September 12, 2026

hackergotchi for ArcheOS

ArcheOS

Preserving the Past: Ötzi's Digital Twin

 Hello everyone,

Our article regarding the 3D documentation of Ötzi and the archaeological artifacts found with him has been published in the scientific journal Heritage. The open-access paper can be read and downloaded directly from the journal's website or on ResearchGate .

I had previously teased a few of these topics here on ATOR—such as developing a 3DHOP extension to view the mummy in X-ray mode and utilizing the open-source DCMTK libraries to analyze DICOM data from CT scans. However, the new paper details the project's specific challenges and the solutions adopted.


In particular, the article explains:

  •     How we achieved higher detail in surveying leather artifacts using Displacement Mapping, a technique we first experimented with during the Forensic Facial Approximation (FFA) of Santa da Genova;
  •     How we overcame challenges related to specular reflections on non-Lambertian surfaces;
  •     How, in the case of the bear-fur cap, we applied neural radiance fields (NeRF) algorithms using the open-source software nerfstudio;
  •     How we reconstructed a multimodal Digital Twin of Ötzi, capable of simultaneously displaying both the mummy’s 3D surface model (obtained via SfM) and the internal skeletal structure (derived from CT DICOM data).


The seeds of this research were presented in Turin during ArcheoFOSS 2023, but this paper expands significantly on the methodologies developed throughout the Ötzi project.


As always, all software tools used in this work are FLOSS. You can also read the official press release from the South Tyrol Museum of Archaeology here.



I hope you find the article useful. Have a nice day!


12 September, 2026 04:33PM by Luca Bezzi (noreply@blogger.com)

hackergotchi for Volumio

Volumio

Audio OEM: Build a Streamer People Want

A beautiful component can earn attention at a hi-fi show. What earns a permanent place in a listening room is the experience after the customer gets home. For an audio OEM, that experience is increasingly defined by software: how quickly music starts, whether a local library feels alive, how naturally streaming services fit together, and whether the product remains reliable years after purchase.

Connected audio is no longer an optional add-on to a traditional hardware range. It is where listeners choose music, manage their systems, discover artists, and form an opinion about a brand every day. Building that experience well requires more than adding a network module to an existing amplifier, DAC, or speaker.

The connected product is the real product

A network streamer sits at the meeting point of several expectations that used to be separate. A customer may want to play a carefully tagged NAS library one evening, use Qobuz the next, send music from a phone during a dinner party, and control volume across an integrated system without thinking about protocols or source switching.

From the listener’s perspective, these are simple requests. For a manufacturer, they involve streaming integrations, library indexing, playback architecture, control apps, hardware drivers, account authentication, network behavior, and ongoing support. A product can sound extraordinary and still create frustration if its interface is slow, its setup process is brittle, or software maintenance is treated as a one-time launch task.

That is why the strongest connected products begin with a clear listening promise. Is the goal to make a reference DAC easier to live with? To bring a brand’s amplifier heritage into multiroom listening? To give a compact all-in-one system the confidence of a serious source component? The technical choices should serve that promise, not obscure it.

What an audio OEM partnership should provide

An audio OEM relationship is often described as a shortcut to market. Speed matters, but it is not the full value. The right partner gives a brand a mature foundation while leaving room for the product to feel recognizably its own.

That foundation should include dependable playback from local and networked sources, major streaming-service support, a coherent control experience, and an update path that can evolve with changing services and customer expectations. It should also account for the less visible work: certification requirements, security updates, diagnostic tools, provisioning, and the support questions that arrive after thousands of units are in homes.

For a hi-fi manufacturer, this allows internal engineering teams to concentrate on the areas where they create genuine distinction. That may be analog output design, clocking, power supply architecture, industrial design, speaker integration, or a carefully voiced amplifier stage. It is a better use of expertise than repeatedly rebuilding the basic plumbing of digital music playback.

There is a trade-off. A fully bespoke platform can provide maximum control, but it brings a long development cycle and a permanent software obligation. A ready-made platform can launch sooner and benefit from proven behavior, but only if it is flexible enough to support the brand’s hardware, visual language, and intended customer journey. The practical answer is rarely all-or-nothing. Most successful projects pair a stable music platform with purposeful customization.

Differentiation is not just a new control app

It is tempting to define differentiation through appearance alone: a new app skin, a front-panel display, or a distinctive enclosure. These choices matter, particularly in premium audio, where an object should feel at home beside the rest of a system. But the deeper differentiators are often felt rather than announced.

A listener notices whether browsing an album collection is immediate. They notice whether the product wakes reliably, remembers its state, and handles high-resolution playback without ceremony. They notice whether a search result makes sense when local albums and streaming catalog results appear together. Those details create confidence, and confidence gives customers a reason to stay with a product instead of replacing it when their habits change.

A strong platform should therefore be customizable at the level that matters. Manufacturers may need tailored input behavior, unique display flows, product-specific settings, branded onboarding, or integration with their own control ecosystem. The objective is not to make proven software unrecognizable. It is to make the overall experience feel intentional.

Start with the listening journey, then specify the hardware

Hardware requirements become clearer when they are built around real use cases. Consider the difference between a dedicated transport feeding an external DAC and an all-in-one amplifier with streaming built in. Both may share network and software foundations, yet their priorities are different.

The transport owner may expect detailed control over digital outputs, playback formats, and DAC compatibility. The all-in-one owner may value clear setup, volume behavior, input selection, and an interface the entire household can use. A portable or compact product may need fast Wi-Fi provisioning and minimal physical controls. A flagship component may call for a high-resolution display, elaborate metadata presentation, and deep system integration.

These decisions affect processing power, memory, storage, connectivity, display hardware, thermal design, and the relationship between the playback engine and audio board. They also affect the test plan. A product intended for an enthusiast with a wired network and a large library should still be evaluated in the imperfect conditions found in real homes: crowded Wi-Fi, mesh routers, changing passwords, mixed file formats, and family members who expect music to work on the first attempt.

This is where experienced integration pays for itself. The challenge is not merely proving that a prototype plays music in a lab. It is ensuring that the finished product behaves gracefully across a wide range of systems and routines.

Updates are part of the ownership experience

Digital music changes after a product ships. Streaming services adjust their requirements. Mobile operating systems evolve. New playback capabilities emerge. Security expectations rise. A connected component that cannot be maintained gradually becomes less valuable, regardless of the quality of its audio circuitry.

Manufacturers should treat the update strategy as part of the product specification from day one. That means deciding how updates are delivered, how releases are tested, what happens if an installation is interrupted, and how customers learn about useful new features without being overwhelmed by technical detail.

It also means setting honest expectations. Frequent updates are not always a sign of quality if they introduce instability. Conversely, silence is not reassuring when services and devices around the product continue to change. The ideal cadence is measured: regular maintenance, careful validation, and meaningful improvements that respect a customer’s time and listening habits.

A proven platform can reduce this burden because its update mechanisms, device management, and playback behavior have already met a broad community of users. Volumio brings that perspective from an ecosystem shaped by both dedicated hi-fi components and hands-on music lovers building their own players.

The questions worth asking before development begins

Before selecting a software and integration partner, a manufacturer should look beyond the feature checklist. Features can appear equivalent on a presentation slide while the real-world experience differs substantially.

Ask how local libraries are indexed and presented, not only which file formats are supported. Ask how service integrations are maintained when APIs change. Ask whether the platform can accommodate the intended hardware architecture and user interface. Ask how issues are diagnosed after deployment, and who owns each layer of support.

It is also worth asking which parts of the experience can be shaped without creating an expensive fork that becomes difficult to maintain. A good partner will be direct about boundaries. Some standardized behaviors protect reliability and make future updates practical. Other areas should be open to design because they are central to the manufacturer’s identity.

Finally, evaluate the partnership as a long-term collaboration rather than a software purchase. Connected products have a lifecycle. The teams involved need a shared way to prioritize improvements, investigate field issues, and make thoughtful decisions when a new opportunity or constraint appears.

Build for the moment music becomes personal

The most compelling connected components do not ask customers to think about software. They let a favorite album begin with the right sense of occasion, whether it comes from a decades-old local collection or a newly discovered release. The interface recedes, the system feels coherent, and the brand earns trust through every ordinary listening session.

That is the standard worth designing for: not simply a streamer that can connect, but a music experience that gives people another reason to sit down, choose an album, and listen.

The post Audio OEM: Build a Streamer People Want appeared first on Volumio.

12 September, 2026 02:08AM

September 11, 2026

hackergotchi for Univention Corporate Server

Univention Corporate Server

Who Does the Cloud Trust When You Log In?

Around 5,000 Dropbox accounts were accessed using Lenovo IDs that had apparently not been properly verified. The incident highlights an aspect of cloud security that is often overlooked in public debate. This is not about a conventional security vulnerability, but about whose judgement a service relies on when it accepts a login.

Dropbox allows users to sign in with a password or through accounts held with other providers, including Google, Apple and Lenovo. These providers act as authentication services. Users who sign in this way authenticate with the third-party provider. The email address serves as the link between the two services.

Anyone could create a Lenovo ID simply by entering an email address. Lenovo did not, however, check whether the person creating the account actually had access to that mailbox. Anyone who knew or guessed the email address associated with another person’s Dropbox account could therefore create a new Lenovo ID and use it to sign in to Dropbox. Dropbox accepted this as sufficient proof of identity, provided two-factor authentication (2FA) was not enabled for the account. This is how an attacker gained access to the affected accounts.

A successful login says little about someone’s identity

When users sign in to a digital service, another provider often verifies their identity. The application then receives only confirmation that the user has been successfully authenticated. This creates a chain of trust: the application relies on the authentication service, which in turn depends on the reliability of the accounts and evidence it uses.

That is what makes this case significant. No Dropbox password was guessed or stolen. All it took was a Lenovo ID that anyone could create. Dropbox accepted the resulting confirmation without questioning how reliable it was. In other words, a successful login did not answer the crucial question in this case: was the person signing in really who they claimed to be?

This is a significant security risk

An incident like this is serious even for a personal account. When companies store business data in the cloud, trade secrets, personal data, internal communications, and information from customers and partners are at stake.

Few organisations would accept a Lenovo ID for access to their own corporate network. Yet when the same data is accessed through a cloud service, organisations often apply different standards and rely on the provider’s authentication mechanisms.

At a minimum, a service must authenticate employees exclusively through their organisation’s authentication service. It must be possible to disable all other sign-in methods.

Before approving a service such as Dropbox, organisations must therefore establish which identity sources it accepts and how those sources verify identities. They must also check whether additional authentication factors can be made mandatory, who can change these settings, and how access rights are revoked when employees change roles or leave the organisation. These checks remain necessary, regardless of the provider’s size or how well known it is.

Why authentication services should be open source

The same applies to external identity services such as Microsoft Entra ID and Okta. They are often central components of modern IT architectures, but may in turn trust systems that are unknown to the organisations using them. With some caveats, this also applies to directory services operated in-house, such as Active Directory. Without access to the source code, it is impossible to fully verify whether a system contains deliberate or unintended mechanisms for bypassing authentication requirements. Where a service runs does not, by itself, answer that question.

This is why the authentication service itself must be open source and capable of being operated independently. Only when the source code is accessible can organisations examine which bypass mechanisms exist, which dependencies a service has, and which sign-in methods it actually accepts. This also makes independent audits possible. Depending on the solution, organisations retain greater control over how the service is operated and developed.

The German Federal Office for Information Security (BSI) rightly points out that using free and open-source software does not, by itself, guarantee a secure system. Open-source software must still be maintained and operated securely. However, the BSI also notes that open-source software offers significant strategic advantages in managing security. That is where its value lies: open source provides a key foundation for a high level of security.

Digital sovereignty starts with access

Digital sovereignty is often associated with where data is stored or which cloud infrastructure an organisation chooses. Yet it begins with digital identity. An organisation must be able to understand and control who verifies identities, which systems trust one another, and who can change or revoke those relationships. Without that control, it remains unclear on what basis access to the organisation’s data is granted.

By using a cloud service, a company transfers part of its IT operations to an external provider. Responsibility for its data and for access to that data remains with the company.

The Dropbox-Lenovo case is therefore more than an isolated security incident. It illustrates why the sign-in methods used by cloud services matter: one system accepts another system’s assertion and uses it to decide who can access data. The organisation using the service may have no control over that decision.

The key question is: who decides who can access our data, and can we verify that decision?

Source reference: This article is based on the German-language heise report titled “Ich mach mir eine Lenovo-ID und hol mir Deine Dropbox-Dateien,” published on September 2, 2026: https://www.heise.de/news/Fremde-Dropbox-Konten-ueber-Lenovo-ID-zugaenglich-11437565.html.

Der Beitrag Who Does the Cloud Trust When You Log In? erschien zuerst auf Univention.

11 September, 2026 01:50PM by Peter Ganten

hackergotchi for Deepin

Deepin

September 10, 2026

hackergotchi for Volumio

Volumio

OEM Streamer Launch Case Study for Audio Brands

A connected audio product can look finished long before it feels finished. The enclosure may be beautiful, the DAC section may measure well, and the first prototype may play music without issue. But an OEM streamer launch case study reveals where the real work happens: in the moments when a listener moves from a local library to Qobuz, changes rooms, updates firmware, or simply wants an album to begin without thinking about the technology behind it.

For an established audio brand, adding streaming is not just a feature decision. It is a decision about product identity, customer support, software ownership, sound quality, and the speed at which a new product can reach the market. This representative case study follows the path of a premium hi-fi manufacturer preparing its first network streamer. The details are generalized, but the launch questions are familiar to many audio teams.

The Brief: Add Streaming Without Losing the Brand

The manufacturer had earned its reputation through traditional separates: amplification, digital conversion, and carefully voiced analog stages. Its customers valued long product lifecycles, tactile controls, and a presentation that made recordings feel immediate and involving. Yet dealers were increasingly hearing the same request: customers wanted access to streaming services and personal music libraries without adding another app, another remote, or another box of uncertain quality.

The initial brief sounded straightforward. Create a network streamer with a premium digital output, a clear display, support for major music services, and a companion control experience. The product also needed to fit the brand’s industrial design language and sit comfortably in systems ranging from compact integrated amplifiers to reference-level DACs.

The more useful version of the brief was more demanding: make digital music feel like a natural part of the brand’s established listening experience.

That distinction shaped every decision that followed. A generic streaming module could have accelerated the first prototype, but it would have limited differentiation. Building every layer internally would have offered maximum control, but required a software organization, certification effort, and maintenance commitment that the manufacturer was not structured to carry.

The OEM Streamer Launch Case Study: Three Early Decisions

The project began with three decisions that prevented expensive changes later.

1. Define the listening journey before the feature list

The team started with use cases rather than a checklist of protocols. A customer might browse a NAS library by artist, select a radio station during breakfast, hand control to a family member, or use the streamer as a transport into an existing DAC. Each journey had to be clear on a phone or tablet, stable over a home network, and understandable without a manual.

This exposed an early trade-off. More sources and settings can make a product seem more capable, but they can also make it feel less inviting. The team chose to prioritize a unified music experience: local files, streaming services, internet radio, and network playback presented in one coherent environment. Advanced settings remained available, but they did not interrupt the first listen.

2. Establish where sound quality is won or lost

Streaming software does not replace audio engineering. The manufacturer wanted the streamer to preserve the timing, low-level detail, and tonal character that customers associated with its components. That required a clear division of responsibility between the digital transport, clocking approach, power supply design, output stage, and the customer’s downstream equipment.

The OEM platform needed to support the desired audio architecture without forcing a one-size-fits-all sound. In this case, the brand selected a dedicated network and processing section, isolated it carefully from sensitive audio circuitry, and retained control over its output implementation. The software partner supplied the playback intelligence and interface foundation; the audio brand concentrated its effort where its own engineering voice mattered most.

3. Treat updates as part of the product, not a post-launch fix

A network player is never entirely static. Streaming service requirements change. New control features become relevant. Bugs appear in combinations of routers, libraries, and mobile devices that cannot all be predicted in a lab.

The launch plan therefore included a defined firmware-update process, release validation, customer communication, and support escalation path. This was not as visible as the front panel or product photography, but it was essential to protecting dealer confidence after the first units shipped.

From Prototype to a Product People Want to Use

The first engineering sample proved that the selected hardware could play high-resolution music and connect reliably in a controlled environment. It did not yet prove that the product was ready for customers.

The next phase focused on integration. The display needed to feel connected to the control app rather than like a separate system. Input and output labels had to match the language customers would see in setup. Network onboarding had to work for listeners who knew nothing about IP addresses, while still offering useful options to experienced installers. The team also tested how quickly the unit recovered after power interruptions, router restarts, and service sign-ins.

These details influence perceived quality more than many specifications do. A streamer that sounds exceptional but takes several attempts to join a network creates doubt before the first track plays. Conversely, a thoughtfully guided setup gives listeners confidence that the product belongs in their system.

The manufacturer also resisted the temptation to overload the first release. A requested feature that had not been thoroughly tested was deferred rather than added late. That choice can be difficult when launch calendars are tight, but it avoids turning early customers into unpaid beta testers. The strongest first release is not the one with the longest feature list. It is the one that delivers its promised listening experience consistently.

What the OEM Partnership Changed

Working with an experienced streaming platform partner changed the economics and the risk profile of the launch. Instead of creating playback software, app infrastructure, source integrations, account management, and update mechanisms from zero, the manufacturer could build on technology already shaped by real listening habits and a broad device ecosystem.

For a partner such as Volumio, the role is not simply to provide software that plays music. It is to help translate an audio brand’s product vision into a connected experience that feels intentional from setup to daily use. That can include hardware-platform guidance, interface customization, integration support, testing, and an ongoing path for product updates.

This model does involve trade-offs. The manufacturer must align its roadmap with an external platform and agree on responsibilities for support, certification, and release timing. It also needs to decide how much of the user experience should carry its own visual identity versus using familiar platform conventions. Those conversations are productive when they happen at the beginning, not after industrial design and electronics are already fixed.

The Launch Result: Fewer Friction Points, More Listening

At launch, the product was evaluated on more than sound quality. Dealers could demonstrate it without a lengthy explanation. Customers could bring together music services and personal collections in one place. Owners using external DACs had a refined transport option, while listeners building a simpler system could begin with a single component and grow later.

The most meaningful result was not a dramatic specification claim. It was a reduction in friction. Customers spent less time deciding which app to open or which input to select, and more time with the music they already loved.

The support team benefited as well. Because the product had a consistent setup flow and a planned update process, common questions could be identified and resolved systematically. Product feedback became useful input for future software releases rather than a collection of isolated complaints.

Lessons for Audio Brands Planning Their First Streamer

An OEM streaming project succeeds when the hardware, software, and listening experience are planned as one product. Start by deciding what the listener should be able to do in the first five minutes and after five months of ownership. Then build the technical architecture around that reality.

It also helps to be honest about differentiation. An audio brand does not need to reinvent every layer of connected playback to make a distinctive product. Its identity may live in industrial design, sonic voicing, DAC implementation, display behavior, physical controls, dealer relationships, or the way all of those elements work together. The right OEM partner protects room for that identity while removing the burden of rebuilding proven streaming foundations.

Finally, allow enough time for home-network testing. Real homes are less predictable than product labs, and real listeners are less patient than engineering teams. Testing across routers, services, library sizes, and control devices is part of delivering high-fidelity playback, not an administrative step before shipping.

A great streamer should disappear once the music starts. For an audio brand, that is the standard worth designing toward: technology that feels considered, dependable, and fully at home in the listening room.

The post OEM Streamer Launch Case Study for Audio Brands appeared first on Volumio.

10 September, 2026 01:43AM

OEM Streamer Launch Case Study for Audio Brands

A connected audio product can look finished long before it feels finished. The enclosure may be beautiful, the DAC section may measure well, and the first prototype may play music without issue. But an OEM streamer launch case study reveals where the real work happens: in the moments when a listener moves from a local library to Qobuz, changes rooms, updates firmware, or simply wants an album to begin without thinking about the technology behind it.

For an established audio brand, adding streaming is not just a feature decision. It is a decision about product identity, customer support, software ownership, sound quality, and the speed at which a new product can reach the market. This representative case study follows the path of a premium hi-fi manufacturer preparing its first network streamer. The details are generalized, but the launch questions are familiar to many audio teams.

The Brief: Add Streaming Without Losing the Brand

The manufacturer had earned its reputation through traditional separates: amplification, digital conversion, and carefully voiced analog stages. Its customers valued long product lifecycles, tactile controls, and a presentation that made recordings feel immediate and involving. Yet dealers were increasingly hearing the same request: customers wanted access to streaming services and personal music libraries without adding another app, another remote, or another box of uncertain quality.

The initial brief sounded straightforward. Create a network streamer with a premium digital output, a clear display, support for major music services, and a companion control experience. The product also needed to fit the brand’s industrial design language and sit comfortably in systems ranging from compact integrated amplifiers to reference-level DACs.

The more useful version of the brief was more demanding: make digital music feel like a natural part of the brand’s established listening experience.

That distinction shaped every decision that followed. A generic streaming module could have accelerated the first prototype, but it would have limited differentiation. Building every layer internally would have offered maximum control, but required a software organization, certification effort, and maintenance commitment that the manufacturer was not structured to carry.

The OEM Streamer Launch Case Study: Three Early Decisions

The project began with three decisions that prevented expensive changes later.

1. Define the listening journey before the feature list

The team started with use cases rather than a checklist of protocols. A customer might browse a NAS library by artist, select a radio station during breakfast, hand control to a family member, or use the streamer as a transport into an existing DAC. Each journey had to be clear on a phone or tablet, stable over a home network, and understandable without a manual.

This exposed an early trade-off. More sources and settings can make a product seem more capable, but they can also make it feel less inviting. The team chose to prioritize a unified music experience: local files, streaming services, internet radio, and network playback presented in one coherent environment. Advanced settings remained available, but they did not interrupt the first listen.

2. Establish where sound quality is won or lost

Streaming software does not replace audio engineering. The manufacturer wanted the streamer to preserve the timing, low-level detail, and tonal character that customers associated with its components. That required a clear division of responsibility between the digital transport, clocking approach, power supply design, output stage, and the customer’s downstream equipment.

The OEM platform needed to support the desired audio architecture without forcing a one-size-fits-all sound. In this case, the brand selected a dedicated network and processing section, isolated it carefully from sensitive audio circuitry, and retained control over its output implementation. The software partner supplied the playback intelligence and interface foundation; the audio brand concentrated its effort where its own engineering voice mattered most.

3. Treat updates as part of the product, not a post-launch fix

A network player is never entirely static. Streaming service requirements change. New control features become relevant. Bugs appear in combinations of routers, libraries, and mobile devices that cannot all be predicted in a lab.

The launch plan therefore included a defined firmware-update process, release validation, customer communication, and support escalation path. This was not as visible as the front panel or product photography, but it was essential to protecting dealer confidence after the first units shipped.

From Prototype to a Product People Want to Use

The first engineering sample proved that the selected hardware could play high-resolution music and connect reliably in a controlled environment. It did not yet prove that the product was ready for customers.

The next phase focused on integration. The display needed to feel connected to the control app rather than like a separate system. Input and output labels had to match the language customers would see in setup. Network onboarding had to work for listeners who knew nothing about IP addresses, while still offering useful options to experienced installers. The team also tested how quickly the unit recovered after power interruptions, router restarts, and service sign-ins.

These details influence perceived quality more than many specifications do. A streamer that sounds exceptional but takes several attempts to join a network creates doubt before the first track plays. Conversely, a thoughtfully guided setup gives listeners confidence that the product belongs in their system.

The manufacturer also resisted the temptation to overload the first release. A requested feature that had not been thoroughly tested was deferred rather than added late. That choice can be difficult when launch calendars are tight, but it avoids turning early customers into unpaid beta testers. The strongest first release is not the one with the longest feature list. It is the one that delivers its promised listening experience consistently.

What the OEM Partnership Changed

Working with an experienced streaming platform partner changed the economics and the risk profile of the launch. Instead of creating playback software, app infrastructure, source integrations, account management, and update mechanisms from zero, the manufacturer could build on technology already shaped by real listening habits and a broad device ecosystem.

