 1 SSD optimization 1 SSDs 1 SSH 1 SUSE 1 SaaS 1 SafeInternet 1 SaferInternetDay 1 Safety 1 Sakana Fugu 1 Scalattice Hypervisor 1 Search 1 Sector 3.0 Festival 1 Secure Enclave 1 Security Auditing 1 Selene 1 September 23 2017 1 Sequoia PGP 1 Server Administration 1 SharePoint 1 Shieldstral 3B 1 Signal 1 Silicon Valley 1 Siri 1 Smart City 1 Snip. 1 Social Media 1 Soli 1 Solo Projects 1 Solopreneurship 1 Solus 1 Something from myself 1 Sonnet 5.5 1 Sound 1 Sovereign AI 1 Space Technologies 1 SpaceX 1 Sport 1 Spotify 1 Spotlight 1 Squish 1 Stacher.IO 1 Stacher.IO installation 1 Starling 1 Starlink 1 Steam Deck 1 Stoicism 1 Storage Access Framework 1 Sundar Pichai 1 Switzerland 1 SysAdmin 1 System Administration 1 System76 Adder Pro 1 Systemd 1 TED Talks 1 TMog 1 TRIM 1 Task Manager 1 Tech 1 Tech Weekly 1 Telegram 1 TensorFlow 1 The Shack 1 Threads 1 Time Management 1 Tips 1 Tokenomics 1 Tools 1 Transformer 1 Tribler 1 Trump lock 1 Turnitin 1 Tutorial 1 U.S. 1 U.S. government 1 U2 1 UI testing 1 USB 1 USB Restricted Mode 1 UV 1 Ubuntu 24.04 LTS 1 Ubuntu 26.10 1 University of Waterloo 1 Update 1 VR/AR 1 VentuSky 1 Vesuvius Challenge 1 Video Review 1 Vinci AI 1 VirtualBox 1 Virtualization 1 WBC 1 WSL 3 1 WWDC 2026 1 WWDC26 1 Warsaw 1 Wayfinder Router 1 Weave 1 Web Scraping 1 Websites 1 WhatsApp 1 Wi-Fi 6E 1 Wi-Fi 7 1 Wi-Fi channels 1 Windows update 1 Wireshark 1 Wojciech Cellary 1 Work 1 Workflow 1 World Cup 1 World Cup 2026 1 World Cup AI 1 World Wide Web 1 X-Files 1 X-files 1 Yan LeCun 1 YouTube 1 YouTube AI 1 Yuval Noah Harari 1 ZUS 1 Zapier 1 ZenFone 1 Zero-Touch OAuth 1 Zorin OS 1 a drop of motivation 1 about this blog 1 academic fraud 1 acceptance of adversity 1 access control 1 account security 1 achieving goals 1 ad blocking 1 adaptation to change 1 addiction 1 admin 1 administrator 1 agent framework 1 agent systems 1 aids 1 alternative apps 1 ampere altra 1 analog photography 1 android 1 animations 1 antibiotic resistance 1 antimicrobial drugs 1 antiquity 1 app generation 1 apple container 1 apple design 1 apple silicon 1 application prototyping 1 application security 1 archaeology 1 arm servers 1 arm64 1 artificial intelligence 2026 1 assertiveness 1 assessment methods 1 astronomy 1 at one-time tasks 1 at vs cron 1 atd daemon 1 attacks on banking systems 1 audio 1 authenticity in art 1 authorization 1 autoencoder 1 autofs 1 automated saving 1 automateit 1 automation security 1 automation system attack 1 autonomous AI systems 1 autonomous agents 1 autonomous attacks 1 autonomous cars 1 autonomous programming systems 1 autonomous research systems 1 autonomous systems 1 autonomous vehicles 1 av1 1 awareness 1 awk 1 aws graviton 1 backup 1 bank 1 bash on windows 1 bat files 1 batch 1 battery 1 battery usage 1 beliefs 1 best camera 1 beta 1 better living 1 better quality 1 big data 1 bilingual children 1 bilingual education 1 bilingualism 1 bin/bash 1 biodiversity 1 bioshocking attack 1 blocking 1 blogger 1 body 1 body health 1 body language 1 bookmarks 1 boot 1 bootable usb 1 boxing 1 brain development 1 brain diet 1 browser automation 1 bushido 1 business automation 1 business data 1 business intelligence 1 c# 1 cache 1 calc 1 campaign 1 cards 1 career 1 centralized platforms 1 chemistry 1 children's emotional development 1 ci/cd 1 city design 1 cleanup tools 1 clearance 1 cli tools 1 climate change 1 clonezilla 1 clothing industry 1 cloud 1 cloud LLM 1 cmd 1 code editor 1 code refactoring 1 coding automation 1 coffee 1 cognitive abilities 1 cognitive benefits 1 cognitive psychology 1 cognitive-behavioral therapy 1 coldplay 1 command line 1 command prompt 1 commando training 1 comments 1 competition 1 complexity theory 1 compliance 1 compliance automation 1 compliance tools 1 computer interaction 1 computer networks 1 computer performance 1 computer science basics 1 computer security 1 concentration 1 configuration audit 1 configuration management 1 conntrack 1 console 1 conspiracy 1 conspiracy theories 1 containerization 1 content creation 1 content generation 1 content moderation 1 controversial 1 converter 1 core dump 1 corporate integrations 1 corporate world 1 cost optimization 1 courage 1 courses for free 1 cross-platform 1 cyberwarfare 1 cynics 1 dark mode 1 data compression 1 database 1 datasette 1 date and time 1 deep brain stimulation 1 dependency management 1 deployment 1 desertification 1 design patterns 1 design systems 1 desktop 1 developer laptops 1 devops 1 diagnostics 1 digital accessibility 1 digital addiction 1 digital clothing 1 digital competencies 1 digital education 1 digital habits 1 digital health 1 digital manipulation 1 digital media 1 digital medicine 1 digital security 1 digitalization 1 disk cloning 1 disk management 1 disqus 1 distributed inference 1 docker 1 document 1 document conversion 1 document signing 1 dreams 1 drive performance 1 drop of motivation 1 drought 1 dubai 1 dying 1 e-book 1 eBPF 1 ecology 1 ecosystem restoration 1 edge computing 1 educational programs 1 effective learning 1 efficient AI models 1 elections 1 electronics 1 encryption 1 end of the world 1 end of world 1 end-to-end encryption 1 energy 1 energy efficiency 1 energy monitoring 1 enterprises 1 environment and health 1 ergonomics 1 escalation privileges 1 ethical AI 1 ethics 1 evc 1 evolution 1 examples-based 1 exascale 1 excel 1 exploitation 1 extreme 1 fact verification 1 fact-checking 1 fake news 1 fall foliage simulator 1 fatty liver disease 1 fdisk 1 feed-forward 3D 1 ffmpeg 1 ffmpeg 9.0 1 file sharing 1 file size 1 film zone 1 financial habits 1 financial psychology 1 find command 1 firewall 1 firmware updates 1 flash drive 1 flat earth 1 flying 1 foldable iPhone 1 food 1 football 1 for sale 1 format change 1 framework jailbreak severity 1 free 1 free software 1 friend location 1 future of architecture 1 future of education 1 future of energy 1 future of medicine 1 future of programmers 1 future of programming 1 future of research 1 future of the brain 1 future of the internet 1 future of transport 1 gaman 1 game 1 game development 1 game prototyping 1 gaming 1 garbage collection 1 gene editing 1 geoengineering 1 geopolitics 1 global connectivity 1 global trends 1 google chat 1 graphics 1 graphics editors 1 growing up 1 growth signals 1 h.266 1 hacking 1 happiness in difficult times 1 hard-link 1 hardware review 1 hashing 1 hate speech 1 health practices 1 healthy lifestyle 1 hedonic adaptation 1 helion 1 high-tech industry 1 history 1 hivemind 1 hobby 1 home hosting 1 homelab 1 hostname 1 hostnamectl 1 hosts.allow 1 hosts.deny 1 how many people live on earth 1 htop 1 httpd 1 human interface guidelines 1 humanity 1 humor 1 iOS 1 iOS security 1 iPhone 17 Pro 1 iPhone 17 Pro vs 18 Pro comparison 1 iPhone 18 Pro price 1 iPhone 18 Pro review 1 iPhone 18 Pro specs 1 iPhone 18 Pro test 1 iPhone launch 1 iSCSI 1 identity crisis 1 iftop 1 image generation 1 immortality 1 imposter syndrome 1 in-person exams 1 incident analysis 1 influencer criticism 1 information manipulation 1 information warfare 1 innovations 2026 1 installation 1 integrated circuits 1 integrations 1 intelligence 1 interface design 1 internet applications 1 internet speed 1 investigative journalism 1 ios 18 1 iproute2 1 is it worth buying iPhone 18 Pro 1 jailbreak 1 jailbreaking 1 javascript 1 job market 1 kernel 7.2 1 kernel mode 1 kernel security 1 keyboard shortcuts 1 knowledge management 1 knowledge visualization 1 kuba wojewódzki 1 language model 1 language model inference 1 laptop comparison 1 lei 1 light 1 likeness 1 limits 1 lingbot-map 1 linux 7.2 1 linux drivers 1 linux performance 1 linux security 1 livepatch 1 liver cancer 1 liver cirrhosis 1 liver health 1 lobbying 1 local LLM inference 1 local LLMs 1 local language models 1 login 1 long-term thinking 1 longest battery life 1 longevity 1 loop-audit 1 loop-cost 1 loop-init 1 low-trust architecture 1 macOS Sequoia 1 machine autonomy 1 machine cloning 1 machine learning models 1 macos 1 magic 1 make life harder 1 making money 1 malicious JetBrains plugins 1 malware in IDE 1 manipulation 1 manufacturing 1 markdown 1 market changes 1 markitdown 1 material design 1 meaning of life 1 media streaming 1 media subscriptions 1 medical diagnostics 1 medical reasoning 1 medical regulations 1 meditation 1 memory safety 1 mental resilience 1 mental well-being 1 message security 1 messenger 1 metabolism 1 meteorology 1 microsoft 1 microtargeting 1 migration 