For a partner such as Volumio, the role is not simply to provide software that plays music. It is to help translate an audio brand’s product vision into a connected experience that feels intentional from setup to daily use. That can include hardware-platform guidance, interface customization, integration support, testing, and an ongoing path for product updates.

This model does involve trade-offs. The manufacturer must align its roadmap with an external platform and agree on responsibilities for support, certification, and release timing. It also needs to decide how much of the user experience should carry its own visual identity versus using familiar platform conventions. Those conversations are productive when they happen at the beginning, not after industrial design and electronics are already fixed.

The Launch Result: Fewer Friction Points, More Listening

At launch, the product was evaluated on more than sound quality. Dealers could demonstrate it without a lengthy explanation. Customers could bring together music services and personal collections in one place. Owners using external DACs had a refined transport option, while listeners building a simpler system could begin with a single component and grow later.

The most meaningful result was not a dramatic specification claim. It was a reduction in friction. Customers spent less time deciding which app to open or which input to select, and more time with the music they already loved.

The support team benefited as well. Because the product had a consistent setup flow and a planned update process, common questions could be identified and resolved systematically. Product feedback became useful input for future software releases rather than a collection of isolated complaints.

Lessons for Audio Brands Planning Their First Streamer

An OEM streaming project succeeds when the hardware, software, and listening experience are planned as one product. Start by deciding what the listener should be able to do in the first five minutes and after five months of ownership. Then build the technical architecture around that reality.

It also helps to be honest about differentiation. An audio brand does not need to reinvent every layer of connected playback to make a distinctive product. Its identity may live in industrial design, sonic voicing, DAC implementation, display behavior, physical controls, dealer relationships, or the way all of those elements work together. The right OEM partner protects room for that identity while removing the burden of rebuilding proven streaming foundations.

Finally, allow enough time for home-network testing. Real homes are less predictable than product labs, and real listeners are less patient than engineering teams. Testing across routers, services, library sizes, and control devices is part of delivering high-fidelity playback, not an administrative step before shipping.

A great streamer should disappear once the music starts. For an audio brand, that is the standard worth designing toward: technology that feels considered, dependable, and fully at home in the listening room.

The post OEM Streamer Launch Case Study for Audio Brands appeared first on Volumio.

10 September, 2026 01:43AM

September 09, 2026

hackergotchi for Deepin

Deepin

hackergotchi for Qubes

Qubes

Qubes Canary 048

We have published Qubes Canary 048. The text of this canary and its accompanying cryptographic signatures are reproduced below. For an explanation of this announcement and instructions for authenticating this canary, please see the end of this announcement.

Qubes Canary 048


                    ---===[ Qubes Canary 048 ]===---


Statements
-----------

The Qubes security team members who have digitally signed this file [1]
state the following:

1. The date of issue of this canary is September 09, 2026.

2. There have been 118 Qubes security bulletins published so far.

3. The Qubes Master Signing Key fingerprint is:

       427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494

4. No warrants have ever been served to us with regard to the Qubes OS
   Project (e.g. to hand out the private signing keys or to introduce
   backdoors).

5. We plan to publish the next of these canary statements in the first
   fourteen days of December 2026. Special note should be taken if no new
   canary is published by that time or if the list of statements changes
   without plausible explanation.


Special announcements
----------------------

None.


Disclaimers and notes
----------------------

We would like to remind you that Qubes OS has been designed under the
assumption that all relevant infrastructure is permanently compromised.
This means that we assume NO trust in any of the servers or services
which host or provide any Qubes-related data, in particular, software
updates, source code repositories, and Qubes ISO downloads.

This canary scheme is not infallible. Although signing the declaration
makes it very difficult for a third party to produce arbitrary
declarations, it does not prevent them from using force or other means,
like blackmail or compromising the signers' laptops, to coerce us to
produce false declarations.

The proof of freshness provided below serves to demonstrate that this
canary could not have been created prior to the date stated. It shows
that a series of canaries was not created in advance.

This declaration is merely a best effort and is provided without any
guarantee or warranty. It is not legally binding in any way to anybody.
None of the signers should be ever held legally responsible for any of
the statements made here.


Proof of freshness
-------------------

Wed, 09 Sep 2026 06:09:30 +0000

Source: DER SPIEGEL - International (https://www.spiegel.de/international/index.rss)
Fake Jewish Lineage: The Passport Scheme that Exploited Germany’s Nazi History
BYD, Geely, Xpeng: Germany’s Vaunted Auto Industry in Dire Straits Amid Chinese Surge
Amodei vs. Altman: How the Race for AI Dominance Is Increasing the Risks
Boats from Eastern Libya: How Europe Is Bowing to a Libyan Warlord on Migration
Moaning for the Mainland: How Taiwan Satisfies China's Lust for Pornography

Source: NYT > World News (https://rss.nytimes.com/services/xml/rss/nyt/World.xml)
AfD’s Far Right Win Puts New Pressure on Germany’s Leader Merz
Chinese Ship Takes Arctic Shortcut: Smart Business? Or a Political Flex?
Israeli Allies Ban Trade With Settlements as U.K. Cites ‘Ethnic Cleansing’
Saudi Arabia and Yemen’s Houthis Edge Back to the Brink of War
Carney Says Retaliation Against U.S. Tariffs Was Unavoidable

Source: BBC News (https://feeds.bbci.co.uk/news/world/rss.xml)
US strikes Iranian oil tankers as Tehran targets American base in Jordan
Paul Adams: British-Israeli relations at lowest ebb in decades
US slaps import ban on Canadian alcohol, motorbikes and other goods
'Constantly on my mind' - 9/11 agony endures for bereaved, 25 years on
South Park creators rename show 'South America' in apparent dig at Trump

Source: Blockchain.info
000000000000000000017721d9b2add64d85980a3bb8587851798bb854c3d514


Footnotes
----------

[1] This file should be signed in two ways: (1) via detached PGP
signatures by each of the signers, distributed together with this canary
in the qubes-secpack.git repo, and (2) via digital signatures on the
corresponding qubes-secpack.git repo tags. [2]

[2] Don't just trust the contents of this file blindly! Verify the
digital signatures! Instructions for doing so are documented here:
https://doc.qubes-os.org/en/latest/project-security/security-pack.html

--
The Qubes Security Team
https://www.qubes-os.org/security/

Source: canary-048-2026.txt

Marek Marczykowski-Górecki’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmqhJaEACgkQ1lWk8hgw
4GpAUA//dvesbc30xLrZ5hRrJgPBBOaMIXjLZk2il/EljKLAMLdPOk5Y01kNLLGS
nvnLU0M5U8y1Oqlfj7WybABht8SrPSBg9gI1CrRvA69urz5V6VHDUsqAMhXozdLK
FgT4+SuQfiAvlXOdjPljcZO4jWXWcQMWjecYTTiQdnMNC90VkrncYjNeioh6rhaL
oCim2t5ynb9wpyo7zzG9KNDtDUzPSAphSZoJhb3PJXNOxHV6RLsyoz9b1wa1c3xp
IJdS1EzMf/1/bmlZwg9FnLcGVOO/TdyOSKxP4d54SVt/JmYfpk2qAVfn/NWjlzVc
LqcwebzGHQ56A4kyvc04PEuMzryneYDmxboKtwKUnOyMdnOxHtpbqh/jX6T/GodA
wO8oJdoT5l1ugLfFK/sGluSx6FnFoczgukFxk+cIn3l38mEUAQLshWRNL3gk8LkW
cKTFBBntwlV2XfmJBFhOM4s6N74RTrNhxWlsgT4LyOCcFRIT8CCLicmvmxSgjWJo
v3p+pKqLNFe0GU64KUlt3Fvc0m4hyvxPZbmzA/UOevMzssX5BHkRXQDJaknLppy+
yZp/gfBX575wlgWn+khXPYQSIcHyEuZifZoMaGnfU0OgjPMcmC4SY9xQf2cH/dN+
gTyhd0+s9RfyWDdA2l1ZvG10t1Pz5SIJecPXHFMk+F6qHEpjezI=
=wcFj
-----END PGP SIGNATURE-----

Source: canary-048-2026.txt.sig.marmarek

Simon Gaiser (aka HW42)’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqhK+QACgkQSsGN4REu
FJCzHQ//ejKjw9KcCp8EKE/pMMSeCHmIOBDqZFsM0Ifo4rzyCVc2TqLZ6K0JviuQ
5otz/lor5rI4Z1wCR4fZO7YwWHewaX7w7yILp6tRV+9el22lhWPJMl7BavjBK92d
8WUiuab0DrlxROUDtm62mgzQ5dHcqQjj/bZZhSeq/69e/L3OJsWclOdAOt+LjSUa
rXYD+bB23PZh3FGdvW0znTLbs/0XpH+RmDld8LbQvbZP6LH1+751Xxz6qe7sFOIa
iIxDuUlqo9ZU43enZhN0Vug+wGltiZk3njzpPvvURKNGWyrZKo4m8tR1BdoJ+8Qy
KasUPBOWrZh99IFonBCAUY5dFJScujtOWh/nihbX531nnV7X1XkUc2rieaW7zGye
brxjG4s3h4/r6IfH3K38cCLw3m5luvSmOm0F1zt9xthnUp7PnNK+qOOkPNzWptsA
upPVS/rjPlfAm01GDU+aqWVpv4kF74TGTMnQj112eRz+LyEnrx9LWqJZ4YsrvgYP
OsrCPnfCPF0fgNsKKbMJ12b17rIXGXw/aKEqL/V3XVJUKbaGTlJU8GbBsQG7a1oD
JpEWdU7I7RR40UXwGHNUnS5bSCVdAhlNEs/tnyWW2zEScAkZXu/wJTGaPA6wcTkd
l1Um8S7H4Q2rRTCMGziJHjTUjdlMegcjrkEmHOzM3r78fCsZJgY=
=vexT
-----END PGP SIGNATURE-----

Source: canary-048-2026.txt.sig.simon

What is the purpose of this announcement?

The purpose of this announcement is to inform the Qubes community that a new Qubes canary has been published.

What is a Qubes canary?

A Qubes canary is a security announcement periodically issued by the Qubes security team consisting of several statements to the effect that the signers of the canary have not been compromised. The idea is that, as long as signed canaries including such statements continue to be published, all is well. However, if the canaries should suddenly cease, if one or more signers begin declining to sign them, or if the included statements change significantly without plausible explanation, then this may indicate that something has gone wrong.

The name originates from the practice in which miners would bring caged canaries into coal mines. If the level of methane gas in the mine reached a dangerous level, the canary would die, indicating to miners that they should evacuate. (See the Wikipedia article on warrant canaries for more information, but bear in mind that Qubes Canaries are not strictly limited to legal warrants.)

Why should I care about canaries?

Canaries provide an important indication about the security status of the project. If the canary is healthy, it’s a strong sign that things are running normally. However, if the canary is unhealthy, it could mean that the project or its members are being coerced in some way.

What are some signs of an unhealthy canary?

Here is a non-exhaustive list of examples:

  • Dead canary. In each canary, we state a window of time during which you should expect the next canary to be published. If no canary is published within that window of time and no good explanation is provided for missing the deadline, then the canary has died.
  • Missing statement(s). Canaries include a set of numbered statements at the top. These statements are generally the same across canaries, except for specific numbers and dates that have changed since the previous canary. If an important statement was present in older canaries but suddenly goes missing from new canaries with no correction or explanation, then this may be an indication that the signers can no longer truthfully make that statement.
  • Missing signature(s). Qubes canaries are signed by the members of the Qubes security team (see below). If one of them has been signing all canaries but suddenly and permanently stops signing new canaries without any explanation, then this may indicate that this person is under duress or can no longer truthfully sign the statements contained in the canary.

No, there are many canary-related possibilities that should not worry you. Here is a non-exhaustive list of examples:

  • Unusual reposts. The only canaries that matter are the ones that are validly signed in the Qubes security pack (qubes-secpack). Reposts of canaries (like the one in this announcement) do not have any authority (except insofar as they reproduce validly-signed text from the qubes-secpack). If the actual canary in the qubes-secpack is healthy, but reposts are late, absent, or modified on the website, mailing lists, forum, or social media platforms, you should not be concerned about the canary.
  • Last-minute signature(s). If the canary is signed at the last minute but before the deadline, that’s okay. (People get busy and procrastinate sometimes.)
  • Signatures at different times. If one signature is earlier or later than the other, but both are present within a reasonable period of time, that’s okay. (For example, sometimes one signer is out of town, but we try to plan the deadlines around this.)
  • Permitted changes. If something about a canary changes without violating any of the statements in prior canaries, that’s okay. (For example, canaries are usually scheduled for the first fourteen days of a given month, but there’s no rule that says they have to be.)
  • Unusual but planned changes. If something unusual happens, but it was announced in advance, and the appropriate statements are signed, that’s okay (e.g., when Joanna left the security team and Simon joined it).

In general, it would not be realistic for an organization to exist that never changed, had zero turnover, and never made mistakes. Therefore, it would be reasonable to expect such events to occur periodically, and it would be unreasonable to regard every unusual or unexpected canary-related event as a sign of compromise. For example, if something usual happens with a canary, and we say it was a mistake and correct it (with valid signatures), you will have to decide for yourself whether it’s more likely that it really was just a mistake or that something is wrong and that this is how we chose to send you a subtle signal about it. This will require you to think carefully about which among many possible scenarios is most likely given the evidence available to you. Since this is fundamentally a matter of judgment, canaries are ultimately a social scheme, not a technical one.

What are the PGP signatures that accompany canaries?

A PGP signature is a cryptographic digital signature made in accordance with the OpenPGP standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG). The Qubes security team cryptographically signs all canaries so that Qubes users have a reliable way to check whether canaries are genuine. The only way to be certain that a canary is authentic is by verifying its PGP signatures.

Why should I care whether a canary is authentic?

If you fail to notice that a canary is unhealthy or has died, you may continue to trust the Qubes security team even after they have signaled via the canary (or lack thereof) that they been compromised or coerced.

Alternatively, an adversary could fabricate a canary in an attempt to deceive the public. Such a canary would not be validly signed, but users who neglect to check the signatures on the fake canary would not be aware of this, so they may mistakenly believe it to be genuine, especially if it closely mimics the language of authentic canaries. Such falsified canaries could include manipulated text designed to sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.

How do I verify the PGP signatures on a canary?

The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software.)

  1. Obtain the Qubes Master Signing Key (QMSK), e.g.:

    $ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
    gpg: directory '/home/user/.gnupg' created
    gpg: keybox '/home/user/.gnupg/pubring.kbx' created
    gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
    gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
    gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported
    gpg: Total number processed: 1
    gpg:               imported: 1
    

    (For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key.)

  2. View the fingerprint of the PGP key you just imported. (Note: gpg> indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)

    $ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
    gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.
       
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    gpg> fpr
    pub   rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
     Primary key fingerprint: 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
    
  3. Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key.

    Tip: After you have authenticated the QMSK out-of-band to your satisfaction, record the QMSK fingerprint in a safe place (or several) so that you don’t have to repeat this step in the future.

  4. Once you are satisfied that you have the genuine QMSK, set its trust level to 5 (“ultimate”), then quit GnuPG with q.

    gpg> trust
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    Please decide how far you trust this user to correctly verify other users' keys
    (by looking at passports, checking fingerprints from different sources, etc.)
       
      1 = I don't know or won't say
      2 = I do NOT trust
      3 = I trust marginally
      4 = I trust fully
      5 = I trust ultimately
      m = back to the main menu
       
    Your decision? 5
    Do you really want to set this key to ultimate trust? (y/N) y
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: ultimate      validity: unknown
    [ unknown] (1). Qubes Master Signing Key
    Please note that the shown key validity is not necessarily correct
    unless you restart the program.
       
    gpg> q
    
  5. Use Git to clone the qubes-secpack repo.

    $ git clone https://github.com/QubesOS/qubes-secpack.git
    Cloning into 'qubes-secpack'...
    remote: Enumerating objects: 4065, done.
    remote: Counting objects: 100% (1474/1474), done.
    remote: Compressing objects: 100% (742/742), done.
    remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591
    Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done.
    Resolving deltas: 100% (1910/1910), done.
    
  6. Import the included PGP keys. (See our PGP key policies for important information about these keys.)

    $ gpg --import qubes-secpack/keys/*/*
    gpg: key 063938BA42CFA724: public key "Marek Marczykowski-Górecki (Qubes OS signing key)" imported
    gpg: qubes-secpack/keys/core-devs/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 8C05216CE09C093C: 1 signature not checked due to a missing key
    gpg: key 8C05216CE09C093C: public key "HW42 (Qubes Signing Key)" imported
    gpg: key DA0434BC706E1FCF: public key "Simon Gaiser (Qubes OS signing key)" imported
    gpg: key 8CE137352A019A17: 2 signatures not checked due to missing keys
    gpg: key 8CE137352A019A17: public key "Andrew David Wong (Qubes Documentation Signing Key)" imported
    gpg: key AAA743B42FBC07A9: public key "Brennan Novak (Qubes Website & Documentation Signing)" imported
    gpg: key B6A0BB95CA74A5C3: public key "Joanna Rutkowska (Qubes Documentation Signing Key)" imported
    gpg: key F32894BE9684938A: public key "Marek Marczykowski-Górecki (Qubes Documentation Signing Key)" imported
    gpg: key 6E7A27B909DAFB92: public key "Hakisho Nukama (Qubes Documentation Signing Key)" imported
    gpg: key 485C7504F27D0A72: 1 signature not checked due to a missing key
    gpg: key 485C7504F27D0A72: public key "Sven Semmler (Qubes Documentation Signing Key)" imported
    gpg: key BB52274595B71262: public key "unman (Qubes Documentation Signing Key)" imported
    gpg: key DC2F3678D272F2A8: 1 signature not checked due to a missing key
    gpg: key DC2F3678D272F2A8: public key "Wojtek Porczyk (Qubes OS documentation signing key)" imported
    gpg: key FD64F4F9E9720C4D: 1 signature not checked due to a missing key
    gpg: key FD64F4F9E9720C4D: public key "Zrubi (Qubes Documentation Signing Key)" imported
    gpg: key DDFA1A3E36879494: "Qubes Master Signing Key" not changed
    gpg: key 1848792F9E2795E9: public key "Qubes OS Release 4 Signing Key" imported
    gpg: qubes-secpack/keys/release-keys/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key D655A4F21830E06A: public key "Marek Marczykowski-Górecki (Qubes security pack)" imported
    gpg: key ACC2602F3F48CB21: public key "Qubes OS Security Team" imported
    gpg: qubes-secpack/keys/security-team/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 4AC18DE1112E1490: public key "Simon Gaiser (Qubes Security Pack signing key)" imported
    gpg: Total number processed: 17
    gpg:               imported: 16
    gpg:              unchanged: 1
    gpg: marginals needed: 3  completes needed: 1  trust model: pgp
    gpg: depth: 0  valid:   1  signed:   6  trust: 0-, 0q, 0n, 0m, 0f, 1u
    gpg: depth: 1  valid:   6  signed:   0  trust: 6-, 0q, 0n, 0m, 0f, 0u
    
  7. Verify signed Git tags.

    $ cd qubes-secpack/
    $ git tag -v `git describe`
    object 266e14a6fae57c9a91362c9ac784d3a891f4d351
    type commit
    tag marmarek_sec_266e14a6
    tagger Marek Marczykowski-Górecki 1677757924 +0100
       
    Tag for commit 266e14a6fae57c9a91362c9ac784d3a891f4d351
    gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    

    The exact output will differ, but the final line should always start with gpg: Good signature from... followed by an appropriate key. The [full] indicates full trust, which this key inherits in virtue of being validly signed by the QMSK.

  8. Verify PGP signatures, e.g.:

    $ cd QSBs/
    $ gpg --verify qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify qsb-087-2022.txt.sig.simon qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    $ cd ../canaries/
    $ gpg --verify canary-034-2023.txt.sig.marmarek canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify canary-034-2023.txt.sig.simon canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    

    Again, the exact output will differ, but the final line of output from each gpg --verify command should always start with gpg: Good signature from... followed by an appropriate key.

For this announcement (Qubes Canary 048), the commands are:

$ gpg --verify canary-048-2026.txt.sig.marmarek canary-048-2026.txt
$ gpg --verify canary-048-2026.txt.sig.simon canary-048-2026.txt

You can also verify the signatures directly from this announcement in addition to or instead of verifying the files from the qubes-secpack. Simply copy and paste the Qubes Canary 048 text into a plain text file and do the same for both signature files. Then, perform the same authentication steps as listed above, substituting the filenames above with the names of the files you just created.

09 September, 2026 12:00AM

September 08, 2026

hackergotchi for ZEVENET

ZEVENET

The Human Side of Cybersecurity: How to Make Security Content More Engaging

Cybersecurity often involves technical terminology, complex technologies, and serious warnings. While all of these are important, people still play a critical role in keeping organizations secure. Employees need to know how to recognize a phishing email, customers should understand how to behave safely online, and website users need to know how to protect their data.

The harder security information is to understand and the more formal or technical the language, the less likely people are to pay attention to it.

Making cybersecurity content engaging does not mean trivializing the subject. It means communicating important information in a way that is clear, relatable, and memorable. Simple language, relevant examples, visual content, and even appropriate humor can make security communication far more effective.

Why Human-Friendly Security Content Matters

Technical security concepts can quickly become overwhelming for people who do not work in IT. Terms such as phishing, credential stuffing, DDoS attacks, and zero-day vulnerabilities may be familiar to cybersecurity professionals, but they can be confusing to employees and customers.

A more human-centered approach can make security content easier to understand and engage with. Instead of explaining every technical detail of a threat, focus on what it means, why it matters, and what people can do about it.

For example, instead of explaining that phishing attacks use social engineering techniques to steal login credentials, consider a more relatable scenario: “Imagine receiving a fake email that appears to come from your bank. Before entering your password, check that you are actually on the bank’s legitimate website.”

This gives readers practical knowledge they can apply in a real-world situation.

Turn Technical Ideas Into Everyday Situations

Real-world examples are particularly useful because they help people recognize threats when they encounter them.

A security article might use familiar situations such as a fake delivery notification, an unexpected password reset request, or a suspicious login alert.

This creates a connection between an abstract cyber threat and something the reader already recognizes, making the threat easier to understand and remember.

Use Visuals to Explain Security Concepts

Most people can process visual information more quickly than lengthy technical explanations. Diagrams, screenshots, graphics, and even simple illustrations can help explain how an attack works and what users should do to protect themselves.

For example, a simple visual could highlight the differences between a legitimate login page and a phishing page. Another could illustrate the steps someone should follow when evaluating a suspicious email.

Make Security Content More Memorable With Humor

Not everything about cybersecurity has to be frightening. Used appropriately, humor can make educational content more relatable, particularly when addressing common mistakes people make in their everyday digital lives.

Memes, for example, can be an effective way to communicate simple security tips through familiar situations and clear messages. A security team might create a humorous image about using the same password for every account or clicking a link from an unknown sender without checking where it came from.

Using a meme generator can help teams turn everyday security situations into entertaining visuals that employees are more likely to remember.

However, humor should never undermine the main security message. Jokes about victims, security breaches, financial losses, or other serious incidents should be avoided.

Encourage People to Take Action

Good security content should always give readers a clear next step. Explaining a threat without showing people what they can do about it may leave them informed, but not necessarily prepared.

Useful actions might include:

  • Enable multi-factor authentication on important accounts.
  • Use strong, unique passwords and a reputable password manager.
  • Check links and sender addresses before clicking or opening anything.
  • Report suspicious messages to the appropriate security team.
  • Keep operating systems, browsers, and applications up to date.

These recommendations should also reflect the needs of the audience. An employee may need clear instructions on how to report a phishing email, while a website owner may need guidance on protecting an application against automated attacks or large volumes of malicious traffic.

Make Security a Conversation

Security awareness is more effective when people feel comfortable asking questions.

Organizations can encourage this through newsletters, short training sessions, internal communications, quizzes, and other educational resources. Security teams do not have to wait until something goes wrong to communicate with employees; they can share useful advice on a regular basis.

This helps make cybersecurity part of employees’ everyday routines while also giving them opportunities to learn from common mistakes and real-world situations.