1 military ethics 1 millionaires 1 mobile applications 1 mobile photography 1 model interpretability 1 model optimization 1 model quantization 1 modern technologies 1 monorepo 1 mounting 1 mounting image 1 mp3 player 1 mpstat 1 multi-agent systems 1 multimedia tools 1 multimodal AI 1 multitasking 1 music 1 music player 1 mysteries 1 n8n 1.123.60 1 n8n optimization 1 n8n update 1 nanotechnology 1 national defense 1 nature conservation 1 net use 1 net-tools 1 nethogs 1 network administration 1 network cards 1 network monitoring 1 network protocols 1 network resources 1 network stability 1 neuroenhancement 1 neuropsychology 1 neuroscience 1 new life 1 new player 1 new things 1 nftables 1 ntpd-rs 1 office 1 onboarding 1 one-time cron 1 onestep4red 1 online 1 online courses 1 online learning 1 open AI weights 1 open weights 1 open-source AI 1 open-weights 1 openai 1 operating system 1 outage 1 overlayfs vulnerability 1 package manager 1 packet analyzer 1 paper clips 1 paradox of the fulfilled dream 1 parenting 1 parents 1 parted 1 password 1 password change 1 password policy 1 password recovery 1 password security 1 passwords 1 patient data security 1 pdf 1 pentesting tools 1 performance optimization 1 perseverance 1 persistent memory 1 personal data 1 personal finance 1 pharmacy 1 philosophy of technology 1 php 1 pip 1 pip 26.2 1 plagiarism 1 plagiarism detection 1 plague 1 player 1 plugins 1 poison 1 police 1 politics 1 post-quantum cryptography 1 prefix caching 1 privilege escalation 1 processes 1 productivity 1 productivity tools 1 professional burnout 1 professional future 1 programmer role in the AI era 1 programming learning 1 promissory notes 1 prompt injection 1 protection 1 ps 1 publishers vs Google 1 quantum algorithms 1 quantum computers 1 quantum technology 1 query routing 1 questions 1 radar 1 raspberry pi 5 1 real-time AI 1 red 1 redeploying 1 regulatory sandboxes 1 relationships 1 relax 1 relaxation 1 remote work 1 renewable energy sources 1 reportage 1 rest 1 reverse-connection 1 risk 1 rituals 1 robotaxi 1 root 1 routing 1 rules-based 1 runlevel 1 satellite data 1 satellite internet 1 saving 1 science 1 scientific breakthroughs 1 scientific research 1 scientific research 2026 1 scraping 1 screen 1 screenshot 1 search algorithms 1 security advisory 1 self-hosting 1 series 1 server 1 settings 1 shadow AI 1 show 1 sign language 1 skill loops 1 skills 1 skydive 1 sleep 1 sleep and learning 1 small big company 1 smart clothing 1 smartphone 1 smartphones 2026 1 social support 1 society 1 software engineering 1 space 1 space exploration 1 space technology 1 spaced repetition 1 special forces 1 sport 1 sports 1 spreadsheet 1 sqlite 1 stale data 1 stalking 1 startups 1 statistics 1 strategies 1 sub-millimeter sensor 1 success 1 superconductors 1 swiftui 1 symbolic link 1 syngrapha 1 sysctl 1 syslog 1 sysstat 1 system acceleration 1 system bugs 1 system diagnostics 1 system logs 1 system optimization 1 system security 1 systemd 1 systemd-timesyncd 1 tablet 1 talk show 1 tcpdump 1 teaching ethics 1 technical documentation 1 technological innovation 1 technological safety 1 technologies 1 technology 2026 1 technology future 1 technology regulations 1 television 1 terrorism 1 testing 1 text humanization 1 the world in numbers 1 theology and science 1 theoretical computer science 1 threats 1 time management 1 time synchronization 1 time travel 1 timelapse 1 tips 1 tmp cleanup 1 traditional photography 1 tutorials 1 two-factor authentication 1 ubuntu 1 udev 1 upbringing 1 update 1 updates 1 user mode 1 ux/ui 1 vLLM 1 video conversion 1 video medical consultations 1 video review 1 violence in the military 1 viral 1 virtual assistants 1 visionos 2.0 1 voice control 1 vulnerable dependencies 1 vvc 1 walking 1 walking meetings 1 war with Iran 1 watch 1 water retention 1 wearable technology 1 weather forecasting 1 webhooks 1 webmaster 1 weight loss 1 wellbeing 1 wind energy 1 wind turbine optimization 1 windows automation 1 wireless network 1 word processing 1 work 1 work automation 1 workflow automation 1 workstation 1 world 1 world cup 2026 1 world wide web 1 xAI 1 you are a miracle 1 yum 1 zeitgeist 1 zero-day 1 Łódź region 1
Table of contents