Build Trust Through Clear Communication

Trust is essential to effective cybersecurity communication. People need to feel that the security information they receive is relevant, understandable, and useful.

Avoid unnecessary jargon and technical concepts that your audience may not understand. When technical terminology is necessary, explain it in clear and accessible language.

A more approachable tone can also make security messages more effective. It is possible to capture people’s attention without frightening them, particularly when clear explanations, relatable examples, and useful visuals are used together.

Conclusion

Cybersecurity may be a highly technical field, but people remain a critical part of keeping organizations secure.

By using simple language, relatable examples, relevant visuals, and appropriate humor, companies can create security content that is easier to understand and remember.

The goal is not simply to make cybersecurity more engaging. It is to help people understand the risks they face, recognize potential threats, and know what actions they can take to improve their security.

08 September, 2026 03:12PM by Isabel Perez

hackergotchi for ARMBIAN

ARMBIAN

Github Highlights

Github Highlights

This cycle centers on Linux 7.2/7.3 kernel enablement across out-of-tree drivers, new board support and platform fixes across Rockchip, SpacemiT, and Amlogic, and a broad documentation and CI cleanup.

Kernel progression dominated the driver ecosystem, with 7.3 patch sets prepared for rockchip64, meson64, and the UEFI targets, and edge bumps to 7.2.3 landing for qcs6490, qrb2210, and sc8280xp. A wave of Wi‑Fi drivers was re-enabled and bumped for 7.3 compatibility, including rtl8189es/fs, rtl8192eu, rtl8723ds, rtl8852bs, uwe5622, and bcmdhd-dkms, most addressing the strncpy removal and the cfg80211 remain_on_channel cookie signature change. The rk35xx vendor kernel also advanced to the 6.1.172 rkr7.2 SDK.

Board and platform work introduced GL.iNet GL-MT2500, Xiangcheng XC3399FR, and NanoPi R28S, alongside U-Boot bumps to v2026.07 for Helios64, Odroid N2, Khadas VIM3L, and Mixtile Core3588e. Notable hardware corrections include a cold-boot switch fix on BananaPi R2, RK808 LDO mapping repair on Firefly RK3399 to restore analog audio, RTC correction on Orange Pi Zero 3W, an MSDOS partition table workaround for GPT/eGON on Orange Pi 4A, and SPI controller selection on NanoPi NEO3 Plus. SpacemiT K3 saw defconfig refinements and a transition from extlinux to boot.scr on the Pico ITX.

Infrastructure work focused on documentation consolidation and workflow hardening: a new "Armbian vs Debian & Ubuntu" comparison page, pinned third-party actions with scoped GITHUB_TOKEN, removal of dead PDF plumbing and unused announce workflows, and CI adjustments including GHCR visibility reporting and a lower stall-retry threshold in the SDK. The configng TUI received usability improvements to help text and top-level navigation.

#Armbian #EmbeddedLinux #Rockchip #LinuxKernel #SBC

Changes

08 September, 2026 01:36PM by Michael Robinson

hackergotchi for Univention Corporate Server

Univention Corporate Server

See Everything: Visualizing Nubus Metrics with Prometheus and Grafana

The metrics endpoint in UCS 5.2 delivers the raw data, Prometheus stores it, Grafana turns it into a graph. Give it a little time and you stop reading numbers off a screen—you start seeing how your Nubus instance is changing.

 

How many user accounts right now? How close are we to the license limit? What patch level are we on? If you run a Nubus environment, you know these questions. Until now, the answers lived in the portal or on the command line.

Thats’s what errata level 410 for UCS 5.2-5 changed. Nubus now exposes a metrics endpoint for the UDM REST API that reports the key numbers in Prometheus format. Admins can pull them in seconds, keep them for later, and also graph them in Grafana.

So let’s do that. This article takes you from the raw endpoint to a Prometheus collector, and ends up with a Grafana dashboard actually worth watching. By the time you’re done, you’ll know exactly where your Nubus instance stands and which way it’s going.

Pulling Nubus Metrics from the UDM REST API

The metrics endpoint is part of the UDM REST API, protected by HTTP basic auth (username and password go in the request header). You’ll find it at /univention/udm/-/metrics. Access goes to members of the udm-rest-metrics group, plus any account that can already reach the UDM REST API. That includes the Administrator account, which is what we’ll use here to keep things simple. In production, set up a dedicated account and add it to the udm-rest-metrics group.

A single curl call is enough to grab the current metrics:

:~# curl -k -u Administrator:<password> https://<nubus-host>/univention/udm/-/metrics
# HELP nubus_ucs_version_info UCS version information
# TYPE nubus_ucs_version_info gauge
nubus_ucs_version_info{domain="nubus.example",errata="515",license_uuid="dce67f03-e7b2-4a6b-92f7-c4777dac6ef5",patch="6",system_uuid="1847168b-4caf-418c-a741-edaec5fc8978",ucs="5.2"} 1.0
# HELP nubus_n4k_version_info Nubus for Kubernetes version information
# TYPE nubus_n4k_version_info gauge
# HELP nubus_users_user_total Total number of UDM objects of type users/user
# TYPE nubus_users_user_total gauge
nubus_users_user_total{domain="nubus.example",license_uuid="dce67f03-e7b2-4a6b-92f7-c4777dac6ef5",platform="ucs"} 949.0
# HELP nubus_settings_license_users_limit_total Number of active users permitted by the installed license
# TYPE nubus_settings_license_users_limit_total gauge
nubus_settings_license_users_limit_total{domain="nubus.example",license_uuid="dce67f03-e7b2-4a6b-92f7-c4777dac6ef5",platform="ucs"} +Inf

 

Replace <password> in the command with the password for the Administrator account. The response comes back in the Prometheus exposition format: plain text that Prometheus reads directly. Right now the endpoint serves three metrics:

  • nubus_ucs_version_info shows the full version info for the instance. The actual values live in the labels: ucs, patch, and errata describe the software level, while domain and system_uuid identify the installation uniquely.
  • nubus_users_user_total counts the active, managed user accounts in the Nubus domain. Disabled accounts and system accounts don’t count; this is the same number the license check uses.
  • nubus_settings_license_users_limit_total shows the maximum number of active user accounts allowed under the installed license. With no license limit, the endpoint returns +Inf or -1, which is what you’ll see in our test setup running the Core Edition.

Which version metric the endpoint fills with values depends on the deployment type. In a UCS environment like the one here, nubus_ucs_version_info reports the version, patch level, and errata status. In a Kubernetes environment, nubus_n4k_version_info reports the Kubernetes-specific version details. Whichever metric doesn’t apply still shows up in the output—as a header line with no data.

One label stands out: domain. It appears on every metric and ties each value cleanly to a specific Nubus domain. If you monitor several instances later on, that’s the field that keeps them apart.

Setting Up Prometheus and Grafana Fast (for Testing)

This article assumes you’ve already got Prometheus and Grafana running in your environment. To try the new endpoint first, spin up a test setup with Docker Compose in a few minutes. Create a directory for the configuration (e.g. /root/monitoring) and save the following compose.yml file in that directory:

services:
  prometheus:
    image: prom/prometheus:latest
    container_name: prometheus
    ports:
      - "9090:9090"
    volumes:
      - ./prometheus.yml:/etc/prometheus/prometheus.yml:ro
      - prometheus_data:/prometheus
    extra_hosts:
      - "host.docker.internal:host-gateway"
    restart: unless-stopped
  grafana:
    image: grafana/grafana-oss:latest
    container_name: grafana
    ports:
      - "3000:3000"
    volumes:
      - grafana_data:/var/lib/grafana
    environment:
      - GF_SECURITY_ADMIN_PASSWORD=admin
    restart: unless-stopped
volumes:
  prometheus_data:
  grafana_data:

 

The extra_hosts entry lets the Prometheus container reach the Nubus host by the name host.docker.internal, regardless of its IP address. In the same directory, create a prometheus.yml with the scrape job from the next section. For the test setup, set host.docker.internal as the value under targets. Then bring the stack up with docker-compose up -d. Grafana is now available at http://<host>:3000 (default login admin/admin, which you’ll change on first use), and Prometheus’s web interface at http://<host>:9090.

Configuring Prometheus for Nubus

Prometheus actively queries the metrics from the endpoints it monitors (that’s called “scraping”) and stores them in its own time series database. To connect Nubus, add a new scrape job to your prometheus.yml:

global:
  scrape_interval: 30s

scrape_configs:
  - job_name: 'nubus'
    metrics_path: '/univention/udm/-/metrics'
    scheme: https
    tls_config:
      insecure_skip_verify: true
    basic_auth:
      username: Administrator
      password: <password>
    static_configs:
      - targets: ['<nubus-host>']

Adjust the password and target host for your environment. The insecure_skip_verify option skips the certificate check; in production, use a valid certificate and drop the option instead. After you reload Prometheus, open the web interface and go to StatusTarget health to check whether the nubus job shows up as UP. That tells you Prometheus is reaching the endpoint on schedule and collecting the metrics.

That’s the data collection running. Prometheus now pulls the Nubus metrics every 30 seconds and files them in its database. Next up: visualizing them with Grafana.

Building a Grafana Dashboard for Nubus

A dashboard gathers several panels on one page. Each panel sends a query to the data source and visualizes the answer. For our Nubus monitoring, four panels are enough to cover the whole picture: the current user count, the license limit, the version info, and the trend over time.

Create an empty dashboard under DashboardsNew Dashboard. For the layout, pick Custom grid so you can set the size and position of each panel yourself. The + Add visualization button creates your first panel.

Panel 1: Active Users

The first panel sits in the top left corner and shows the current number of active user accounts as a large single figure. Below it, a small arrow gives the percentage change from the previous period, and a sparkline sketches the trend within the selected time window. The figure carries the panel; the two additions supply the context.

In the panel editor, pick the prometheus data source at the bottom and enter the query in code mode:

nubus_users_user_total

In the top right, switch the panel type to Stat. In the options on the right, set Panel optionsTitle to Active Users. Under Stat styles → Graph mode, choose Area: alongside the large number, a small sparkline now appears in the panel. The Show percent change option adds an arrow and a percentage that reflect the change from the previous period.

It’s also worth opening the Thresholds section. This is where you define which value turns the panel which color: green as the baseline, say, yellow from 1199, red from 1200. The number in the panel then switches color on its own as soon as it crosses a threshold.

Panel 2: User Limit (License)

The second panel shows the license limit; in our test setup on the Core Edition, it reads . Create a new panel with this query:

nubus_settings_license_users_limit_total

Set the panel type to Stat and the title to User Limit (License). Grafana recognizes the +Inf value automatically and renders it as an infinity symbol.

Panel 3: UCS Version

The third panel shows all the labels of the version metric in a clear table. This time the query is:

nubus_ucs_version_info

Set the panel type to Table. Since the interesting information sits in the metric’s labels, you need a transformation that surfaces those labels as columns. Switch to the Transformations tab at the bottom and add the Labels to fields transformation. Set the mode to Rows so the labels stack vertically instead of side by side.

For a simplified view, add a second transformation: Organize fields by name. Use it to hide technical fields like _name_ and job, and to sort the labels that remain: domain, ucs, patch, errata, license_uuid, system_uuid.

Panel 4: User Count over Time

The fourth panel tracks the user count over time. This is what a time series database is for. Create a new panel with the same query as in Panel 1:

nubus_users_user_total

The Time series panel type is already selected. A click into the query options takes you to the Legend field. Enter this:

{{domain}}

Now the legend shows just the domain name of the Nubus instance instead of the expression with every label; in our example, that’s nubus.example. Once you’re monitoring several instances later on, Grafana tells them apart by exactly this label.

Final Layout

Drag and drop the panels into an arrangement that works. For the screenshots in this article, the three Stat and table panels sit side by side up top, with the time series panel spanning the full width beneath them. Save the finished dashboard with Save.

In Practice: Watching Growth and Consolidation

The real strength of a Grafana dashboard like this comes out in daily use. What matters isn’t a metric’s single reading, but its trend. Take the start of a school year. Over a few weeks, the administrators create several hundred new accounts. The time series panel renders that as a staircase, and the figure in the Active Users panel climbs. As the number nears a threshold you defined earlier, it flips from green to yellow. One look is enough: things are getting tight, and the license may need to be expanded.

At the end of the year, graduating classes leave and their accounts are deleted from the system. The time series panel registers the drop, and the percent arrow in the Stat panel goes red with a negative value. Once the number falls back below the warning band, it returns to green. Consolidation phases like these show that your data hygiene is working, and they give you a realistic basis for capacity planning.

In larger environments, the same metrics can also feed automated alerts. Prometheus evaluates alert rules and passes any triggered alerts to Alertmanager, which then notifies the admin team by email or chat, for example, when the user limit hits 90 percent. The dashboard is what you check on purpose; the alerts make sure nothing slips past.

Looking Ahead: Nubus Monitoring across Distributed Environments

The setup in this article monitors a single Nubus instance. In practice, single instances are rare. Educational providers, municipalities, and other organizations often run dozens or hundreds of deployments, one per school, per site, per department. This is exactly where the approach shown here scales without much effort.

Prometheus can query any number of endpoints. To bring in another Nubus instance, add it as one more entry under static_configs in prometheus.yml. Because every metric carries the domain label automatically, Grafana keeps the instances neatly separated. What starts as a handful of panels for one instance becomes an overview dashboard for many.

PromQL, Prometheus’s own query language, handles the rest. It offers aggregation operators that summarize or filter metrics across any set of labels. An expression like sum(nubus_users_user_total) returns the total user count across every instance you monitor. Others, such as topk, avg, or count, open up different views: the five largest environments, for example, or the average number of users per site. You’ll find the full list of operators in the Prometheus documentation, and examples of common queries in the Query Examples chapter.

Conclusion: What Nubus Metrics mean for your IAM Environment

The new metrics endpoint gives Nubus an interface to Prometheus and makes central identity management fit right in with the monitoring tools you already run. If Prometheus and Grafana are handling your other services, a few lines of configuration bring Nubus into the same setup, on the same dashboard as your servers, databases, and web applications.

A single query on the command line answers the question of where things stand right now. The time series in a Grafana panel shows how they develop, which gives you a solid basis for capacity planning, license management, and the assessment of operational processes. For small environments, that’s a useful tool. For large ones with many instances, it becomes the foundation for dependable statements about your own infrastructure.

As of July 2026, the endpoint delivers three metrics. That’s enough for a first overview, and it lays the groundwork for the metrics to come in future releases. A good moment to set up monitoring for your own Nubus.

Der Beitrag See Everything: Visualizing Nubus Metrics with Prometheus and Grafana erschien zuerst auf Univention.

08 September, 2026 09:14AM by Ingo Steuwer

hackergotchi for Deepin

Deepin

hackergotchi for Volumio

Volumio

How to Reduce Streaming Dropouts at Home

A dropout has a way of breaking the spell. You are midway through a quiet passage, the system has disappeared, and then the music stops, stutters, or skips ahead. To reduce streaming dropouts, the answer is rarely a single expensive upgrade. It is usually a matter of finding where the connection between your music service, home network, and player is being interrupted.

The encouraging part is that most streaming problems are fixable with a few deliberate checks. Start with the path your music takes, then improve the weakest link rather than changing everything at once.

What causes a music streamer to drop out?

A streaming dropout is not always a Wi-Fi problem. A track may be delivered from a service over the internet, travel through your router, cross your local network, reach the player, and then be buffered before playback. Any part of that chain can fall behind.

If dropouts happen only with Qobuz, TIDAL, Spotify, or internet radio, look first at the internet connection, the service, or the player’s connection to the router. If local files stored on a NAS or computer also stop, the issue is more likely within the home network. If only one streaming device has trouble while phones, tablets, and other players work normally, placement, cabling, or that device’s settings deserve closer attention.

Sound quality settings can reveal useful clues. High-resolution streams require more consistent bandwidth than CD-quality playback, especially when several people are using the same network. That does not mean hi-res music needs extraordinary internet speed. It does mean a momentary Wi-Fi interruption that goes unnoticed while reading email can be enough to interrupt music.

Reduce streaming dropouts by checking the basics first

Before changing router settings, restart the equipment in the order the signal travels. Power-cycle the modem, router, network switch if you use one, and music player. Give each device time to reconnect before moving on. Routers can run for months without attention, and a restart can clear a temporary issue without telling you why it appeared.

Then check whether the problem is tied to a particular time. Regular dropouts in the evening may point to household demand: video calls, gaming, cloud backups, 4K video, or multiple devices downloading updates. A broadband plan can have plenty of advertised speed yet still suffer from congestion, unstable latency, or limited upload capacity.

Run a speed test near the router and, if possible, near the player. The result is not a final verdict, but a large difference between those tests suggests wireless coverage is part of the story. More useful than peak speed is consistency. A connection that briefly falls away is more disruptive to playback than one that is merely modestly paced.

Distinguish internet issues from local-network issues

Play a local album from a USB drive, NAS, or computer library, then stream an album from your preferred service. Test at a similar resolution where possible. If the local album plays perfectly and streaming does not, investigate the broadband connection, DNS behavior, or service account and app settings. If both fail, focus on the router, Wi-Fi, Ethernet connection, or network hardware.

Also try the same stream on another device connected to the same network. If a phone plays it without interruption while the hi-fi player does not, do not assume the streamer is at fault. Phones often have different antennas, may switch bands more gracefully, and are usually used closer to an access point.

Ethernet is the simplest stability upgrade

For a fixed hi-fi system, wired Ethernet remains the most direct way to remove wireless uncertainty. A properly installed Ethernet cable is not glamorous, but it offers stable bandwidth, low latency, and freedom from the walls, appliances, and neighboring networks that affect Wi-Fi.

If your player sits close enough to the router or a network switch, connect it by Ethernet and listen for a few days. This is also an excellent diagnostic test. When dropouts disappear on a cable, you have isolated the issue to Wi-Fi coverage or wireless network configuration.

Not every room can accommodate a cable. Powerline adapters can help in some homes, but their performance depends heavily on the electrical wiring and can vary from room to room. Mesh Wi-Fi can be a better answer for larger spaces, although a mesh node connected wirelessly still shares airtime with the player. Where practical, use a wired backhaul between mesh nodes, or place the player near a node with a strong, proven connection.

Make Wi-Fi work for the listening room

Wi-Fi is capable of excellent music streaming, provided the signal is clean and reliable where the system lives. Router placement matters more than many people expect. Keep it in an open, elevated position rather than inside a cabinet, behind a television, or on the floor. Dense materials such as brick, concrete, plaster, and metal can substantially weaken a signal.

The 5 GHz band generally offers more capacity and less congestion than 2.4 GHz, but it has shorter range and is more easily blocked by walls. The 2.4 GHz band reaches farther but is crowded by many household devices. There is no universal winner. If the listening room is distant from the router, a strong 2.4 GHz connection can outperform a marginal 5 GHz one.

Separate network names for 2.4 GHz and 5 GHz can make testing easier, though modern routers often manage band selection well. If your router offers channel selection, leaving it on automatic is usually sensible. In dense apartment buildings or urban neighborhoods, however, manually choosing a quieter channel after observing repeated interference may help.

Avoid placing a streamer directly beside the router, a wireless access point, or a stack of network gear. This is less about audiophile ritual than radio behavior and practical cable management. Give antennas and components some physical breathing room, and keep Wi-Fi equipment away from microwave ovens, cordless phone bases, and other obvious sources of interference.

Give the player enough room to buffer

A music player uses a playback buffer to hold a small amount of audio before you hear it. That buffer gives the network time to recover from minor fluctuations. If a player offers buffer or cache settings, increasing them can reduce dropouts on an inconsistent connection.

There is a trade-off. A larger buffer may make the system slightly slower to start playing, switch tracks, or respond to seeking within a song. For most dedicated listening systems, that is a worthwhile exchange for uninterrupted playback. For listeners who frequently jump between tracks, a moderate setting may feel more responsive.

In Volumio, confirm that the selected output and streaming-service settings match your intended system configuration, then avoid changing multiple audio parameters at once while troubleshooting. Keep the test simple: one service, one album, one output, and enough time for the issue to repeat or disappear.

Look beyond the streamer

The player is often blamed because it is where the silence is heard, but other devices can create the disruption. An aging router may struggle with a busy smart home. A low-cost network switch can develop a faulty port. A NAS may be indexing files or waking from sleep just as playback begins. Even a loose Ethernet cable can cause brief disconnects that look like a streaming fault.

Use this short isolation check when the problem persists:

  • Connect the player to Ethernet temporarily, even if it is only for testing.
  • Try a different Ethernet cable and router or switch port.
  • Pause large downloads, cloud backups, and video streams during a listening test.
  • Test local-library playback separately from internet streaming.

If you use a VPN at the router level, disable it briefly for a controlled test. Some VPN routes add latency or interact poorly with particular streaming services. Likewise, custom DNS services can be useful, but returning temporarily to your internet provider’s default DNS can help identify an unusual name-resolution issue.

When the problem is outside your home

A perfect home network cannot correct every interruption upstream. Streaming services occasionally have regional outages, and internet providers can experience routing problems that affect one service more than another. If a dropout begins suddenly after months of stable listening, test another service or station before rebuilding your network around a temporary event.

Keep a small note of what was playing, the time, whether it was local or streamed, and whether other household devices were active. That evidence is more valuable than a vague memory when contacting your internet provider, a streaming service, or technical support.

Music streaming should feel invisible once it is working well. Start with the simplest test, change one variable at a time, and let a full album play before declaring success. The reward is not merely a cleaner network – it is the freedom to stay with the performance, exactly where the artist intended.

The post How to Reduce Streaming Dropouts at Home appeared first on Volumio.

08 September, 2026 05:24AM

hackergotchi for Qubes

Qubes

XSAs released on 2026-09-08

The Xen Project has released one or more Xen security advisories (XSAs). The security of Qubes OS is not affected.

XSAs that DO affect the security of Qubes OS

The following XSAs do affect the security of Qubes OS:

  • (none)

XSAs that DO NOT affect the security of Qubes OS

The following XSAs do not affect the security of Qubes OS, and no user action is necessary:

  • XSA-509: Denial of service only.
  • XSA-510: Denial of service only.
  • XSA-511: Qubes OS does not use XSM silo.
  • XSA-512: Qubes OS does not use oxenstored.
  • XSA-513: Qubes OS does not use tapdisk.

About this announcement

Qubes OS uses the Xen hypervisor as part of its architecture. When the Xen Project publicly discloses a vulnerability in the Xen hypervisor, they issue a notice called a Xen security advisory (XSA). Vulnerabilities in the Xen hypervisor sometimes have security implications for Qubes OS. When they do, we issue a notice called a Qubes security bulletin (QSB). (QSBs are also issued for non-Xen vulnerabilities.) However, QSBs can provide only positive confirmation that certain XSAs do affect the security of Qubes OS. QSBs cannot provide negative confirmation that other XSAs do not affect the security of Qubes OS. Therefore, we also maintain an XSA tracker, which is a comprehensive list of all XSAs publicly disclosed to date, including whether each one affects the security of Qubes OS. When new XSAs are published, we add them to the XSA tracker and publish a notice like this one in order to inform Qubes users that a new batch of XSAs has been released and whether each one affects the security of Qubes OS.

08 September, 2026 12:00AM

September 07, 2026

hackergotchi for GreenboneOS

GreenboneOS

August 2026 Threat Report: The Vulnpocalypse Hits Full Force

The so-called Vulnpocalypse is now in full force. This August 2026 threat report only scratches the surface of new high-risk vulnerabilities that emerged in August 2026. To see how Greenbone’s industry leading vulnerability detection can benefit your IT security operations, visit our SecInfo portal and view our complete coverage portfolio. August reinforced a now too […]

07 September, 2026 12:56PM by Joseph Lee

hackergotchi for VyOS

VyOS

VyOS 1.5.1 and 1.4.5 LTS released: security fixes, BGP enhancements, and automated upgrades

Hello, Community!

VyOS 1.5.1 and VyOS 1.4.5 LTS are both available, and subscribers can download images from the Support Portal.

Both releases are primarily security releases. They fix thirteen vulnerabilities, twelve of which are in accel-ppp — the daemon behind the PPPoE, IPoE, L2TP, and PPTP servers. Most let an unauthenticated attacker crash the service with a crafted packet, but some disclose memory contents that can include other clients’ data, credentials, and pointers, and one lets a client be authenticated without valid credentials at all. The thirteenth is a remote code execution vulnerability in the update-check mechanism. If you run any of these services, upgrade promptly. VyOS 1.4.5 additionally fixes a vulnerability in its NHRP subsystem that does not affect 1.5.1.

Beyond the security work, VyOS 1.5.1 brings a substantial set of new features and improvements, and both releases include a large number of bug fixes. Full lists are at the end of this announcement.

07 September, 2026 11:45AM by Daniil Baturin (daniil@sentrium.io)

hackergotchi for Deepin

Deepin

deepin Community Monthly Report for August 2026

Learn more about deepin on DistroWatch:  https://distrowatch.com/table.php?distribution=deepin I. August Community Data Overview II. Community Products deepin 25.2.1 Update: Intelligent Semantic Search Launched · Multiple High-Frequency Issues Fixed In August, deepin 25.2.1 was released(official push on August 3, emergency update on August 10). The biggest highlight is the introduction of intelligent semantic search: the file manager and global search now support natural language queries (e.g., "financial spreadsheets modified yesterday," "videos larger than 1 GB") combined with filters such as time, type, location, and size to quickly locate local files. At the same time, optimizations were made to the file management and ...Read more

07 September, 2026 10:12AM by Chen, Rong

September 06, 2026

hackergotchi for Volumio

Volumio

Can a Streamer Replace a Computer in Your Hi-Fi?

A laptop beside a hi-fi rack can feel like a compromise: a bright screen, fan noise, update alerts, and a keyboard where the music should be. So, can a streamer replace computer duties in a serious music system? For many listeners, yes. A dedicated network streamer can take over music playback completely while making the experience more focused, quieter, and easier to live with.

The more useful question is not whether a computer is good enough to play music. It is. The question is whether a computer is the best long-term music source for the way you listen. That answer depends on your library, your streaming habits, and whether you want a system built around listening rather than general-purpose computing.

What a streamer replaces in a hi-fi system

A network streamer is a purpose-built music player. It connects to your home network, finds music from streaming services and local storage, and sends audio to a DAC or directly to an integrated amplifier with digital inputs. Rather than using a desktop operating system designed for work, video calls, browsers, and notifications, it runs software dedicated to music playback.

For day-to-day listening, that means a streamer can replace a computer as the device that:

  • Plays music from services such as TIDAL, Qobuz, Spotify, and internet radio
  • Accesses a library stored on a NAS drive, USB drive, or network share
  • Organizes albums, artists, playlists, favorites, and metadata
  • Delivers digital audio to an external DAC, amplifier, or active speakers
  • Provides playback control through a phone, tablet, or dedicated display

The computer does not need to remain powered on in the listening room. Your phone becomes a remote control, not the audio source. The streamer does the actual work of receiving, buffering, and playing the music.

That distinction matters. Sending audio from a phone over Bluetooth is convenient, but it is not the same as operating a network player from an app. With a proper streamer, the audio travels directly from the music service or your local network to the hi-fi system. Your phone can leave the room, receive a call, or run out of battery without interrupting playback.

Why dedicated streaming often feels better than a PC

A computer offers enormous flexibility, but flexibility carries distractions. Notifications can interrupt a quiet record. Operating-system updates can change audio settings. A new application, driver, or security prompt can turn a simple listening session into troubleshooting.

A streamer removes much of that friction. Turn on the system, choose an album, and play it. It is a small change, but it alters the relationship with your collection. Music is no longer an activity nested among open tabs and unfinished tasks.

There is also a practical hardware advantage. Many computers are electrically noisy environments, especially compact desktops, inexpensive laptops, and machines running many background processes. A well-designed streamer is engineered around one job: moving digital music through your system reliably. It may include carefully considered power regulation, low-noise clocks, isolated outputs, and hardware chosen for stable audio performance.

None of this means every computer sounds poor or every streamer sounds identical. A thoughtfully configured computer with quality USB output and a capable DAC can be excellent. But a dedicated streamer reaches a high standard with fewer variables, less maintenance, and a more natural place in a hi-fi rack.

Can a streamer replace a computer for local music?

For most local libraries, absolutely. If your albums are stored on a NAS, an external USB drive, or a shared folder on another computer, a streamer can scan the files and present them in a music-focused library. You can browse by artist, album, genre, composer, date added, resolution, or other useful tags, depending on the playback platform.

This is especially valuable for listeners with a carefully collected library of FLAC, WAV, AIFF, ALAC, or DSD files. A good streaming interface makes those files feel like part of one collection rather than a separate, technical task. Your locally stored music can sit alongside streaming favorites, internet radio, and playlists in one familiar place.

There is an important qualification: a streamer can play and organize your library, but it does not always replace a computer for managing it. If you need to edit metadata in bulk, rip CDs, convert file formats, repair a damaged archive, or maintain complex backups, a computer remains useful. It simply moves out of the signal path and into the background, where it belongs for many systems.

A sensible arrangement is to keep a computer for library maintenance and store the music on a NAS or external drive. The streamer then becomes the dedicated front end for listening.

When a computer still makes sense

A computer remains the right choice in some systems. If your listening involves professional audio work, music production, extensive DSP experimentation, or unusual software tools, a general-purpose machine gives you options a dedicated streamer may not. The same is true if you rely on a niche music application that is unavailable on your preferred streaming platform.

Some listeners also keep an enormous library directly on a desktop or laptop and have no interest in adding network storage. In that case, computer playback can be simple and effective, provided the machine is configured carefully and stays close to the system.

Room correction is another case where the details matter. Some streamers support DSP and may offer excellent control over playback settings, while advanced measurement workflows or proprietary correction software can require a computer. Before choosing, consider whether your system needs straightforward music playback or an ongoing laboratory for tuning every variable.

The point is not to eliminate computers on principle. It is to give each component the job it performs best.

Choosing the right streamer for your setup

The phrase streamer covers several types of product. A network transport has digital outputs and is designed to feed an external DAC. This is often the ideal choice for an established hi-fi system with a DAC you already enjoy. An all-in-one network player may include a DAC, analog outputs, and sometimes amplification, reducing the number of boxes in a simpler system.

Start with the connection you need. If you own a separate DAC, look for the digital output it accepts, such as USB, coaxial, AES/EBU, or optical. If your amplifier has only analog inputs, you need a streamer with an internal DAC and analog outputs. Network connection matters too: wired Ethernet is generally the most stable choice for high-resolution playback, although good Wi-Fi can work very well in a properly covered home.

Then consider the control experience. The best streamer is not merely compatible with your favorite service. It should make you want to explore your music. Search should be quick, your local library should be easy to browse, and switching from a saved album to a new release should not require jumping among disconnected apps.

Volumio approaches this as one music-player ecosystem, bringing local libraries, streaming services, connected audio devices, and a clear control interface together. For builders, the same idea can begin with a Raspberry Pi or PC-based player; for a finished hi-fi system, dedicated hardware can bring that experience into a more refined component.

A streamer changes the role of the computer

Replacing a computer does not necessarily mean throwing it away. It means removing it from the center of your listening ritual. Your computer can still rip discs, tag files, maintain backups, and handle the occasional project that calls for a screen and keyboard. But when it is time to play music, a dedicated streamer can make the system feel like a hi-fi system again.

Choose the solution that leaves you spending less time managing devices and more time returning to the albums that made you build the system in the first place.

The post Can a Streamer Replace a Computer in Your Hi-Fi? appeared first on Volumio.

06 September, 2026 05:22AM

September 05, 2026

Optical Versus Coaxial Digital Audio Compared

A new DAC arrives, the music server is already playing, and there are two familiar ports on the back panel: optical and coaxial. Optical versus coaxial digital audio is not a contest with one universal winner. Both can carry excellent digital sound, but their physical designs solve different problems. The right choice depends on the gear in your system, the electrical environment around it, and the formats you intend to play.

For most two-channel systems, either connection can deliver a satisfying, detailed result when it is properly implemented. The more useful question is not which cable is inherently more “audiophile,” but which connection lets your streamer and DAC perform at their best together.

Optical Versus Coaxial Digital Audio: The Core Difference

Both optical and coaxial connections usually carry S/PDIF, a digital audio protocol found on streamers, CD transports, televisions, game consoles, and DACs. The audio data can be the same. What changes is the way that data travels.

Optical S/PDIF uses light. A source converts the electrical signal to pulses of light, which travel through a fiber-optic cable, commonly terminated with the square-shaped TOSLINK connector. At the receiving end, the DAC converts those light pulses back into an electrical signal.

Coaxial S/PDIF uses an electrical signal sent through a 75-ohm copper cable. RCA connectors are common on consumer hi-fi components, while BNC connectors appear on some higher-end equipment. The cable may resemble a conventional analog interconnect, but a true digital coaxial cable is designed to maintain the impedance required for reliable S/PDIF transmission.

That difference between light and electricity has practical consequences. Optical creates electrical isolation between source and DAC. Coaxial creates an electrical connection between them.

When Optical Is the Better Choice

Optical’s defining advantage is isolation. Because the signal crosses the cable as light, there is no direct ground path between the two components. That can be valuable when a system suffers from hum, buzz, computer noise, or other artifacts caused by ground loops.

This matters especially when connecting a television, computer, or cable box to a DAC or integrated amplifier. Video equipment and computers often share power with many other devices, and their electrical noise can find unwanted routes through an audio system. An optical cable breaks that route. If you hear a low-frequency hum with coaxial or analog connections, optical is often the first digital connection worth trying.

Optical is also convenient. TOSLINK cables are inexpensive, widely available, and immune to radio-frequency interference along the cable itself. For a television feeding a hi-fi system, it is frequently the cleanest, simplest answer.

There are trade-offs. The quality of the optical transmitter and receiver matters, and the standard’s real-world bandwidth can vary between components. Many optical outputs and inputs comfortably support CD-quality material and high-resolution PCM, but some are limited to 24-bit/96 kHz. Others handle 24-bit/192 kHz. Do not assume the connector alone tells you the maximum supported resolution. Check the specifications of both the sending device and the DAC.

Fiber-optic cables also deserve sensible handling. Avoid sharply bending, crushing, or loosely seating them. The small protective caps on a new TOSLINK cable are not glamorous, but removing them and ensuring each plug clicks fully into place prevents many frustrating no-signal moments.

When Coaxial Is the Better Choice

Coaxial digital is often favored for a dedicated audio source and DAC that sit in the same rack and are well designed. It can support higher sample rates more consistently across many components, and it is commonly available on CD transports, network streamers, and DACs built for serious two-channel listening.

A good coaxial connection can be particularly appealing if your library includes 24-bit/176.4 kHz or 24-bit/192 kHz PCM files and both components specify support for those rates over S/PDIF. It may also be the more dependable route for certain DSD-over-PCM implementations, although compatibility remains entirely device-specific.

Coaxial’s other advantage is mechanical familiarity. A properly made 75-ohm cable with secure RCA or BNC plugs is durable, easy to route, and less sensitive to tight bends than optical fiber. For a streamer placed close to a DAC, it is a straightforward, high-performing connection.

Its limitation is the same electrical link that makes it possible. If the source and DAC have different ground potentials, a coaxial cable can contribute to a ground-loop issue. This does not mean coaxial is noisy by nature. In a thoughtfully assembled system, it is often completely quiet. But if unwanted noise appears after connecting components, changing to optical is an easy diagnostic step.

Use a cable intended for 75-ohm digital transmission rather than treating any spare RCA cable as the ideal choice. A short analog interconnect may pass audio without obvious problems, but impedance mismatches can increase reflections and make a marginal connection less reliable. The goal is not an extravagant cable purchase. It is correct construction, good connectors, and a sensible length for the installation.

Does One Connection Sound Better?

The honest answer is: sometimes, but not for the reasons marketing shorthand suggests. Digital audio is not automatically immune to implementation quality. Timing behavior, electrical noise, receiver design, and a DAC’s clock recovery all influence what reaches the conversion stage.

Older or simpler DAC designs may respond more noticeably to differences between optical and coaxial inputs. A modern DAC with effective reclocking and input isolation may make the distinction very small. In that case, the quietest, most reliable connection that supports your desired formats is the better connection.

It is also worth separating audible changes from level differences, expectation, and setup variables. If you compare inputs, use the same track, the same DAC settings, comparable cable lengths where practical, and matched playback levels. Give each configuration time. A quick switch can reveal an obvious noise problem, but it is less reliable for judging subtle changes in tonal balance or imaging.

The source matters, too. A carefully configured network player running Volumio can organize local music and streaming services in one place, but the final result still depends on the digital output selected, the DAC’s input stage, and the rest of the system. The connection is one part of a longer chain that includes mastering quality, speaker placement, room acoustics, and listening level.

Choosing the Right Digital Connection for Your System

Start with compatibility. If your DAC only accepts up to 24-bit/96 kHz through optical and you regularly play higher-resolution PCM through a source that supports coaxial output, coaxial is the practical choice. If your music is largely CD quality, both options are likely to meet your needs easily.

Next, consider the source. For a TV, computer, or multi-purpose entertainment setup, optical is often preferable because it avoids electrical interaction with the audio system. For a dedicated streamer and DAC on the same equipment shelf, coaxial is often an excellent fit, provided the system is quiet.

Then consider the symptoms, not just the specifications. Choose optical if you are troubleshooting hum, buzz, or electrical noise. Choose coaxial if optical proves unstable at the sample rate you want to use, or if your DAC’s coaxial input is known to offer broader format support. If both work flawlessly, let listening decide rather than chasing a theoretical rule.

Cable length is rarely the first concern in a typical hi-fi rack, but avoid extremes. Keep the run tidy, protect optical cable from sharp bends, and use a correctly specified coaxial cable. Do not place excessive weight on claims that a cable alone will transform a system. Reliable transmission and clean system integration matter far more.

A Simple Way to Test Both

If your equipment provides both outputs and inputs, testing is worthwhile. Begin with coaxial, play several familiar recordings, and listen for clarity as well as silence between tracks. Then switch to optical with the same playback settings. Pay attention to obvious changes such as hum, intermittent lock, clicks when sample rates change, or a format that no longer plays at its native resolution.

If neither connection introduces noise or dropouts and both support your music, you have a fortunate result: either can be part of a refined digital front end. Select the one that keeps the installation clean and gives you confidence that every album, from a treasured local rip to a late-night streaming discovery, will play exactly as intended.

The best connection is the one that disappears once the first notes begin. Use optical when isolation brings peace to the system, use coaxial when its compatibility and stability suit your components, and spend the saved attention where it belongs: with the music.

The post Optical Versus Coaxial Digital Audio Compared appeared first on Volumio.

05 September, 2026 09:18AM

September 04, 2026

hackergotchi for Deepin

Deepin

deepin Community Monthly Report for August 2026

Learn more about deepin on DistroWatch:  https://distrowatch.com/table.php?distribution=deepin I. August Community Data Overview II. Community Products deepin 25.2.1 Update: Intelligent Semantic Search Launched · Multiple High-Frequency Issues Fixed In August, deepin 25.2.1 was released(official push on August 3, emergency update on August 10). The biggest highlight is the introduction of intelligent semantic search: the file manager and global search now support natural language queries (e.g., "financial spreadsheets modified yesterday," "videos larger than 1 GB") combined with filters such as time, type, location, and size to quickly locate local files. At the same time, optimizations were made to the file management and ...Read more

04 September, 2026 10:32AM by xiaofei

hackergotchi for GreenboneOS

GreenboneOS

Agent-Based, Agentless, or Both? What Each One Can Actually See

Agents are not new to vulnerability management. The reason the question keeps resurfacing is that the estate being scanned stopped holding still. A scanner that assumes every host is reachable on a known network at a scheduled time described most organisations reasonably well fifteen years ago. It describes very few of them now, in an […]

04 September, 2026 10:23AM by Greenbone AG

hackergotchi for Volumio

Volumio

Choosing a USB DAC Network Streamer for Hi-Fi

A USB DAC network streamer can be the missing link between the music you love and the DAC already at the heart of your system. It puts streaming services, internet radio, and your personal library on the network, then sends a dedicated digital signal to an external DAC over USB. For listeners who have chosen their DAC carefully, that separation can be more satisfying than replacing it with an all-in-one box.

The appeal is simple: all your music can live in one player experience without asking one component to do every job. But a USB-equipped streamer is not automatically the right answer for every system. The best choice depends on your DAC, your listening habits, and whether you value flexibility, minimalism, or a carefully matched component stack.

What a USB DAC network streamer actually does

A network streamer connects to your home network through Ethernet or Wi-Fi and retrieves music from services such as TIDAL, Qobuz, and Spotify, as well as music stored on a NAS drive, computer, or USB storage device. Rather than converting that music to analog itself, a streamer with USB audio output passes the digital data to a separate DAC.

Your DAC then handles digital-to-analog conversion before the signal reaches your preamplifier, integrated amplifier, or active speakers. This division of labor matters because a DAC is not just a socket for digital audio. Its conversion architecture, analog output stage, clocking approach, and power supply all shape how it performs within a system.

A streamer can also bring order to a fragmented listening routine. Instead of moving between separate service apps, a server interface, and a computer audio player, you can browse albums, search across sources, build playlists, and control playback from one place. That convenience is not separate from sound quality. It often means you spend less time managing devices and more time playing complete records.

Why use USB instead of another digital connection?

Many DACs offer optical, coaxial, and USB inputs. Each can be excellent, but USB is especially useful when you want broad format support and a direct connection to a modern external DAC. Depending on the hardware and the music service, USB can support high-resolution PCM and DSD playback beyond the limits commonly associated with optical connections.

USB also allows the DAC to take an active role in timing the incoming audio stream. In an asynchronous USB implementation, the DAC’s clock controls the pace at which data is requested from the streamer. That can be an elegant arrangement when the DAC’s USB input has been designed well.

Still, USB is not a universal upgrade. A DAC with an exceptional coaxial input may sound best through coaxial. An older DAC may have a USB implementation that is limited compared with its other inputs. The right question is not which connector wins in the abstract. It is which connection lets your specific DAC perform at its best while supporting the music formats you actually use.

The DAC remains the voice of the system

With a USB streamer, the external DAC retains its role as the primary digital voice in your system. That is valuable if you already own a DAC whose presentation you know well: perhaps it has a generous sense of space, strong tonal density, or the particular timing and texture that keeps you listening late into the evening.

It also gives you an easier upgrade path. You can update the streamer when software, service support, or connectivity needs change without discarding a DAC you still enjoy. Or you can audition a different DAC later while keeping the same music interface and network setup intact.

What to look for before you buy

Start with compatibility, not a specification race. Confirm that the streamer can send audio through USB to your DAC at the formats you need. If you listen mainly to CD-quality streaming, nearly any competent pairing will cover the basics. If you maintain a library of high-resolution PCM or DSD files, check the supported limits and whether playback is native, converted, or unavailable.

Network stability deserves just as much attention. Ethernet is usually the most dependable option for a fixed hi-fi system, particularly when the router is in another room or the household has many connected devices. Wi-Fi can work beautifully when the signal is strong, but a wired connection removes one variable from critical listening.

The control experience is equally important. A great streamer should not force you to think like a network administrator every time you want to hear an album. Look for clear library browsing, reliable search, support for your preferred services, and an interface that treats local files and streaming catalogs as parts of the same collection. Features such as favorites, playlists, multiroom playback, and internet radio may seem secondary until they become part of your daily listening.

Finally, consider physical integration. You need a quality USB cable of practical length, but extreme claims around cable cost should not distract from the fundamentals. A stable network, a well-designed streamer, a compatible DAC, and a quiet, sensible installation will make a far larger difference than chasing accessories for their own sake.

Build the signal path around how you listen

The typical connection is straightforward: network router to streamer, streamer USB output to DAC, DAC analog outputs to amplifier. If your system includes a preamp, the DAC usually connects to a line-level input. If you use active speakers, the DAC may feed them directly, provided its output level and volume-control arrangement suit the speakers.

The more interesting decisions happen around the edges. If your DAC has a fixed output and your amplifier lacks volume control, you will need a preamp or a streamer-DAC setup with appropriate volume management. If you own a headphone amplifier with a DAC built in, a network streamer may be all you need to turn that desktop or listening-room setup into a complete streaming system.

For a main hi-fi system, keep the streamer close enough to the DAC for a tidy USB connection and give both components good ventilation. Avoid placing networking gear or switching power supplies directly on top of sensitive analog equipment where possible. These are practical housekeeping choices, not rituals, but a clean installation is easier to troubleshoot and easier to enjoy.

Local music deserves equal treatment

A USB DAC network streamer is particularly rewarding if your collection extends beyond streaming. Ripped CDs, purchased downloads, live recordings, and carefully tagged high-resolution files should not feel like an afterthought beside a subscription catalog.

Good library software can make a personal collection feel alive again. Browse by artist, composer, genre, date added, or label. Find different editions of a favorite album. Move from a saved local recording to a related release on a streaming service without changing devices. This is where a network player becomes less like an accessory and more like the center of a music habit.

Volumio approaches that idea with a unified ecosystem built for both dedicated components and hands-on DIY players, giving listeners a familiar way to bring services, local music, and connected audio together.

Sound quality: where expectations should be realistic

A quality streamer can contribute to clear, stable digital playback, but it will not override the character of every other component. Your speakers, room, amplification, and DAC remain deeply influential. A USB connection does not turn an entry-level system into a reference system, and a high-resolution badge does not guarantee a more moving performance.

What you may notice with a well-matched streamer and DAC is consistency. Albums start reliably. The system remains quiet between tracks. Complex recordings retain their composure. You can move from a favorite local file to a new release without changing the listening setup. Those gains support the real goal: hearing more of the performance and less of the technology.

If you are comparing streamers, use music you know intimately and listen at comparable levels. Pay attention to ease of use as well as sound. A product that sounds wonderful but makes you avoid your own library is not necessarily the better long-term choice.

When an all-in-one player may be better

There are sensible reasons to choose a streamer with a built-in DAC instead. It reduces box count, cabling, and setup complexity. It can be ideal for a second system, a compact living room, active speakers, or anyone beginning a hi-fi journey without an existing DAC.

An integrated player may also offer a manufacturer-designed digital and analog stage that works exceptionally well as a whole. Fewer choices can be a benefit when you want a refined system quickly.

Choose a separate USB streamer and DAC when you already value your DAC, want greater component flexibility, or prefer to keep the digital source and conversion stages independent. Choose an all-in-one player when simplicity, space, and a single coordinated component matter more. Neither approach is inherently more serious. The better one is the one that invites you to sit down, choose an album, and stay for the next track.

The post Choosing a USB DAC Network Streamer for Hi-Fi appeared first on Volumio.

04 September, 2026 05:21AM

September 03, 2026

hackergotchi for ZEVENET

ZEVENET

Vendor Security Assessment: Why the Security of Your ADC Provider Matters

Choosing infrastructure technology has traditionally involved a familiar set of questions. Does it meet the technical requirements? Will it handle the expected traffic? Is it compatible with the existing environment? What will it cost to deploy and maintain?

Security teams are adding another question to that process: how much do we know about the company behind the technology?

This is particularly relevant when a supplier provides technology that becomes part of important application infrastructure. An Application Delivery Controller (ADC), for example, may sit in the path of critical application traffic and remain in the infrastructure for years. The organization is therefore not only selecting software. It is establishing a long-term relationship with the company responsible for developing, maintaining, updating and supporting it.

For organizations handling sensitive information or critical digital services, this can lead to a much broader security review. Healthcare providers, universities, public-sector organizations and other security-conscious environments may ask vendors about their security policies, vulnerability management, internal controls, testing practices or incident response procedures before approving them.

Why Security Evidence Matters When Evaluating a Technology Vendor

A vendor security assessment is a review of the cybersecurity posture of a supplier. It can form part of a broader vendor risk assessment and may involve security questionnaires, technical discussions and requests for documentation that help the organization understand how the vendor manages security.

The depth of that assessment will vary considerably. A supplier of a low-risk business tool will not necessarily receive the same scrutiny as a company providing technology used in critical infrastructure.

But the underlying principle is simple: security claims are more useful when they can be supported by evidence.

A questionnaire may ask whether a vendor has an information security policy, a vulnerability management process or an incident response plan. For a more detailed assessment, the customer may also want evidence showing that those practices have actually been established.

Depending on the organization and the technology being assessed, this could include information about security policies, security testing, vulnerability management, architecture, data flows, access controls, incident response, supplier management or recognized security standards.

What Are Security Teams Actually Evaluating in a Vendor?

A vendor security questionnaire can cover a surprisingly broad range of areas. That is because the purpose is not simply to establish whether the supplier sells a cybersecurity product. The objective is to understand whether security is managed consistently across the organization that develops and supports the technology.

Several areas tend to become particularly relevant.

Security governance and risk management

One of the first things a security team may want to establish is whether cybersecurity has a defined place within the organization.

That can mean checking whether information security policies exist, whether responsibilities have been assigned, how security risks are identified and whether there are processes for reviewing those risks as the business, technology or threat landscape changes.

The question behind all of this is fairly straightforward: is security managed systematically, or only when a problem appears?

For technology vendors, this matters because product security, corporate infrastructure and customer support do not operate independently. They depend on decisions, responsibilities and controls across the company.

Corporate infrastructure and access control

Customers may also want to understand how a vendor protects the infrastructure used to develop, distribute and support its technology.

This does not require the vendor to disclose its network topology or internal configurations. What matters during an assessment is whether appropriate controls exist around areas such as administrative access, least privilege, credential management, logging, monitoring, asset management and access to sensitive systems.

There is a good reason for looking at this layer.

A security problem affecting a technology supplier can potentially originate outside the product itself. Development systems, repositories, administrative accounts, support platforms or other corporate assets can all become relevant to the overall risk relationship between customer and vendor.

Secure development and vulnerability management

For a software vendor, security also needs to continue throughout the lifecycle of the product.

Security teams may therefore ask whether software changes are reviewed before release, whether vulnerabilities are actively identified and evaluated, how security fixes are managed and whether third-party components are monitored for known vulnerabilities.

The presence of a vulnerability is not in itself evidence that a vendor has failed. Vulnerabilities can be discovered in practically any sufficiently complex software environment.

A more useful question is how the vendor responds when one is found.

Does it have a defined process to assess the issue? Can it determine the potential impact? Is there a mechanism for remediation, testing and distribution of the necessary update?

These practices are important because customers depend on the vendor not only at the point of purchase but throughout the useful life of the technology.

Security testing

Security testing provides another layer of assurance.

Depending on the vendor, risk and product, this may involve automated vulnerability analysis, dependency reviews, dynamic application testing, targeted assessments or penetration testing.

No individual testing technique proves that software is completely free from vulnerabilities. Security testing is more useful when it forms part of a continuous process: identifying weaknesses, analysing findings, correcting relevant issues and adapting testing as the product evolves.

This is why focusing exclusively on whether a vendor “does pentesting” can miss the wider picture. Penetration testing can be valuable, but it is only one element of a broader security management and vulnerability assessment strategy.

Third-party and supply-chain security

Very few technology companies operate without dependencies.

Software components, infrastructure providers, external services and other suppliers may all contribute to the systems used to develop or deliver a product. A vendor security assessment may therefore extend to how these third parties are considered and how relevant dependencies are monitored.

Understanding how a supplier approaches third-party risk can therefore provide additional context when evaluating its overall cybersecurity posture.

Incident response and resilience

Preventing incidents is important. Being prepared for them is equally important.

Security teams may want to know whether a vendor has an established incident response process and whether responsibilities exist for detection, investigation, containment, recovery and communication.

This becomes particularly relevant in environments such as healthcare or higher education.

A hospital evaluating infrastructure for important application services will naturally consider the operational impact of a security incident or prolonged disruption. A university may have a very different architecture, but it can face similar concerns across administrative applications, academic systems, research environments and large, diverse user populations.

In both cases, supplier security can become part of the technology decision because the consequences of choosing a vendor extend well beyond the initial deployment.

Vendor Security as Part of the Technology Selection Process

Vendor security assessment usually does not happen in isolation.

An organization may already have validated the technology, tested the software or confirmed that the solution satisfies its infrastructure requirements. Security review can take place in parallel with that technical evaluation or become another approval stage before procurement can move forward.

This explains why a technically suitable product may still need to be reviewed by cybersecurity, risk, compliance or procurement teams.

For the technical team, the question may be: does this ADC work in our environment?

For the security team, the question is different: are we comfortable introducing this vendor into our technology supply chain?

A mature selection process needs to answer both.

This is also the relationship between a vendor security assessment and the broader concept of a vendor risk assessment. Vendor risk can include operational, financial, legal, privacy or continuity considerations. A vendor security assessment focuses specifically on the cybersecurity dimension of that relationship.

For infrastructure that plays an important role in application delivery, that dimension can carry considerable weight.

Questions to Ask When Comparing ADC Vendors

When security forms part of an ADC selection process, these questions can help move the conversation from product claims to vendor assurance:

  1. Does the vendor have established information security policies and defined security responsibilities?
  2. Are secure development practices integrated into the software lifecycle?
  3. How does the vendor identify, evaluate and remediate vulnerabilities?
  4. Are third-party components and relevant dependencies monitored for security issues?
  5. Does the vendor perform regular security assessments?
  6. Is there an established incident response process?
  7. How are security updates and patches managed throughout the supported lifecycle?
  8. Can the vendor provide supporting security evidence when a customer’s cybersecurity team requires additional due diligence?
  9. Does the company follow, or is it working toward, recognized information security standards?
  10. How does the vendor protect confidential documentation shared during a security assessment?

There is no single answer that will fit every organization. The level of assurance required varies by sector and risk profile; what is proportionate for one deployment may be excessive, or insufficient, for another.

What matters is that the questions form part of the decision before the technology becomes another dependency that has to be managed later.

For technology vendors, being prepared to answer these questions and to support those answers with appropriate evidence, is becoming an important part of building trust with security-conscious organizations. This is also how SKUDONET approaches vendor security reviews

How SKUDONET Supports Vendor Security Assessments 

At SKUDONET, security is not limited to the cybersecurity capabilities available within our ADC platform.

We apply security practices across the lifecycle of the technology we develop and maintain. These include secure development practices, review and validation of software changes, vulnerability management, monitoring of vulnerabilities affecting relevant third-party components, security testing, and the delivery of security patches and updates when required.

Security also applies to the company infrastructure supporting those activities. SKUDONET maintains internal security controls and an established incident response framework covering systems and information under our responsibility. Our internal Information Security Policy defines principles covering areas such as security governance, access management, vulnerability management, infrastructure security, data protection, logging, backups, incident management, and supplier security.

We also perform internal security assessments as part of our security work, using complementary testing approaches that evolve as the product and threat landscape change.

At the organizational level, SKUDONET is currently working toward ISO/IEC 27001:2022 certification and implementing an Information Security Management System aligned with the standard. We are also implementing security management requirements aligned with Spain’s National Security Framework (ENS) at medium level.

These initiatives are part of our ongoing work to formalize and strengthen how information security is managed across the company.

When an organization carries out a formal vendor security assessment, SKUDONET can provide additional security information and supporting documentation where appropriate. Information covering sensitive internal policies, procedures, architecture, or operational practices is handled under suitable confidentiality conditions.

The goal is straightforward: to give security teams the information they need to make an informed decision without exposing information that should remain protected.

Trusting the Company Behind the ADC

Selecting an ADC is not only a question of throughput, high availability, deployment options or licensing.

When that technology becomes part of important application infrastructure, the organization responsible for developing and maintaining it also becomes part of the equation.

For technology providers, that means trust increasingly has to be demonstrated, not simply stated.

Do you have questions about SKUDONET’s security practices? If your cybersecurity, infrastructure or procurement team needs additional information as part of a vendor security review, contact us. Our team can answer your questions and provide further security information where appropriate.

 

03 September, 2026 04:23PM by Isabel Perez

hackergotchi for Grml developers

Grml developers

grml development blog: Grml - new stable release 2026.09 available

We are proud to announce our new stable release 🚢 version 2026.09, code-named ‘Hättiwaritätti’!

Grml is a bootable live system (Live CD) based on Debian. Grml 2026.09 brings you fresh software packages from Debian testing/forky and enhanced hardware support. Known bugs from previous releases are fixed.

GNU screen 5.0.1 is shipped with adapted Grml configuration.

Like in the previous release 2026.04, Live ISOs 📀 are available for 64-bit x86 (amd64) and 64-bit ARM CPUs (arm64).

For a detailed overview of the changes from Grml 2026.04 to 2026.09, please check out the official release announcement.

Don’t forget to use a current grml2usb (0.20.14 or newer) with this new release.

❤️ Thanks ❤️

Once again netcup contributed financially, this time specifically to this release. Thank you, netcup ❤️

We also want to thank our individual sponsors donating through GitHub. If you like what we are doing, please join in!

Thanks to everyone who contributed to Grml and this release, stay healthy and happy Grml-ing! ❤️🧡💛💚💙💜

grml-live changes

Our build and customization tool grml-live underwent a lot of changes, prompted by systemd not working inside /proc-less chroots anymore.

grml-live now uses Linux user namespaces. Unfortunately these are often unavailable inside containers (think Docker, podman).

To unblock the release of Grml 2026.09, we have implemented the workflows we need for releasing. Support for chroot-based workflows is forthcoming; feedback on how these workflows are used exactly is welcome.

In the meantime please take a look at the grml-live changes in git.

As previously announced, grml-live is no longer part of the GRML_FULL ISO flavour.

Get your copy

Now head over to our download page and grab your own copy.

03 September, 2026 02:00PM

hackergotchi for VyOS

VyOS

VyOS Project August 2026 Update

Hello, Community!

In August, the VyOS development branch saw work in a few directions at once. Contributors outside the core team landed new firewall capabilities, a dynamic DNS overhaul, NTP options, and fixes for bugs that only turned up once someone ran a configuration nobody had tried before.

03 September, 2026 11:44AM by Taras Pudiak (taras@vyos.io)

hackergotchi for Volumio

Volumio

7 Best Music Library Managers for Hi-Fi Systems

A music collection can outgrow a basic folder structure long before it stops being personal. The best music library managers do more than display albums: they make a lifetime of rips, downloads, box sets, live recordings, and high-resolution files feel ready to play. For a serious hi-fi system, that means reliable metadata, fast browsing from the listening chair, and playback that respects both the music and the equipment.

The right choice depends on how you listen. Some people want meticulous control over every composer credit and cover image. Others want local files and streaming favorites to live in one familiar interface. A maker building a Raspberry Pi streamer has different needs than a listener who wants to browse a large NAS library from a tablet. The common goal is simple: less time managing files, more time hearing music.

What makes a music library manager worth using?

A library manager is not just a player. At its best, it scans your storage, reads embedded tags, groups tracks into albums, finds artwork, supports search and filtering, and sends music to your audio system without turning each listening session into an IT task.

Start with format support. If your collection includes FLAC, ALAC, WAV, AIFF, DSD, or high-resolution PCM files, the software should recognize them cleanly and preserve useful information such as sample rate, bit depth, and album grouping. Gapless playback matters for live albums, classical works, and records designed to be heard as a continuous sequence.

Metadata is equally important. A manager that treats Artist, Album Artist, composer, conductor, ensemble, release date, genre, and disc number as meaningful fields will keep a large library intelligible. This is especially valuable when you own multiple editions of the same album or a substantial classical and jazz collection. No software can fix incomplete tags by magic, but good tools make corrections practical and keep them consistent.

Finally, consider where the music lives and how it reaches your system. A computer-attached drive may be enough for a modest collection. A NAS is often a better fit for larger libraries and multiroom homes. If your streamer or network player handles playback separately from the control device, the experience can feel far more natural: browse from a phone or tablet, then let the dedicated audio device do the listening.

The best music library managers for different listeners

Roon for rich discovery and whole-home listening

Roon is designed for listeners who want their music collection to feel editorially alive. It brings together local files and supported streaming catalogs, then adds artist biographies, credits, reviews, related performers, release versions, and deep linking across a library. For someone who often begins with one familiar record and follows the musical thread from there, it is an unusually rewarding experience.

Its strength is also its trade-off. Roon is a premium, subscription-based ecosystem that relies on a dedicated Core running on a capable computer or server. It is best for listeners willing to invest in a polished, information-rich environment and compatible endpoints throughout the home. If you simply want lightweight local playback, it can be more platform than you need.

Audirvana for focused computer-based sound

Audirvana appeals to listeners who use a Mac or Windows computer as a central part of their system and want a clean, music-first interface. It handles local libraries, supports high-resolution playback, and can combine local music with selected streaming services. Its library views emphasize albums and artists without overwhelming the screen with social or editorial layers.

This makes it a strong option for a two-channel system in a home office, studio, or dedicated listening room. It is less compelling if you need broad multiroom control or prefer a hardware-led ecosystem that stays independent of a desktop computer. Still, its direct approach has real appeal when the priority is attentive listening rather than endless browsing.

JRiver Media Center for detailed control

JRiver Media Center remains one of the most capable choices for collectors who want to shape every part of their library. It offers extensive tagging, smart lists, custom views, conversion tools, DSP options, and wide file-format support. A listener with a carefully maintained collection of concert recordings, needle drops, surround files, and obscure releases can make it behave almost exactly as they wish.

That flexibility comes with a steeper learning curve. The interface is functional rather than minimal, and new users may need time to understand its many settings. For collectors who enjoy organizing as much as listening, that is part of the value. For everyone else, it may feel more like a control room than an album shelf.

MusicBee for Windows collectors on a budget

MusicBee is a thoughtful local-library manager for Windows users, particularly those who want strong tagging and flexible organization without a costly commitment. It can manage large collections, create intelligent playlists, edit metadata in batches, and support a wide range of formats. Its customization options make it possible to create an interface that favors albums, detailed track data, or a more traditional media-library view.

It is a particularly good fit for a PC-based music archive and for listeners who enjoy refining tags over time. Its main limitation is that it is centered on the Windows desktop rather than a unified network-audio ecosystem. If your priority is controlling a dedicated streamer from multiple devices, you may want software designed around that workflow.

Plexamp for personal-library convenience

Plexamp takes a different path. It is built around a personal music server and offers an approachable way to take a home collection beyond the listening room. Its excellent search, mix-building features, artwork-forward presentation, and remote access can make a large library feel easy to revisit. It is especially appealing to people who want their own music available in the car, at work, or while traveling.

For a traditional hi-fi setup, its appeal depends on your priorities. Plexamp is strong on access and discovery, but listeners seeking detailed playback settings, specialist metadata views, or a deeply hardware-integrated audio experience may prefer another route. It works best when personal-library portability is as important as the main system at home.

Apple Music for an Apple-centered collection

Apple Music is often overlooked as a library manager because many people think of it only as a streaming service. Yet for users already invested in Apple devices, it can organize locally stored music, synchronize playlists and library changes, and keep purchased or imported albums within a familiar interface. Its convenience is difficult to deny when phones, computers, and tablets are all part of the same household.

The trade-off is control. Advanced tagging, format transparency, and specialist playback workflows are not its central focus. It is a sensible solution for an Apple-centered lifestyle and a manageable collection, but less suited to the listener who wants to inspect, curate, and preserve every detail of a high-resolution archive.

Volumio for a unified listening system

Volumio is a natural fit when the goal is to bring local music, supported streaming services, and connected audio devices into one focused music-player ecosystem. Whether it runs on a DIY Raspberry Pi build, a PC-based player, or dedicated hi-fi hardware, its interface is built around the act of choosing and playing music rather than managing a general-purpose computer.

For a local collection, that means browsing by artist, album, genre, and more from a phone, tablet, or computer while the network player handles playback. The benefit is practical: your library can remain on a NAS or USB drive, your control device stays free for browsing, and your hi-fi system retains a purpose-built center. The best setup will still depend on your source storage, streaming preferences, and desired level of metadata detail, but a unified player can remove a great deal of app switching from everyday listening.

Build the library before judging the software

Even the finest manager cannot fully compensate for inconsistent files. Before migrating to a new platform, make a copy of your library and check a representative sample. Confirm that album artists are consistent, multi-disc sets have disc numbers, compilations are marked correctly, and artwork is embedded or stored in a predictable way. Classical listeners should decide early whether they want to prioritize composer, conductor, soloist, ensemble, or work title in their browsing views.

Keep your folder structure simple. A format such as Artist/Album/Track is usually enough, with separate folders only where they genuinely help, such as various artists compilations or classical composers. Avoid renaming thousands of files solely to please one application unless you understand how it writes changes back to your library. Your tags should remain useful if you change software later.

There is no single winner for every collection. The best music library manager is the one that makes your own records easier to find, presents them with the care they deserve, and gets out of the way when the first note begins. Choose the environment that suits your habits, then give yourself an evening with an album you know by heart.

The post 7 Best Music Library Managers for Hi-Fi Systems appeared first on Volumio.

03 September, 2026 09:24AM

hackergotchi for Deepin

Deepin

hackergotchi for Tails

Tails

Tails 7.12

Firefox is moving to a 2-week release cadence starting in September, and so Tor Browser and Tails are doing the same. Tails 7.12 is the first release on this new cadence.

Changes and updates

  • Update Electrum from 4.7.2 to 4.8.1.

  • Update Tor Browser to 15.0.21.

  • Update some firmware packages. This improves support for newer hardware, including graphics cards, Wi-Fi, and more.

Get Tails 7.12

To upgrade your Tails USB stick and keep your Persistent Storage

  • Automatic upgrades are available from Tails 7.0 or later to 7.12.

  • If you cannot do an automatic upgrade or if Tails fails to start after an automatic upgrade, please try to do a manual upgrade.

To install Tails 7.12 on a new USB stick

Follow our installation instructions.

The Persistent Storage on the USB stick will be lost if you install instead of upgrading.

To download only

If you don't need installation or upgrade instructions, you can download Tails 7.12 directly:

03 September, 2026 12:00AM

September 02, 2026

hackergotchi for Univention Corporate Server

Univention Corporate Server

Nubus for Kubernetes 1.22: Secure Password Hashes, More Metrics & Logs that are Easier to Analyze

This release delivers tangible improvements for operations and security. Nubus for Kubernetes 1.22 makes the stored password hashes configurable, enables the metrics of the Keycloak identity provider, and switches log output to structured logging. This gives operators a better view of their environment while raising the level of security at the same time.

Password Hashes: More Control and a More Secure Default

Nubus never stores passwords in plain text; instead, it protects them with current hashing methods. Even someone who gains access to the stored values cannot read passwords from them. Because Nubus supports various authentication methods over protocols such as LDAP, Kerberos, and OIDC, along with a wide range of clients, it stores several of these hashes in parallel – since not every method and not every client can process every hash algorithm.

Sometimes this requires balancing security against functionality. Until now, Nubus has also stored hashes from older methods, such as those needed for Wi-Fi authentication via MS-CHAPv2. For many school environments, this Wi-Fi authentication is a functional must. In security-critical environments, however, the “old” hashes required for it pose a risk.

With Nubus for Kubernetes 1.22, operators gain significantly more influence over which hashing methods are used through the system configuration. At the same time, we have adjusted the default configuration under Kubernetes: only hashes that are considered secure even for critical environments according to BSI TR-02102 are now shipped. In addition, Nubus allows you to remove hashes from older methods.

Incidentally, the configurability of the stored hashes has also been available for Nubus on UCS since Erratum 533. Because significantly more different hashes are used under UCS through the available integrations, we are not changing the default configuration here. Operators of UCS should decide together with Univention Support whether adjustments make sense.

Metrics for Authentication: More Insight into Keycloak

In this release, we not only updated Keycloak but also enabled the metrics that Keycloak supports. This makes it easy to analyze key indicators such as the number of authentications, response times, and errors that have occurred. As a result, operators can assess the state of their environment more quickly and prevent problems.

Screenshot from the Keycloak documentation
Keycloak Capacity Planning example dashboard

The metrics are provided in a way that is compatible with the widely used tools Prometheus and Grafana. In addition, ready-made Grafana dashboards already exist – both from the Keycloak project and from the Grafana community. They can be used directly or serve as a template for your own dashboards.

Switching to Structured Logging: Analyze Logs More Easily

As announced with earlier releases of Nubus for Kubernetes, we are now switching log output to the structured logging format. It has been available as an option since Nubus for Kubernetes 1.17 – and from now on it is the new standard. In solutions such as Elasticsearch, the events documented in log entries can now be analyzed automatically and much more easily.

For now, operators can still use the configuration to fall back to the previous, unstructured log format. A future version of Nubus will no longer support this old format, and new extensions no longer offer it either. We therefore recommend switching to the new format early on.

Comprehensively Updated

As with every release, we have updated numerous components to benefit from improvements and security updates in the open source software we use. For some of the container images shipped with Nubus for Kubernetes, we have switched from Debian 12 (UCS 5.2) to Debian 13 (UCS 5.3) as the source for the software versions. This transition is taking place gradually across the coming releases for all container images.

Nubus for Kubernetes 1.22 is available for download via our container registry as usual. You will find a complete overview of the improvements in the release notes, and the installation steps in the Operation Manual.

Der Beitrag Nubus for Kubernetes 1.22: Secure Password Hashes, More Metrics & Logs that are Easier to Analyze erschien zuerst auf Univention.

02 September, 2026 09:01AM by Ingo Steuwer

hackergotchi for Volumio

Volumio

How to Configure UPnP Playback on Your Network

A music library can be beautifully organized, carefully tagged, and stored in lossless formats, yet still feel frustratingly out of reach when the listening room cannot see it. To configure UPnP playback properly, think of the system as three collaborators on one home network: the music server that shares files, the player that renders them, and the control app that brings them together.

UPnP can make local playback feel refreshingly direct. Choose an album from a phone, tablet, or computer, send it to the hi-fi system, and keep the music playing without moving files or changing inputs. The best results come from a few deliberate choices around network setup, library sharing, and format handling.

What UPnP playback actually does

UPnP, often used alongside the term DLNA, is a set of network standards that lets compatible devices find one another automatically. In a music system, the roles are straightforward. A UPnP media server indexes and shares your collection. A UPnP renderer receives the selected track and plays it through its digital or analog outputs. A control point is the app or interface used to browse music and tell the renderer what to play.

Those roles may live on separate devices, or more than one may be handled by the same device. A NAS might run the server, a network player may be the renderer, and a phone can act as the controller. This flexibility is useful, but it also explains why an issue can appear in one part of the chain while everything else looks normal.

UPnP is particularly well suited to listeners with substantial local libraries. It preserves the sense of ownership and curation that comes with a personal collection, while making albums, artists, composers, and playlists available from the listening seat.

Start with the network, not the app

Before adjusting playback settings, confirm that every device is on the same local network. The server, player, and controller should normally be connected to the same router and subnet. A device on a guest Wi-Fi network may have internet access but be intentionally prevented from discovering your player or server.

For a fixed hi-fi component, Ethernet is usually the preferred connection. It avoids the variability of crowded wireless networks and can be especially reassuring when streaming high-resolution files from a NAS. Good Wi-Fi can work very well for a controller and, in many homes, for a player too. The deciding factor is consistency, not simply the connection type.

If devices do not appear, check for Wi-Fi client isolation, guest-network separation, or VLAN rules that block multicast traffic. UPnP discovery relies on multicast messages, so a network designed to keep devices isolated may also keep your music system from finding itself. Managed switches and advanced routers can also affect multicast behavior through IGMP snooping settings. These tools are useful, but a poorly configured rule can make discovery intermittent.

Do not expose a UPnP server directly to the public internet or create port-forwarding rules for it. UPnP playback is intended for your trusted home network. Remote access, if you need it, should be handled through a secure method designed for that purpose.

Configure UPnP playback in a practical order

A reliable setup is easiest when you establish one role at a time. First, choose where the music library will be served from. A NAS is a natural choice for an always-available collection, while a computer can be ideal for a smaller library or for listeners who only play music when that computer is on.

1. Prepare the library folder

Place your music in a folder the media server can access consistently. If the library sits on network storage, use a stable share and ensure the server has permission to read it. Avoid moving the folder or changing its name after the library has been indexed, unless you are prepared to rescan.

A clear folder structure helps, even though UPnP browsing is usually driven by metadata. Organize files by artist and album, and use accurate embedded tags for album artist, release year, genre, track number, and artwork. Classical collections benefit from extra care with composer, conductor, ensemble, and work tags. The server can only present the information it receives.

2. Enable the media server and scan the collection

Open your chosen UPnP server and add the library folder as a music source. Let the initial scan finish before judging search speed or browsing quality. Large libraries can take time, particularly when the server is reading high-resolution artwork and detailed metadata.

Once scanning is complete, browse the library from a control point. Check a few albums that are likely to reveal tagging problems: a multi-disc release, a compilation, a classical recording, and an album with high-resolution artwork. Correcting metadata early is far more satisfying than trying to navigate a disordered collection later.

3. Confirm the renderer is visible

Power on the network player and make sure it has an address from your router. Then open the controller and look for available playback devices. Select the renderer before choosing music, rather than relying on a default output that may point to the phone or tablet.

A Volumio-based player can provide a focused listening interface for this role, bringing local library playback and connected audio control into the same music-first environment. Whatever renderer you use, give it a recognizable name. “Living Room Hi-Fi” is more helpful than a generic factory label when multiple devices are visible.

4. Select formats and transcoding carefully

The ideal setting is usually direct playback: the server sends the original file, and the renderer decodes a format it supports. This keeps the signal path simple and avoids unnecessary processing.

Transcoding has a place, however. If a renderer does not support a file format, sample rate, or bit depth in your library, the server can convert it to a compatible stream. That solves a compatibility problem, but it can increase CPU load on the server and may alter the original format. Use transcoding when it is needed, not as a default for every track.

For lossless libraries, verify support for the formats you use most often, such as FLAC, WAV, AIFF, ALAC, or DSD where applicable. Also check whether the renderer supports gapless playback through your specific server and controller combination. UPnP compatibility is broad, but the finer details of implementation can vary.

5. Set volume behavior with intention

Decide where volume control belongs in your system. If your network player feeds an integrated amplifier or preamplifier, fixed output may be appropriate, with level controlled by the analog component. If the player is connected directly to a power amplifier or active speakers, its digital volume control may be the practical choice.

There is no universal answer. Fixed output can prevent accidental double attenuation, while digital volume gives convenient control from the listening position. What matters is knowing which component is in charge before pressing play at a higher-than-expected level.

Troubleshoot the problems that matter most

When a server is visible but an album will not play, begin with one known-good file in a common format. A standard CD-quality FLAC or WAV track is useful for this test. If it plays, the network path is likely sound and the issue may be format support, transcoding, or a damaged file.

When the player is missing entirely, restart the controller app first, then the renderer, then the server. Discovery information can become stale after router updates, sleep mode, or a changed IP address. Restarting the router is worthwhile only after checking that all devices are actually connected to the expected network.

Dropouts call for a different approach. Check signal strength if the player uses Wi-Fi, pause large downloads and cloud backups, and try Ethernet temporarily. If the issue disappears on a wired connection, you have narrowed the cause without replacing any audio equipment.

If browsing is slow or albums appear under the wrong artist, inspect metadata rather than the network. Inconsistent Album Artist tags are a common reason compilations and collaborations become scattered. A careful library cleanup improves every control app that reads the same server.

Build a system you will want to use

UPnP playback is at its best when it fades into the background. The goal is not to admire a network diagram. It is to sit down, find the version of an album you love, and hear it through the system you chose with care.

Give the server a stable home, keep the player on a dependable connection, and treat metadata as part of the collection rather than an afterthought. Then your library becomes what it should be: a living part of the listening room, ready whenever the next record calls.

The post How to Configure UPnP Playback on Your Network appeared first on Volumio.

02 September, 2026 05:21AM

September 01, 2026

hackergotchi for SparkyLinux

SparkyLinux

Sparky news 2026/08

The 8th monthly Sparky project and donate report of the 2026: – Linux kernel updated up to 7.2.2, 6.18.48-LTS, 6.12.107-LTS (6.12: amd64 + i686-pae) – Sparky 8.4 of the stable line released, including i686-pae/32bit Minimal ISO images Many thanks to all of you for supporting our open-source projects. Your donations help keeping them and us alive. Don’t forget to send a small tip in…

Source

01 September, 2026 06:08PM by pavroo

hackergotchi for Volumio

Volumio

A Practical Guide to Audio Streaming Protocols

A great network player can make music from a hard drive, a phone, and a favorite streaming service feel like one collection. The catch is that those sources do not all speak the same language. This guide to audio streaming protocols explains what those languages do, where they sound their best, and how to choose the right one for the way you listen.

The short version: a protocol affects more than whether music plays. It can determine which app controls playback, whether the stream is lossless, how reliably rooms stay in sync, and whether your music player or your phone is doing the heavy lifting. There is no single best choice for every system. A carefully organized local library and a casual evening with friends place very different demands on a streamer.

What an audio streaming protocol actually does

An audio streaming protocol is the set of rules that lets one device find another, send it music, and control playback over a network or wireless connection. Your phone may discover a player, pass along a track selection, or transmit the audio itself. Those are not always the same thing.

This distinction matters. With one method, your phone sends audio directly to the player and remains central to the playback chain. With another, the phone simply tells the player what to play, after which the player retrieves the music from your server or streaming service. The latter approach often preserves battery life, reduces interruptions from calls and notifications, and can offer higher-quality playback depending on the service and hardware.

Audio quality is only one variable. Supported formats, sample rates, gapless playback, multiroom behavior, metadata, queue management, and volume control can all change from protocol to protocol. The ideal setup is the one that gets you to the music with the least friction while respecting the capability of your hi-fi system.

Guide to audio streaming protocols: the main choices

UPnP and DLNA for local music libraries

UPnP, often used alongside DLNA, remains one of the most useful standards for listeners with their own files. It is built around three roles: a media server that indexes music, a control point that lets you browse it, and a renderer that plays it. Sometimes one app or player handles more than one of these roles.

In practical terms, this can mean a music library stored on a NAS drive or computer is indexed by a server, then browsed from a phone or tablet and played through a network streamer. It is a natural fit for FLAC, WAV, ALAC, DSD, and other locally held formats, provided every part of the chain supports them.

The appeal is freedom. You are not tied to one music service or one operating system, and your collection can remain at the center of the experience. The trade-off is that UPnP is a broad standard, so the polish of browsing, search, artwork, and format handling depends heavily on the server and control app you choose. Good implementation makes it feel effortless. Poor implementation can make an excellent library feel scattered.

For a listener with a substantial ripped CD collection or high-resolution downloads, UPnP is often the protocol worth understanding first. It treats your library as a real music collection rather than a folder of files.

AirPlay for Apple-friendly convenience

AirPlay is designed for simple playback from Apple devices. Select a compatible player from an iPhone, iPad, or Mac, then send music from many supported apps with little setup. It is especially convenient for family members and guests who already live comfortably in Apple’s ecosystem.

Its strength is familiarity, not maximum format flexibility. Depending on the AirPlay version and the devices involved, the transmission path may be limited compared with what a dedicated local-library protocol or a direct streaming-service connection can support. For many listening sessions, that limitation is not a problem. For a system built around high-resolution files, it is worth checking the actual behavior of every device in the chain instead of assuming the badge tells the whole story.

AirPlay also keeps the source device more involved than a true direct-play approach. That is perfectly reasonable when you want to send a podcast, a radio station, or an album from an app that does not have its own native player integration.

Chromecast for broad app support

Chromecast built-in follows a different model. A phone or tablet generally acts as a controller: it tells the compatible player what to retrieve, then the player pulls the stream from the internet. Once playback begins, your phone can leave the room, lock its screen, or take a call without necessarily stopping the music.

For streaming services, this can be a very appealing arrangement. The app you already use stays in charge of discovery and playlists, while the network player handles playback. Chromecast can also support group playback in compatible ecosystems, though synchronization and feature availability vary by product and app.

Its limitations are mostly about ecosystem decisions. Some services expose more controls than others, and the resolution available can depend on the service tier, the app, and the receiving hardware. If your priority is using a wide range of mainstream apps with minimal setup, it is a strong option. If your priority is one consistent interface for local files and several services, you may prefer to center playback around your music-player platform instead.

Bluetooth for fast, close-range playback

Bluetooth is not a network streaming protocol in the same sense as UPnP or Chromecast, but it belongs in any real-world conversation about wireless audio. It sends sound from a nearby device directly to a speaker, headphone, or receiver. No home network is required.

That makes it ideal for quick listening, visiting friends, and places where Wi-Fi is unreliable. Modern Bluetooth codecs can sound very good, especially in casual systems. Still, Bluetooth usually involves compression, and its quality depends on codec support at both the sending and receiving ends. It also offers less range and less whole-home flexibility than Wi-Fi-based playback.

Use Bluetooth because it is the right tool for immediacy, not because it is automatically the highest-fidelity path. A dedicated streamer connected by Ethernet or strong Wi-Fi is generally the better foundation for serious listening from local files and lossless services.

Service Connect features for direct streaming

Many music services offer their own Connect-style playback. The service app becomes the remote control, while the compatible streamer logs into the service and receives the music directly. Spotify Connect and TIDAL Connect are familiar examples of this model.

This approach is elegant because it combines the service’s own discovery tools with direct playback on the audio device. Your phone does not have to relay the stream, and switching from headphones to the hi-fi can be as simple as choosing another playback device in the app.

The trade-off is fragmentation. Each service has its own interface, features, quality settings, and device support. If you move among multiple services, internet radio, and a personal library, repeatedly changing apps can interrupt the listening experience. A unified player interface can reduce that friction while still preserving direct service playback where it is available.

How to choose the right protocol for your system

Start with the music you play most often. For a local library, prioritize UPnP compatibility and a server that handles your file formats, tags, and artwork well. For a household built around Apple devices, AirPlay may be the easiest common language. For listeners who spend most of their time inside a particular streaming app, its native Connect feature can be the most natural route.

Then consider the role of your network. Ethernet is the most predictable connection for a fixed player, particularly where high-resolution files or busy household Wi-Fi are involved. Strong Wi-Fi can be excellent, but placement, router quality, and network traffic all matter. A protocol cannot compensate for a weak signal or an overloaded network.

Finally, think about control. Do you want to browse from the streaming service’s app, a phone-friendly library manager, or one interface that brings sources together? Volumio is built around that last idea: all your music in one place, with a focused listening experience that can grow from a DIY player to a dedicated hi-fi component.

Do protocols change sound quality?

They can, but not in the simplistic way protocol comparisons sometimes suggest. If two paths deliver the same audio data without unwanted conversion, arrive reliably at the player, and use the same DAC and analog chain, the result may be indistinguishable. Differences become more likely when one path resamples audio, applies lossy compression, has limited format support, or relies on an unstable connection.

The best test is practical. Play familiar music, verify the format reaching your player, and listen over several sessions rather than chasing instant impressions. The protocol that preserves your preferred quality while making you want to play more music is doing its job.

Choose the path that fits your collection, your services, and the people who share your system. When the technology disappears into the background, an album can finally hold the room the way it was meant to.

The post A Practical Guide to Audio Streaming Protocols appeared first on Volumio.

01 September, 2026 10:15AM

August 31, 2026

hackergotchi for ARMBIAN

ARMBIAN

Github Highlights

Github Highlights

This week&aposs development centered on kernel and toolchain progression, expanded board support, and substantial wireless driver cleanup.

Mainline tracking advanced with kernel bumps to 7.2-rc7, Rockchip edge promoted to 7.2, and sunxi edge moved to 7.1.y. Platform work included loong64 migration from debian-ports to the main Debian archive with corresponding apt repository publishing, mainline kernel and U-Boot enablement on the Avaota A1, restored CONFIG_DWMAC_SUN8I for sunxi64, and a new RK3528 bl32/DDR blob update. Rockchip64 also received backported fixes for an 8250 DMA reopen crash and for CAN TX stalls.

Board coverage grew across multiple vendors, with the NanoPi NEO3 Plus (RK3528A) added and standard-support promotions for the Anbernic RG DS and RG Vita Pro, LubanCat 5IO, Luckfox Nova, and Qidi X-6. UEFI device-tree support was extended with Qualcomm X1E patches and new CIX mainline support, while the Radxa E24C was reworked against U-Boot 26.07 and the v7.2-rcX kernel.

Wireless stacks saw a coordinated quality pass: the rtl8852bs driver had thousands of compiler warnings resolved across missing prototypes, unused functions and variables, enum conversions, and empty-body cases, alongside a NULL-dereference fix and stricter proc write handling. The uwe5622 (unisocwifi) driver received parallel structural cleanups, including a flexible array conversion and forward-declaration hygiene, with both drivers rebased to their August 2026 upstreams.

#Armbian #EmbeddedLinux #Rockchip #Allwinner #MainlineKernel #WirelessDrivers #LoongArch

Changes

31 August, 2026 10:58PM by Michael Robinson

hackergotchi for Purism PureOS

Purism PureOS

PureOS Development Report: July 2026

Welcome back! In our June update, we discussed PureOS's downstream relationship with Debian. Just as PureOS Crimson is based on Debian Bookworm, PureOS Dawn is based on Debian Trixie.

We modify many Debian packages for PureOS to provide the best experience on all Librem devices. Often, when we reach a new Debian release, there will be packages with changes on both sides, creating a conflict.

The post PureOS Development Report: July 2026 appeared first on Purism.

31 August, 2026 06:20PM by Purism

hackergotchi for GreenboneOS

GreenboneOS

CRA Implementation at Greenbone: How We Made the Reporting Obligation Operational

We already explained what requirements the Cyber Resilience Act imposes as of September 11, 2026, in a separate post on the implementation status of the CRA reporting obligation. This post answers the other half of the question: how the implementation was carried out at Greenbone itself. One clarification up front, because it is decisive for […]

31 August, 2026 10:52AM by Greenbone AG

hackergotchi for Volumio

Volumio

How to Connect a Streamer to a DAC Properly

A dedicated streamer and a capable DAC can be one of the most satisfying pairings in digital audio. The streamer brings your music library, streaming services, and network into the system; the DAC turns that digital signal into the analog music your amplifier can use. To connect a streamer to a DAC well, the goal is not simply to make sound come out. It is to choose the connection that suits your components, your listening habits, and the music you love.

The good news is that this is usually straightforward. Most systems will use USB, coaxial S/PDIF, optical S/PDIF, or AES/EBU. Each can sound excellent when implemented well. The right choice depends less on internet folklore and more on the outputs on your streamer, the inputs on your DAC, the cable run, and which features you need.

Start with the right roles in your system

Before connecting anything, make sure you know which component is doing what. A network streamer receives music from your local library, internet radio, or services such as TIDAL, Qobuz, and Spotify. A standalone DAC converts that incoming digital data to analog audio. Your preamplifier, integrated amplifier, or active speakers then handle amplification.

This distinction matters because many streamers include an internal DAC. If you are using an external DAC, you should send a digital signal from the streamer and select the matching digital input on the DAC. Do not connect an analog output from the streamer to a digital input on the DAC. It will not work, and it defeats the purpose of using the external converter.

Some all-in-one units can be configured either as a digital transport feeding an external DAC or as a complete streamer-DAC. Check the playback settings before you begin. If the device has a choice of output modes, select digital output and confirm that volume control is set appropriately for your system.

How to connect a streamer to a DAC

The simplest approach is to look first for the best shared connection between both components. If your streamer has USB audio output and your DAC has USB input, that is often the most flexible place to begin. If USB is unavailable, coaxial or optical S/PDIF are common and highly capable alternatives. AES/EBU is an excellent option when both components support it.

Turn both components off before making the connection. Attach one cable between the streamer’s digital output and the DAC’s corresponding digital input, then power the DAC on first and the streamer second. Select that input on the DAC. Finally, play a familiar track and confirm that the DAC indicates a valid incoming signal and the expected sample rate.

If there is no sound, start with the obvious checks: confirm the correct DAC input is selected, verify the streamer is set to the intended output, and make sure your amplifier is set to the correct analog input. These small settings account for most first-time setup issues.

USB: the most flexible digital connection

USB is widely used because it can support very high-resolution audio formats and often lets the DAC take control of timing through asynchronous USB operation. In practical terms, the DAC receives the music data and uses its own clocking system to convert it. This can be a strong choice for a modern DAC designed around a high-quality USB input.

Use a properly made USB cable that is the right length for your rack. There is no need for an exotic cable to establish a reliable connection, but loose connectors, damaged plugs, and excessively long runs can create problems. Keep the cable away from power transformers and crowded power strips when possible.

USB can also carry electrical noise between components because it includes a ground connection. Whether that is audible depends on the specific streamer, DAC, power supplies, and rest of the system. If you hear a buzz, whine, or computer-like noise during silent passages, try a different connection type or investigate grounding elsewhere in the system before assuming the DAC is at fault.

Coaxial S/PDIF: a trusted hi-fi standard

Coaxial S/PDIF uses an RCA or BNC connection and a 75-ohm digital cable. It is a favorite in many two-channel systems because it is simple, mechanically secure, and supported by a wide range of dedicated audio components.

Coaxial usually handles high-resolution PCM comfortably, although exact limits vary by manufacturer. Some DACs also accept DSD over compatible S/PDIF implementations, while others do not. If you play mixed libraries with high-resolution files, check your components’ manuals for supported formats and sample rates.

Use a cable intended for 75-ohm digital transmission rather than an arbitrary analog RCA interconnect if you can. A short, correctly specified coaxial cable is a sensible starting point and can provide excellent results without complicating the system.

Optical S/PDIF: useful when isolation matters

Optical, often called Toslink, sends data as light rather than electricity. That physical separation can be valuable in systems where ground noise is a concern. If your streamer is near a television, cable box, computer, or other potentially noisy equipment, optical may provide a quieter path.

The trade-off is that optical inputs and outputs vary more widely in their maximum supported resolution. Many are ideal for CD-quality and standard high-resolution playback, but some do not support the highest sample rates available through USB or coaxial. For many music collections, that limitation is irrelevant. A clean, stable optical connection playing the music you actually listen to is more valuable than a specification you never use.

Avoid sharply bending an optical cable and make sure its plugs click fully into place. A poorly seated Toslink connector can cause intermittent dropouts or prevent the DAC from locking to the signal.

AES/EBU: built for balanced digital transmission

AES/EBU uses a three-pin XLR connection and is common on higher-end DACs and professional-derived audio equipment. It is designed for balanced digital transmission and can work especially well over longer cable runs. If your streamer and DAC both offer AES/EBU, it is well worth trying.

As with coaxial, use a cable specified for digital AES/EBU use rather than a standard analog microphone cable when possible. The connectors look familiar, but the electrical requirements are different. This is not a reason to overthink the purchase – it is simply a matter of using the appropriate tool for the connection.

Set volume control with care

Once music is playing, decide where you want volume to be controlled. In a conventional system with an integrated amplifier or preamplifier, set the streamer to fixed output if available and use the amplifier’s volume control. This preserves a clear gain structure and makes everyday operation predictable.

If your DAC has a high-quality analog volume control and connects directly to a power amplifier or active speakers, it may serve as the system’s control center. A streamer with digital volume control can also be used in some setups, but be deliberate. Start at a very low volume whenever you change output mode, connect directly to an amplifier, or bypass a preamp. Digital systems can reach full-level output quickly.

Match format settings to your DAC

A streamer may offer options for sample-rate conversion, DSD handling, volume normalization, crossfade, or digital filters. These settings are useful, but they are not mandatory. Begin with bit-perfect or native playback when your DAC supports the source format, then make changes only when they solve a real need.

For example, a DAC that accepts PCM up to 192 kHz over optical may require the streamer to downsample files above that rate for optical playback. A USB connection may allow those files to play natively instead. Neither answer is universally better. The best choice is the one that gives you stable playback and the features you value.

If a track will not play, do not immediately blame the network. Check the format shown in the streaming app or local library, then verify that the selected output can carry it. A properly configured streamer should make these decisions easy, not force you to manage separate music experiences for every source.

Listen before chasing upgrades

After setup, give the system time. Play recordings you know well: a vocal with natural phrasing, an acoustic instrument with believable tone, a dense live track, and something with deep bass. Listen for consistency, timing, space, and the way music holds together at both low and realistic listening levels.

If two connections are available, compare them one at a time with the same track and volume. Avoid changing cables, filters, and output modes all at once. A calm comparison will tell you more than a long list of claims.

A thoughtfully designed streamer should make this part feel natural. Volumio brings local libraries, streaming services, and connected audio devices into one music-first environment, so the focus can return to choosing an album rather than choosing an app.

The final connection is not a trophy for the back of the rack. It is the one that lets your DAC receive a stable signal, fits the rest of your system, and disappears when the first great song begins.

The post How to Connect a Streamer to a DAC Properly appeared first on Volumio.

31 August, 2026 05:21AM

August 30, 2026

hackergotchi for Xanadu developers

Xanadu developers

August 29, 2026

hackergotchi for Maemo developers

Maemo developers

An In-Depth Look at the LiberNovo Omni SE

Two months, one chair, and a cushion that had to be replaced – twice. This isn’t a review in the strict sense. The only other chair I’ve used long-term is an IKEA Nominell, so I can’t offer broad comparisons. What I can offer is an honest account of living with the Omni SE – plus a few observations most reviews skip.

Where I’m coming from

My background shapes what I look for in a chair, so it’s worth stating up front.

I never had back problems with my old IKEA chair, but I credit that to regular exercise rather than to the chair. In my experience, exercise is by far the most effective way to prevent back pain – closely followed by changing posture throughout the day: standing up now and then and putting your leg muscles to work.

The upshot: for me, the specific chair matters less than people assume. What I value instead are quality-of-life features – freedom to move and the ability to recline deeply for a quick moment of relaxation. That’s the lens I judged the Omni SE through.

The Omni chairs hardly need an introduction; they’re among the most aggressively marketed chairs on social media. So rather than rehash the spec sheet (Dan Ahn’s YouTube channel covers that well), I’ll stick to my own experience.

Ordering

I paid the 10€ deposit, ordered on 16 June for 589€, and received the chair on 23 June – so about two months of use at the time of writing.

The 10€ “deposit” turned out to be a one-year warranty extension rather than a deposit. Fine by me.

The seat cushion problem

The downside of ordering early and cheap: at least the first batch shipped with foam that was too soft in the seat cushion.

The Omni cushion combines three foam densities, with the firmest section only near the backrest. Even that section wasn’t firm enough – once the foam warmed up, you’d sink through to the plastic pan. Steve, the Anthros CEO, summarises the issue neatly – keep in mind though, that this is coming from a rival.

If you’re reading this in a seemingly fine Omni and wonder what this feels like, sit on the front edge for a few minutes: the softer foam lets you bottom out. Sit with your lumbar against the backrest and you’re on the firm section, where it should feel comfortable.

Customer support assured me that batches produced after early May went through improved firmness testing – which means my chair was made before that. At the time of writing, it’s still unclear whether all new deliveries ship with the updated cushion. So if you’d rather not go through the hassle of getting a replacement, wait until that’s confirmed.

How support handled it

Sitting with my lumbar against the backrest was exactly where the problem showed up for me, so after a few uncomfortable weeks I contacted support via email. They replied within 24 hours, and their first suggestion was that I should sit closer to the backrest. Once I confirmed I already was, they promised a revised cushion – and noted that my return window would restart on the day the replacement arrived.

A week later a new cushion arrived – the Pro version, sent by mistake. Since the correct replacement was another month out, I used the Pro cushion in the meantime; its firmer foam didn’t bottom out. I also received a small compensation package for the inconvenience, including the StepSync Mat, which turned out to be surprisingly handy – more on that below.

The correct SE cushion arrived at the end of August, so at the time of writing I’ve used the Pro cushion for about a month and the revised SE cushion for three days.

On the two replacement cushions

The revised SE cushion is noticeably stiffer than the one my chair originally shipped with, across all three foam zones.

The Pro uses Gabriel Atlantic fabric, which the active ventilation requires because it allows more airflow. It’s also more durable. The trade-off is the coarser weave: less soft and slightly scratchy compared to the standard fabric.

In terms of firmness, the two replacement cushions feel about the same to me – the fabric is the main difference. Upgrading to the Pro just for the fabric isn’t worth it in my view.

Backrest and recline

The backrest is what LiberNovo builds its marketing around, and deservedly so. Sitting down for the first time, it was the most noticeable difference to my IKEA chair: it hugs you around the lumbar region and you immediately feel supported, without limiting your range of motion.

The second standout is the recline. If you’ve ever wanted to lie back for a moment of relaxation and quick back relief, that’s what the 160° position gives you. Even at maximum recline the chair feels stable – but to be genuinely comfortable, you’ll want to raise your legs. Whether that calls for the official footrest is up to you; I put the StepSync Mat on the subwoofer under my desk and called it a day.

Day to day, though, I keep the chair locked at 135° with the tension tightened up – that lets me move freely back and forth while still getting the back support.

Armrests

These get called out as a weak point, so I’ll say plainly that I like them. Yes, they slide forward and backward very easily – but for me that’s an advantage: I can pull up to the desk and the armrests simply move out of the way. If you prefer them to stay put, I can see it being annoying.

The one real drawback: at the two narrowest width settings they collide with the backrest unless fully extended forward.

Material-wise, the firmness and smooth surface are pleasant. Keep in mind, though, that my old chair had no armrests at all.

The standout: parts availability

The cushion swap points to what I consider LiberNovo’s real strength – not the chair itself, but what you can do with it after you buy it.

Competing brands may advertise a 12-year warranty instead of six, but their spare-parts selection is very limited. With LiberNovo you can order every individual component – and, unusually, at fair prices: building an Omni SE from parts comes to €681, against €679 for the finished chair (current price). Most brands price their spares steeply enough to make that comparison absurd.

What that enables is customization: want a headrest in a different colour? Order that spare part. Worried about the motorized lumbar? Swap in the manual one from the SE.

Verdict

After two months, I’m happy with the upgrade. The Omni SE is far more comfortable than my IKEA chair, and I use the recline often – reading a book, or just taking the load off my back.

The biggest drawback is probably the fixed seat depth. You can change it later by buying the 45 cm / 48 cm cushion replacement, but that still doesn’t let different people share the same chair.

LiberNovo recently extended the warranty to six years for everyone, which makes seven with my deposit. Since the SE has no electronic components, that covers the whole chair in my case.

My cushion wasn’t right out of the box, and it still took two months and two shipments to sort out. But the parts availability and the support response mean you’re not stuck with a problem you can’t fix – and that, more than any spec, is what won me over.

I’ll update this post if anything changes.

0 Add to favourites0 Bury

29 August, 2026 11:27AM by Pavel Rojtberg (pavel@rojtberg.net)

hackergotchi for Volumio

Volumio

Standalone DAC Versus Streaming DAC Compared

A great digital front end is not defined by how many boxes it occupies. The standalone DAC versus streaming DAC question is really about where you want digital music to become analog – and how much control, flexibility, and simplicity you want before that moment. For some systems, separating those jobs is the clearest route to long-term satisfaction. For others, a well-designed streamer with its own DAC makes listening more immediate and less complicated.

The right choice begins with your listening habits, not a spec sheet. If your evenings move between Qobuz, TIDAL, internet radio, and a carefully organized local library, the experience of finding and playing music matters as much as conversion circuitry. If you already own a digital source you love, or you enjoy shaping a system one component at a time, a dedicated DAC may be the better foundation.

What a standalone DAC does

A standalone digital-to-analog converter takes a digital signal from a source and turns it into the analog signal your amplifier can use. That source might be a network streamer, CD transport, computer, television, or music server. The DAC’s purpose is focused: receive digital audio well, manage timing and noise carefully, and deliver a clean, musical analog output.

This separation gives you choice. You can change your streamer without replacing your DAC, or try a different DAC character while keeping the rest of the digital chain intact. It also allows you to select a converter with the inputs, outputs, volume control, headphone section, or analog stage that suits your system.

A standalone DAC is especially compelling when it has more than one job to do. Perhaps your streamer is only one source among a television, a disc player, and a desktop computer. Perhaps you use a preamp with multiple analog inputs and want the DAC to remain the central digital hub. In these cases, a dedicated component can make the system more coherent.

That said, a separate DAC does not automatically produce better sound. Its quality depends on the implementation: power supply design, clocking, digital input stage, analog output circuitry, grounding, and the care taken in the complete design. The connection between streamer and DAC matters too. A mismatched digital output and input, a poorly configured computer, or an unnecessary conversion step can reduce the benefit of a more ambitious setup.

What a streaming DAC does differently

A streaming DAC combines network playback and digital conversion in one component. It connects to your home network, accesses streaming services and local music, and sends analog audio directly to an integrated amplifier, preamp, or active speakers. One well-chosen unit can replace a chain of separate boxes, cables, and power supplies.

For many listeners, this is the most natural answer. You open one interface, search across services and your own library, choose an album, and play it. There is no need to decide whether a particular app controls the streamer, the DAC, or a separate server. The best integrated designs make the technology recede so the music can take the foreground.

A streaming DAC can also reduce opportunities for system noise and setup errors. Fewer connections do not guarantee superior performance, but they can create a cleaner, more dependable installation. This is valuable in a living room system, on a sideboard where space matters, or with active speakers where a dedicated DAC and streamer may feel excessive.

The trade-off is that source and conversion are tied together. If you later want a different DAC signature or a new digital input arrangement, you may need to add another component or replace the streaming DAC. For some owners, that is not a concern. A thoughtfully engineered integrated player can remain satisfying for years, particularly when its software platform continues to evolve.

Standalone DAC versus streaming DAC: sound quality

The most honest answer is that either architecture can sound exceptional. A standalone DAC has potential advantages when the budget supports a genuinely high-quality converter and the rest of the system reveals the difference. Separating the streamer and DAC can also place physical distance between network circuitry and sensitive analog stages, depending on the designs involved.

But integration has advantages of its own. When the streamer and DAC are designed together, the manufacturer can optimize the digital handoff, clocking, power distribution, grounding, and analog output as one system. There is no need to guess whether a particular cable, output protocol, or input receiver will bring out the best in two independently designed products.

Listen beyond the familiar audiophile vocabulary. A better digital front end should make vocal phrasing easier to follow, allow a bass line to carry pitch rather than just weight, and preserve the space around instruments without making recordings feel etched or thin. It should also make you want to hear another track. If a change brings more detail but turns long listening sessions into analysis, it may not be the upgrade your system needs.

Your amplifier and speakers set the context. In a resolving two-channel system, a dedicated DAC may reveal meaningful gains in tonal color, image depth, and low-level dynamics. In a compact system with an integrated amplifier or active speakers, a fine streaming DAC may deliver a more balanced result by putting more of the budget into the speakers, room setup, and music itself.

Choose based on the system you have

A standalone DAC often makes sense if you already have a capable network streamer, need several digital inputs, or expect to refine your system over time. It also suits listeners who enjoy comparing components and want each part of the chain to have a clear role. A dedicated DAC such as Volumio Preciso can be the analog centerpiece of a flexible digital system, while the streamer remains free to evolve independently.

A streaming DAC is often the stronger choice if you are building from scratch, want an elegant path to active speakers or an integrated amplifier, or prefer fewer boxes without giving up serious sound. It is also attractive for households where more than one person uses the system. A single, intuitive music interface is easier to enjoy than a stack of devices that only one person understands.

Consider placement before committing. Separate units need shelf space, digital interconnects, and usually an additional power outlet. They may also need careful cable routing if your system includes a turntable or sensitive analog equipment. An integrated player reduces those practical demands and can make a system feel more welcoming in a shared room.

Budget should be considered as a complete system question. A modest streamer plus a costly DAC can be rewarding, but only if the streamer offers the software experience and connectivity you need. Conversely, spending heavily on a streaming DAC while neglecting speakers, amplification, or room placement rarely pays off. Put your money where it changes the listening experience most clearly.

Software is part of the component

Digital playback is not only hardware. Library browsing, search, multiroom options, service support, metadata, radio discovery, and update policy shape how often you sit down and listen. A technically excellent converter attached to a frustrating software experience can make your music collection feel smaller than it is.

This is where streaming DACs have a practical advantage: the software and hardware arrive as one intended experience. Yet a standalone DAC paired with a capable streamer can be equally satisfying, especially for listeners who want to choose their playback platform separately from their conversion stage. There is no universal winner. There is only the system that removes friction between you and the next record.

A simple way to decide

If you are uncertain, start with the role you need to fill. Do you need a better source for streaming and local files, a better converter for an existing source, or both? If your current streamer is reliable and enjoyable but its analog output is the weak point, a standalone DAC is a logical next step. If your current experience involves switching apps, adapters, and inputs just to play an album, an integrated streaming DAC may be the more meaningful improvement.

Audition with music you know deeply, including recordings that are less than perfect. Notice how easily you can navigate to them, how long it takes to start playing, and whether the sound remains involving at both low and realistic volume. The best choice will not merely impress in a short comparison. It will invite you back to the music, night after night.

The post Standalone DAC Versus Streaming DAC Compared appeared first on Volumio.

29 August, 2026 05:18AM

hackergotchi for Qubes

Qubes

QSB-118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting

We have published Qubes Security Bulletin (QSB) 118: Dom0 arbitrary code execution in qvm-copy-to-vm error reporting. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.

Qubes Security Bulletin 118


             ---===[ Qubes Security Bulletin 118 ]===---

                              2026-08-28

    Dom0 arbitrary code execution in qvm-copy-to-vm error reporting

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.

Summary
--------

If `qvm-copy-to-vm` is used to copy a file from dom0 to a malicious
qube, that qube can inject an arbitrary command into dom0.

Impact
-------

If an attacker has compromised a qube, and if the user initiates a
`qvm-copy-to-vm` call from dom0 to the compromised qube, then the
attacker can exploit this vulnerability in order to inject an arbitrary
command into dom0, which allows the attacker to take control of
Qubes OS.

Technical details
------------------

The `qvm-copy-to-vm` tool allows copying files from dom0 to a specified
qube. It uses the "qfile" protocol, which is a simplified archive
format, including simple file metadata (much simpler than `tar` or
`cpio`). The protocol also includes transfer confirmation at the end,
which is sent by the target back to the source. This confirmation
includes a checksum of all the transferred files, an error code (if
any), and the name of the last received file. In the case of an error,
as reported by the error code field, dom0 displays a GUI message that
includes the error information and the name of the affected file, as
reported by the target qube. The vulnerability exists in the processing
of that file name:

1. The `wait_for_result()` function calls `sanitize_remote_filename()`
on the received name before passing it to the error handler:

linux-utils/qrexec-lib/pack.c:

     55 static void sanitize_remote_filename(char *untrusted_filename)
     56 {
     57     for (; *untrusted_filename; ++untrusted_filename) {
     58         if (*untrusted_filename < ' ' ||
     59             *untrusted_filename > '~' ||
     60             *untrusted_filename == '"')
     61             *untrusted_filename = '_';
     62     }
     63 }
     64
     65 void wait_for_result(void)
     66 {
    ...
     98     /* sanitize the remote filename */
     99     sanitize_remote_filename(last_filename);
    100
    101     errno = hdr.error_code;
    102     if (hdr.error_code != 0) {
    103         switch (hdr.error_code) {
    104             case EEXIST:
    105                 call_error_handler("A file named \"%s\" already exists in QubesIncoming dir", last_filename);
    106                 break;
    ...

2. Then, `call_error_handler()` calls the dom0 variant of the error
reporting function -- `gui_fatal()` -> `display_error()`, which uses
`system()` to launch the actual error dialog:

core-admin-linux/file-copy-vm/qfile-dom0-agent.c:

     15 void display_error(const char *fmt, va_list args) {
     16     char *dialog_cmd;
     17     char buf[1024];
     18     struct stat st_buf;
     19     int ret;
     20
     21     (void) vsnprintf(buf, sizeof(buf), fmt, args);
     22     ret = stat("/usr/bin/kdialog", &st_buf);
     23 #define KDIALOG_CMD "kdialog --title 'File copy/move error' --sorry "
     24 #define ZENITY_CMD "zenity --title 'File copy/move error' --warning --text "
     25     if (asprintf(&dialog_cmd, "%s '%s: %s (error type: %s)'",
     26                 ret==0 ? KDIALOG_CMD : ZENITY_CMD,
     27                 program_invocation_short_name, buf, strerror(errno)) < 0) {
     28         fprintf(stderr, "Failed to allocate memory for error message :(\n");
     29         return;
     30     }
     31 #undef KDIALOG_CMD
     32 #undef ZENITY_CMD
     33     fprintf(stderr, "%s\n", buf);
     34     system(dialog_cmd);
     35 }
     36
     37 _Noreturn void gui_fatal(const char *fmt, ...) {
     38     va_list args;
     39     va_start(args, fmt);
     40     display_error(fmt, args);
     41     va_end(args);
     42     exit(1);
     43 }

The problem is that `sanitize_remote_filename()` removes only non-ASCII
characters (and double quotation marks) but leaves shell meta-characters
in place. Then, `system()` runs the constructed command, including the
attacker-controlled name via the shell.

Note that the VM variant of `qvm-copy-to-vm` is not affected, as its
version of the error reporting function does not use `system()`:

core-agent-linux/qubes-rpc/gui-fatal.c:

     16 static void produce_message(const char *type, const char *fmt, va_list args)
     17 {
    ...
     31     if (progress_type && !strcmp(progress_type, "gui"))
     32     {
     33         switch (fork())
     34         {
     35         case -1:
     36             exit(1); // what else
     37         case 0:
     38             if (geteuid() == 0) {
     39                 if (setuid(getuid()) != 0) {
     40                     perror("setuid failed, not calling zenity/kdialog");
     41                     exit(1);
     42                 }
     43             }
     44             fix_display();
     45             execlp("/usr/bin/zenity", "zenity", "--error", "--text", dialog_msg, NULL);
     46             execlp("/usr/bin/kdialog", "kdialog", "--sorry", dialog_msg, NULL);
     47             exit(1);
     48         default:;
     49         }
     50     }
     51     free(dialog_msg);
     52 }
     53
     54 void gui_fatal(const char *fmt, ...)
     55 {
     56     va_list args;
     57     va_start(args, fmt);
     58     produce_message("Fatal error", fmt, args);
     59     va_end(args);
     60     exit(1);
     61 }

Affected systems
-----------------

All Qubes OS releases are affected.

Patching
---------

The following package contains the security update that addresses the
vulnerability described in this bulletin:

  For Qubes 4.3, in dom0:
  - qubes-core-dom0-linux, version 4.3.22

This package will migrate from the security-testing repository to the
current (stable) repository after a short period of testing by the
community. [2] Once available, the package should be installed via the
Qubes Update tool or its command-line equivalents. [1]

Credits
--------

The vulnerability was discovered by Tim C.

References
-----------

[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html

--
The Qubes Security Team
https://www.qubes-os.org/security/

Source: qsb-118-2026.txt

Marek Marczykowski-Górecki’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmqSIHAACgkQ1lWk8hgw
4GoFoQ/+PavdhVipF8/C2uLvBrYcdUmPA8FraC89p4DLzAoh2EUOerSjzPSqyTwJ
S50jPNVHYiP6GaHsHoBNuRd8S9IN1GhyHfSRabjgcV/TfhXLXk8LrPVegq2IRMY6
FzkbBdpIUNn0gILeBJXyDhF50weRvrg7SZuwmjYvKUPHb4mA6wHEw01cuj54wVYW
iL/byB7ULnvlQWnsvKSYmSM3u+b9gOz2+jinNh2qRNg3pP3MUv1gQMFKH9CN5wE1
BiPn1bIn5v9V5RcG4nB6qgtqSE1JgB5a9KYJ3gNhGKA0N3Mnf+wS3LfWeU+0xmjW
PtWjMF+d1ZppT3yEeQj1jyyAemmwkB5zl+c/6FcEX8zvWGO2aYT/xe5yTbW7kVsM
js+FiF4opVMRx3t85WfbkN6Pu0F/bNP0OsE2IJ2G7T6v9gfzb4RfuLYdb01p9Mw2
RBZVP+tcQb7gtXdysapkLsIO+ST8AcewocokiPF3st+QeB6v/3pl+aab2NojXoUk
UzoJvRRd3e/KtAV1k1EAtajG5O8HFerW9LaULOGs6nPbVDBRLhJp0nlec5ZuRbpX
jaJGgXzD/QntiNiWH1iaB7NxeZJPzKGg8O7MPUvQV4Cn02uoE5J5EY8XZrGhNPVl
D4HHrQb+dMrwImEAGovHMdqVPJIiTGRFm5umwpKK8NRVWGjpsu8=
=fHjz
-----END PGP SIGNATURE-----

Source: qsb-118-2026.txt.sig.marmarek

Simon Gaiser (aka HW42)’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqSRk0ACgkQSsGN4REu
FJC8wQ//UOa2EdMZpIDLaYropqMHyt7cVlm3Ad4zpgqmteWOUSS2z6Y3DLA2b0Ng
xVDsmgJcoxqMt0tbzU9awSB/v41CKPQlXnevEFucwZWgeoQIhnZwr7c6zo2unngv
wc2eMMsIL/7QX2DPotoieshryTUB6kbb1hKwiXojWOJKTwVvQPRZmU6hWLAXtg7G
F4Ar/XMm2DR+KstIHFpvP+IWdS41+SWjIgjJJraUl5BE7mDF51M8vR4IvVM9Td8w
bb1ENAFO2W/ZnYnqGJpMmzWVhDzxjkikH9TT3CZmdulXa7ggK2V2EgBDJ681XtW+
jOC9f5OJjoVHc5LtPsAMZxL3sGbfOBfogK5Fwpi6lmzjcG3oCB6MMvEkveZRaSiO
H8vPl4H1dEIUKSA1LGZWEgY8RjuX0N4pnNOLzbn86tMpqYLtNBqGZ2/r8WkJSfXS
fYWyVAtF9kcy8scb4lYlsdfD7gZ8wH7dl/iUKikiS3NyFdAlYvb0OZd6c7BZwD2C
+YLHlo03he9WE1GbLoPPzqTN8VnunJ9eyyCs56SsHL5CYLfLnT95kMssAd+uJypo
7QZj3+xz7i2kaqK4osEL+5WUR47DyJEgKP8bMPeCV5ZZFC85eVKAn4BzYULx6tff
wVin+t9uZ2kwur7IyG+8Bb1PUgr+vATsVW1QcrfcRT6ujY4VDDs=
=1/K/
-----END PGP SIGNATURE-----

Source: qsb-118-2026.txt.sig.simon

What is the purpose of this announcement?

The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.

What is a Qubes security bulletin (QSB)?

A Qubes security bulletin (QSB) is a security announcement issued by the Qubes security team. A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.

Why should I care about QSBs?

QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally. However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.

What are the PGP signatures that accompany QSBs?

A PGP signature is a cryptographic digital signature made in accordance with the OpenPGP standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.

Why should I care whether a QSB is authentic?

A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.

How do I verify the PGP signatures on a QSB?

The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software.)

  1. Obtain the Qubes Master Signing Key (QMSK), e.g.:

    $ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
    gpg: directory '/home/user/.gnupg' created
    gpg: keybox '/home/user/.gnupg/pubring.kbx' created
    gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
    gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
    gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported
    gpg: Total number processed: 1
    gpg:               imported: 1
    

    (For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key.)

  2. View the fingerprint of the PGP key you just imported. (Note: gpg> indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)

    $ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
    gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.
       
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    gpg> fpr
    pub   rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
     Primary key fingerprint: 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
    
  3. Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key.

    Tip: After you have authenticated the QMSK out-of-band to your satisfaction, record the QMSK fingerprint in a safe place (or several) so that you don’t have to repeat this step in the future.

  4. Once you are satisfied that you have the genuine QMSK, set its trust level to 5 (“ultimate”), then quit GnuPG with q.

    gpg> trust
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    Please decide how far you trust this user to correctly verify other users' keys
    (by looking at passports, checking fingerprints from different sources, etc.)
       
      1 = I don't know or won't say
      2 = I do NOT trust
      3 = I trust marginally
      4 = I trust fully
      5 = I trust ultimately
      m = back to the main menu
       
    Your decision? 5
    Do you really want to set this key to ultimate trust? (y/N) y
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: ultimate      validity: unknown
    [ unknown] (1). Qubes Master Signing Key
    Please note that the shown key validity is not necessarily correct
    unless you restart the program.
       
    gpg> q
    
  5. Use Git to clone the qubes-secpack repo.

    $ git clone https://github.com/QubesOS/qubes-secpack.git
    Cloning into 'qubes-secpack'...
    remote: Enumerating objects: 4065, done.
    remote: Counting objects: 100% (1474/1474), done.
    remote: Compressing objects: 100% (742/742), done.
    remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591
    Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done.
    Resolving deltas: 100% (1910/1910), done.
    
  6. Import the included PGP keys. (See our PGP key policies for important information about these keys.)

    $ gpg --import qubes-secpack/keys/*/*
    gpg: key 063938BA42CFA724: public key "Marek Marczykowski-Górecki (Qubes OS signing key)" imported
    gpg: qubes-secpack/keys/core-devs/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 8C05216CE09C093C: 1 signature not checked due to a missing key
    gpg: key 8C05216CE09C093C: public key "HW42 (Qubes Signing Key)" imported
    gpg: key DA0434BC706E1FCF: public key "Simon Gaiser (Qubes OS signing key)" imported
    gpg: key 8CE137352A019A17: 2 signatures not checked due to missing keys
    gpg: key 8CE137352A019A17: public key "Andrew David Wong (Qubes Documentation Signing Key)" imported
    gpg: key AAA743B42FBC07A9: public key "Brennan Novak (Qubes Website & Documentation Signing)" imported
    gpg: key B6A0BB95CA74A5C3: public key "Joanna Rutkowska (Qubes Documentation Signing Key)" imported
    gpg: key F32894BE9684938A: public key "Marek Marczykowski-Górecki (Qubes Documentation Signing Key)" imported
    gpg: key 6E7A27B909DAFB92: public key "Hakisho Nukama (Qubes Documentation Signing Key)" imported
    gpg: key 485C7504F27D0A72: 1 signature not checked due to a missing key
    gpg: key 485C7504F27D0A72: public key "Sven Semmler (Qubes Documentation Signing Key)" imported
    gpg: key BB52274595B71262: public key "unman (Qubes Documentation Signing Key)" imported
    gpg: key DC2F3678D272F2A8: 1 signature not checked due to a missing key
    gpg: key DC2F3678D272F2A8: public key "Wojtek Porczyk (Qubes OS documentation signing key)" imported
    gpg: key FD64F4F9E9720C4D: 1 signature not checked due to a missing key
    gpg: key FD64F4F9E9720C4D: public key "Zrubi (Qubes Documentation Signing Key)" imported
    gpg: key DDFA1A3E36879494: "Qubes Master Signing Key" not changed
    gpg: key 1848792F9E2795E9: public key "Qubes OS Release 4 Signing Key" imported
    gpg: qubes-secpack/keys/release-keys/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key D655A4F21830E06A: public key "Marek Marczykowski-Górecki (Qubes security pack)" imported
    gpg: key ACC2602F3F48CB21: public key "Qubes OS Security Team" imported
    gpg: qubes-secpack/keys/security-team/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 4AC18DE1112E1490: public key "Simon Gaiser (Qubes Security Pack signing key)" imported
    gpg: Total number processed: 17
    gpg:               imported: 16
    gpg:              unchanged: 1
    gpg: marginals needed: 3  completes needed: 1  trust model: pgp
    gpg: depth: 0  valid:   1  signed:   6  trust: 0-, 0q, 0n, 0m, 0f, 1u
    gpg: depth: 1  valid:   6  signed:   0  trust: 6-, 0q, 0n, 0m, 0f, 0u
    
  7. Verify signed Git tags.

    $ cd qubes-secpack/
    $ git tag -v `git describe`
    object 266e14a6fae57c9a91362c9ac784d3a891f4d351
    type commit
    tag marmarek_sec_266e14a6
    tagger Marek Marczykowski-Górecki 1677757924 +0100
       
    Tag for commit 266e14a6fae57c9a91362c9ac784d3a891f4d351
    gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    

    The exact output will differ, but the final line should always start with gpg: Good signature from... followed by an appropriate key. The [full] indicates full trust, which this key inherits in virtue of being validly signed by the QMSK.

  8. Verify PGP signatures, e.g.:

    $ cd QSBs/
    $ gpg --verify qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify qsb-087-2022.txt.sig.simon qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    $ cd ../canaries/
    $ gpg --verify canary-034-2023.txt.sig.marmarek canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify canary-034-2023.txt.sig.simon canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    

    Again, the exact output will differ, but the final line of output from each gpg --verify command should always start with gpg: Good signature from... followed by an appropriate key.

For this announcement (QSB-118), the commands are:

$ gpg --verify qsb-118-2026.txt.sig.marmarek qsb-118-2026.txt
$ gpg --verify qsb-118-2026.txt.sig.simon qsb-118-2026.txt

You can also verify the signatures directly from this announcement in addition to or instead of verifying the files from the qubes-secpack. Simply copy and paste the QSB-118 text into a plain text file and do the same for both signature files. Then, perform the same authentication steps as listed above, substituting the filenames above with the names of the files you just created.

29 August, 2026 12:00AM

August 28, 2026

hackergotchi for Deepin

Deepin

hackergotchi for Qubes

Qubes

QSB-117: Intel CPU firmware vulnerabilities

We have published Qubes Security Bulletin (QSB) 117: Intel CPU firmware vulnerabilities. The text of this QSB and its accompanying cryptographic signatures are reproduced below, followed by a general explanation of this announcement and authentication instructions.

Qubes Security Bulletin 117


             ---===[ Qubes Security Bulletin 117 ]===---

                              2026-08-28

                  Intel CPU firmware vulnerabilities

User action
------------

Continue to update normally [1] in order to receive the security updates
described in the "Patching" section below. No other user action is
required in response to this QSB.

Summary
--------

On 2026-08-11, Intel published "microcode-20260811 Release," [3] which
is associated with several Intel security advisories. Among these
security advisories, we suspect the following may apply to Qubes OS:

- "2026.3 IPU, Intel Processor Load Value Injection Zero Data Advisory"
  (INTEL-SA-01423) [4]
- "Intel Processor Firmware Advisory - 01428" (INTEL-SA-01428) [5]
- "Intel Processor Firmware Advisory - 01435" (INTEL-SA-01435) [6]
- "2026.3 IPU, Intel Processor Firmware Advisory" (INTEL-SA-01441) [7]
- "2026.3 IPU, Intel Xeon Processor Firmware Advisory"
  (INTEL-SA-01442) [8]

Unfortunately, these advisories do not provide sufficient information
for us to make a definitive assessment about the extent to which these
vulnerabilities affect the security of Qubes OS. Based on the limited
information available, we cannot exclude possibility of a cross-qube
attack.

Impact
-------

On affected systems, an attacker who has managed to compromise one qube
can attempt to exploit these vulnerabilities in order to infer data
belonging to other qubes or escalate their privileges.

Affected systems
-----------------

Only systems with one of the following Intel CPUs are affected by at
least some of the advisories:

 - 10th Generation Intel Core
 - 11th Generation Intel Core
 - Intel Core Ultra, Series 1 to 3
 - various Xeon variants

For a more detailed list of affected products see Intel's advisories.

Note: As of this writing, Intel has withdrawn the relevant update for
Meteor Lake (Intel Core Ultra Series 2) CPUs "due to functional issues"
[9]. Due to limited information, the impact of the vulnerabilities
discussed in this bulletin on systems without the relevant update is
unclear.

Patching
---------

The following package contains the security update that addresses the
vulnerability described in this bulletin:

  For Qubes 4.3, in dom0:
  - microcode_ctl version 2.1.20260812

Note: This package has already finished migrating from the
security-testing repository to the current (stable) repository after
being tested by the community. [2] (This QSB is being published later
than usual.) The package, which is already available to all users,
should be installed via the Qubes Update tool or its command-line
equivalents. [1]

Dom0 must be restarted afterward in order for the update to take effect.

If you use Anti Evil Maid, you will need to reseal your secret
passphrase to new PCR values, as PCR18+19 will change due to the new
microcode updates.

Credits
--------

See Intel's advisories.

References
-----------

[1] https://doc.qubes-os.org/en/latest/user/how-to-guides/how-to-update.html
[2] https://doc.qubes-os.org/en/latest/user/downloading-installing-upgrading/testing.html
[3] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/blob/main/releasenote.md#microcode-20260811
[4] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html
[5] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html
[6] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html
[7] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html
[8] https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html
[9] https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/blob/main/releasenote.md#microcode-20260812

--
The Qubes Security Team
https://www.qubes-os.org/security/

Source: qsb-117-2026.txt

Marek Marczykowski-Górecki’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEELRdx/k12ftx2sIn61lWk8hgw4GoFAmqSEC8ACgkQ1lWk8hgw
4Go3Xw/+LdLu3Dx+S1iH8YDpk2Ef2WJwXNl+Msmt+cTntk/wdEvsAeRWc0/t85fZ
ySfiYIAq+PvED2G7rSbVmgqWp3sPNCaSS89Penr3praoLfxRxLc23HbLQrabnKgK
2TNRiFlk+OSqvjqvItn/y+kyxB4TZAnNtDHu9Eins/B0gVAz+P//aSFVOb42UTo9
7gLNWpW1CxflQqKfNnEqxah5m2iH72pMzir6F8fXC9JFMp1PWcvn1cRfKHrAs3lw
qw7kUz2mByT1qHIMs/iQ6PA4bOhlo0km1M+z+sFhyXNvsdz2JlAnlViX7ZOCCxrb
YoJd/VPnaH9xtUUh++iDmtIyylxTlx7vmOb/WEefucD+EH7zM5x3BdKb7M0vpKgy
vJU3a5+pY90opla7hT8GWVuIpzhBSLQlhR4RNLWSdu+pQeWqUPG2rapww0B3/Hia
t98H76iMMCDvy74Bj+hChrO95wgY35JJveSXF51WiJmOjofxFeyxgTBrlcjlmpkb
kUybNm8fm9LZAOG6zFJIYJN0q0+tKu0qc4Z1cU+EIIL6G5msMUIMKXV3Tg/KpUW/
Yo3dGYUUTVCsmKtaXw9ASRvnaHS3ADC6wRZK5XSkqsXNVoQI0sWkik5vn0VvS+LW
VdOSWdoQGJRAAEpRmM/grsxgqq3Sn+Tck2g3IcgK+aRysClb6z8=
=Xehb
-----END PGP SIGNATURE-----

Source: qsb-117-2026.txt.sig.marmarek

Simon Gaiser (aka HW42)’s PGP signature

-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEE6hjn8EDEHdrv6aoPSsGN4REuFJAFAmqSEywACgkQSsGN4REu
FJDCww//aucPqi/Fujn0/aVD2zSwNw9+b+8KulNRODaP86MaNu9kUs6+TNIOvGOx
egeJim/vCIbdehCzd2x1+GKonmtlQzHTFE3VKCJXQ7u74/fa2cSIZwmjjwdjhbgs
78m4grmdsW4UtQGBEku6M4Nl4vYDjbw3orCwONf4rqOG8dsHK0REJnBnXTeq6aAo
Q/3NfuE5bBMQkl4FCnLuEKw1ZgC89gFLtYT5A2B2cQlvyEdNqe7tiMV7bczxQUEY
tiPnfcSSnRvT7+wrZ3n4XG1e2IfLX7icMsMqknLD8kla1qf5NpvV2YoRwsWBc6C2
jIGpOjuw/I9XVUHOuWe2+PCSVZswC2AZYJ7Y/sD/8G7eM4YLB7c65EwUCz/YhdU+
4l6MuC94A9UMI8NLx0DiRqTeDkadgJby1IoJOkBKurM6zoi0fyF7FQwvmNosMAIA
vEwESYdUUr4j5gLzmRb7kMyr93XCeMk9Iqzuwe3f5081NCT5Th/tWLjsBa0Dnw4b
JeFjvtPO6W2dBR2MezQ+v/VlcIxOgwPOeS/EhnNx6ykPmEbZMVjR7JHe5CO6npq7
/M6vFvrXoVahDn4QQTTcYpvu6NUcAagrGJQGwLaaOpc7Z03jZOAQMMx1SPjPmsP3
/KDsXFWblRYq7kNAqhmgAqJt/XQcDSp7MnPdZ1jQbvnurRHmJX4=
=XApt
-----END PGP SIGNATURE-----

Source: qsb-117-2026.txt.sig.simon

What is the purpose of this announcement?

The purpose of this announcement is to inform the Qubes community that a new Qubes security bulletin (QSB) has been published.

What is a Qubes security bulletin (QSB)?

A Qubes security bulletin (QSB) is a security announcement issued by the Qubes security team. A QSB typically provides a summary and impact analysis of one or more recently-discovered software vulnerabilities, including details about patching to address them.

Why should I care about QSBs?

QSBs tell you what actions you must take in order to protect yourself from recently-discovered security vulnerabilities. In most cases, security vulnerabilities are addressed by updating normally. However, in some cases, special user action is required. In all cases, the required actions are detailed in QSBs.

What are the PGP signatures that accompany QSBs?

A PGP signature is a cryptographic digital signature made in accordance with the OpenPGP standard. PGP signatures can be cryptographically verified with programs like GNU Privacy Guard (GPG). The Qubes security team cryptographically signs all QSBs so that Qubes users have a reliable way to check whether QSBs are genuine. The only way to be certain that a QSB is authentic is by verifying its PGP signatures.

Why should I care whether a QSB is authentic?

A forged QSB could deceive you into taking actions that adversely affect the security of your Qubes OS system, such as installing malware or making configuration changes that render your system vulnerable to attack. Falsified QSBs could sow fear, uncertainty, and doubt about the security of Qubes OS or the status of the Qubes OS Project.

How do I verify the PGP signatures on a QSB?

The following command-line instructions assume a Linux system with git and gpg installed. (For Windows and Mac options, see OpenPGP software.)

  1. Obtain the Qubes Master Signing Key (QMSK), e.g.:

    $ gpg --fetch-keys https://keys.qubes-os.org/keys/qubes-master-signing-key.asc
    gpg: directory '/home/user/.gnupg' created
    gpg: keybox '/home/user/.gnupg/pubring.kbx' created
    gpg: requesting key from 'https://keys.qubes-os.org/keys/qubes-master-signing-key.asc'
    gpg: /home/user/.gnupg/trustdb.gpg: trustdb created
    gpg: key DDFA1A3E36879494: public key "Qubes Master Signing Key" imported
    gpg: Total number processed: 1
    gpg:               imported: 1
    

    (For more ways to obtain the QMSK, see How to import and authenticate the Qubes Master Signing Key.)

  2. View the fingerprint of the PGP key you just imported. (Note: gpg> indicates a prompt inside of the GnuPG program. Type what appears after it when prompted.)

    $ gpg --edit-key 0x427F11FD0FAA4B080123F01CDDFA1A3E36879494
    gpg (GnuPG) 2.2.27; Copyright (C) 2021 Free Software Foundation, Inc.
    This is free software: you are free to change and redistribute it.
    There is NO WARRANTY, to the extent permitted by law.
       
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    gpg> fpr
    pub   rsa4096/DDFA1A3E36879494 2010-04-01 Qubes Master Signing Key
     Primary key fingerprint: 427F 11FD 0FAA 4B08 0123  F01C DDFA 1A3E 3687 9494
    
  3. Important: At this point, you still don’t know whether the key you just imported is the genuine QMSK or a forgery. In order for this entire procedure to provide meaningful security benefits, you must authenticate the QMSK out-of-band. Do not skip this step! The standard method is to obtain the QMSK fingerprint from multiple independent sources in several different ways and check to see whether they match the key you just imported. For more information, see How to import and authenticate the Qubes Master Signing Key.

    Tip: After you have authenticated the QMSK out-of-band to your satisfaction, record the QMSK fingerprint in a safe place (or several) so that you don’t have to repeat this step in the future.

  4. Once you are satisfied that you have the genuine QMSK, set its trust level to 5 (“ultimate”), then quit GnuPG with q.

    gpg> trust
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: unknown       validity: unknown
    [ unknown] (1). Qubes Master Signing Key
       
    Please decide how far you trust this user to correctly verify other users' keys
    (by looking at passports, checking fingerprints from different sources, etc.)
       
      1 = I don't know or won't say
      2 = I do NOT trust
      3 = I trust marginally
      4 = I trust fully
      5 = I trust ultimately
      m = back to the main menu
       
    Your decision? 5
    Do you really want to set this key to ultimate trust? (y/N) y
       
    pub  rsa4096/DDFA1A3E36879494
         created: 2010-04-01  expires: never       usage: SC
         trust: ultimate      validity: unknown
    [ unknown] (1). Qubes Master Signing Key
    Please note that the shown key validity is not necessarily correct
    unless you restart the program.
       
    gpg> q
    
  5. Use Git to clone the qubes-secpack repo.

    $ git clone https://github.com/QubesOS/qubes-secpack.git
    Cloning into 'qubes-secpack'...
    remote: Enumerating objects: 4065, done.
    remote: Counting objects: 100% (1474/1474), done.
    remote: Compressing objects: 100% (742/742), done.
    remote: Total 4065 (delta 743), reused 1413 (delta 731), pack-reused 2591
    Receiving objects: 100% (4065/4065), 1.64 MiB | 2.53 MiB/s, done.
    Resolving deltas: 100% (1910/1910), done.
    
  6. Import the included PGP keys. (See our PGP key policies for important information about these keys.)

    $ gpg --import qubes-secpack/keys/*/*
    gpg: key 063938BA42CFA724: public key "Marek Marczykowski-Górecki (Qubes OS signing key)" imported
    gpg: qubes-secpack/keys/core-devs/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 8C05216CE09C093C: 1 signature not checked due to a missing key
    gpg: key 8C05216CE09C093C: public key "HW42 (Qubes Signing Key)" imported
    gpg: key DA0434BC706E1FCF: public key "Simon Gaiser (Qubes OS signing key)" imported
    gpg: key 8CE137352A019A17: 2 signatures not checked due to missing keys
    gpg: key 8CE137352A019A17: public key "Andrew David Wong (Qubes Documentation Signing Key)" imported
    gpg: key AAA743B42FBC07A9: public key "Brennan Novak (Qubes Website & Documentation Signing)" imported
    gpg: key B6A0BB95CA74A5C3: public key "Joanna Rutkowska (Qubes Documentation Signing Key)" imported
    gpg: key F32894BE9684938A: public key "Marek Marczykowski-Górecki (Qubes Documentation Signing Key)" imported
    gpg: key 6E7A27B909DAFB92: public key "Hakisho Nukama (Qubes Documentation Signing Key)" imported
    gpg: key 485C7504F27D0A72: 1 signature not checked due to a missing key
    gpg: key 485C7504F27D0A72: public key "Sven Semmler (Qubes Documentation Signing Key)" imported
    gpg: key BB52274595B71262: public key "unman (Qubes Documentation Signing Key)" imported
    gpg: key DC2F3678D272F2A8: 1 signature not checked due to a missing key
    gpg: key DC2F3678D272F2A8: public key "Wojtek Porczyk (Qubes OS documentation signing key)" imported
    gpg: key FD64F4F9E9720C4D: 1 signature not checked due to a missing key
    gpg: key FD64F4F9E9720C4D: public key "Zrubi (Qubes Documentation Signing Key)" imported
    gpg: key DDFA1A3E36879494: "Qubes Master Signing Key" not changed
    gpg: key 1848792F9E2795E9: public key "Qubes OS Release 4 Signing Key" imported
    gpg: qubes-secpack/keys/release-keys/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key D655A4F21830E06A: public key "Marek Marczykowski-Górecki (Qubes security pack)" imported
    gpg: key ACC2602F3F48CB21: public key "Qubes OS Security Team" imported
    gpg: qubes-secpack/keys/security-team/retired: read error: Is a directory
    gpg: no valid OpenPGP data found.
    gpg: key 4AC18DE1112E1490: public key "Simon Gaiser (Qubes Security Pack signing key)" imported
    gpg: Total number processed: 17
    gpg:               imported: 16
    gpg:              unchanged: 1
    gpg: marginals needed: 3  completes needed: 1  trust model: pgp
    gpg: depth: 0  valid:   1  signed:   6  trust: 0-, 0q, 0n, 0m, 0f, 1u
    gpg: depth: 1  valid:   6  signed:   0  trust: 6-, 0q, 0n, 0m, 0f, 0u
    
  7. Verify signed Git tags.

    $ cd qubes-secpack/
    $ git tag -v `git describe`
    object 266e14a6fae57c9a91362c9ac784d3a891f4d351
    type commit
    tag marmarek_sec_266e14a6
    tagger Marek Marczykowski-Górecki 1677757924 +0100
       
    Tag for commit 266e14a6fae57c9a91362c9ac784d3a891f4d351
    gpg: Signature made Thu 02 Mar 2023 03:52:04 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    

    The exact output will differ, but the final line should always start with gpg: Good signature from... followed by an appropriate key. The [full] indicates full trust, which this key inherits in virtue of being validly signed by the QMSK.

  8. Verify PGP signatures, e.g.:

    $ cd QSBs/
    $ gpg --verify qsb-087-2022.txt.sig.marmarek qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 04:05:51 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify qsb-087-2022.txt.sig.simon qsb-087-2022.txt
    gpg: Signature made Wed 23 Nov 2022 03:50:42 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    $ cd ../canaries/
    $ gpg --verify canary-034-2023.txt.sig.marmarek canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 03:51:48 AM PST
    gpg:                using RSA key 2D1771FE4D767EDC76B089FAD655A4F21830E06A
    gpg: Good signature from "Marek Marczykowski-Górecki (Qubes security pack)" [full]
    $ gpg --verify canary-034-2023.txt.sig.simon canary-034-2023.txt
    gpg: Signature made Thu 02 Mar 2023 01:47:52 AM PST
    gpg:                using RSA key EA18E7F040C41DDAEFE9AA0F4AC18DE1112E1490
    gpg: Good signature from "Simon Gaiser (Qubes Security Pack signing key)" [full]
    

    Again, the exact output will differ, but the final line of output from each gpg --verify command should always start with gpg: Good signature from... followed by an appropriate key.

For this announcement (QSB-117), the commands are:

$ gpg --verify qsb-117-2026.txt.sig.marmarek qsb-117-2026.txt
$ gpg --verify qsb-117-2026.txt.sig.simon qsb-117-2026.txt

You can also verify the signatures directly from this announcement in addition to or instead of verifying the files from the qubes-secpack. Simply copy and paste the QSB-117 text into a plain text file and do the same for both signature files. Then, perform the same authentication steps as listed above, substituting the filenames above with the names of the files you just created.

28 August, 2026 12:00AM

August 27, 2026

hackergotchi for Volumio

Volumio

Dedicated Streamer Versus Computer Audio

A laptop on the rack can be an extraordinarily capable music source. It can also be a glowing, fan-equipped general-purpose machine asking to be updated just as the first track begins. The dedicated streamer versus computer audio question is not about whether a computer can play high-resolution music. It certainly can. It is about how each approach behaves in a real hi-fi system, and which one lets you spend more time listening.

For some systems, computer audio is the sensible starting point. For others, a network streamer is the missing component that turns scattered music services, downloads, and local files into one coherent music experience. The right answer depends on your system, your habits, and how much you value a purpose-built source.

Dedicated Streamer Versus Computer Audio: The Real Difference

Both devices can retrieve a music file or stream, process it, and send a digital signal to a DAC. That shared function can make the comparison seem simple. In practice, the surrounding design matters as much as the file format.

A computer is designed to do nearly anything: work, video calls, web browsing, gaming, storage, and music playback. That flexibility is its strength. But it also means background processes, notifications, variable power demands, fans, displays, and multiple connected peripherals can become part of the listening environment.

A dedicated streamer has a narrower purpose. It is built to find, organize, and play music on a network, then deliver it to a DAC or an integrated amplifier with digital inputs. Its hardware, operating system, app control, network behavior, and physical connections are chosen for that role. The result is not automatically better sound in every setup, but it is usually a more focused path from music library to hi-fi system.

Sound Quality Starts With the Whole System

It is tempting to declare one source categorically superior. Audio systems are less absolute than that. A well-configured computer connected to a good external DAC can sound excellent, particularly when it is used carefully and kept away from electrical noise. A dedicated streamer can make an equally meaningful difference, especially in a revealing system where source noise, connection quality, and stable playback matter.

The key consideration is not that digital audio is somehow immune to implementation. The digital data may arrive intact, but the environment around the DAC still matters. Electrical noise can travel through USB, ground connections, and power supplies. Network activity, processor load, and the quality of the output stage can also affect how composed and natural a system feels.

A dedicated streamer separates music playback from the busy electrical environment of a desktop or laptop. Many models offer purpose-designed digital outputs, low-noise internal layouts, and power arrangements selected for audio use. If your DAC accepts a network endpoint directly, the streamer can also reduce unnecessary connections altogether.

That does not make a computer a bad source. It means the computer setup deserves attention. A quiet machine, a quality DAC, thoughtful USB implementation, and sensible power management can produce satisfying results. The difference is that a streamer arrives ready to be a music component, while a computer often becomes one through configuration and add-ons.

The DAC Still Has a Major Role

If you use an external DAC, it will heavily shape the final result. The streamer or computer is feeding it, not replacing it. This is why a source comparison should account for output options: USB, coaxial, optical, AES/EBU, or network playback where supported.

A listener with a DAC that performs best over USB may prioritize a streamer with a carefully implemented USB output. Someone using a DAC with an excellent coaxial input may choose differently. Compatibility is not a footnote. It is the practical foundation of a successful system.

Control Is Where a Streamer Often Wins

The everyday appeal of a dedicated streamer is less about a specification sheet and more about what happens at 9 p.m. when you want to hear an album. You pick up a phone or tablet, open one music interface, choose from your local collection or preferred service, and press play. The computer can remain closed, or remain in another room entirely.

Computer audio can be just as convenient when the listening position is near a desk and the computer is already part of the routine. It is especially appealing to listeners who enjoy detailed library management, desktop software, DSP experimentation, or maintaining a large file archive. For a maker, a PC-based player can also be a rewarding platform for building a system around personal priorities.

The friction appears when the computer serves too many masters. An operating-system alert, a streaming app update, a sleeping network connection, or an unwanted change in system volume can interrupt the experience. None of these problems is insurmountable. They simply ask the listener to think like an IT administrator when they would rather think about the next record.

A dedicated music ecosystem brings local libraries and streaming services together in a single place. That matters if your listening crosses TIDAL, Qobuz, Spotify, internet radio, and files stored on a network drive. Rather than treating each source as a separate destination, the interface can present them as parts of one collection.

Placement, Connections, and Daily Living

A computer is often physically awkward in a hi-fi rack. It needs a screen, a keyboard or mouse for some tasks, and a place for charging or docking. A fanless mini PC can reduce that footprint, but the installation still requires decisions about the operating system, playback software, remote access, and updates.

A streamer is designed to sit with the rest of the system. It usually offers a front panel appropriate to an audio component, stable Ethernet and Wi-Fi connectivity, and outputs selected for DACs and amplifiers. It can be controlled without putting a bright computer screen in the room. For a shared living space, that distinction can be more valuable than any single technical feature.

Wired Ethernet is generally the best choice when it is practical, for both computers and streamers. It offers a stable connection and keeps wireless traffic from becoming another variable. Still, a well-positioned Wi-Fi network can support excellent playback, and it may be the sensible option where a cable is not possible.

The same principle applies to power. A computer may share outlets with displays, chargers, and other household electronics. A music-focused component makes it easier to create a cleaner, more intentional installation. Listeners pursuing the last degree of refinement can also explore dedicated power solutions, but the fundamentals of good system matching come first.

When Computer Audio Is the Better Choice

Computer audio remains a strong option when flexibility is the priority. It can be the ideal hub for room correction, advanced DSP, multichannel projects, recording work, or formats and workflows that require desktop applications. It is also a cost-effective way to enter high-quality playback if you already own a capable computer and a DAC.

It suits the listener who enjoys the process. If configuring software, testing playback modes, tagging files, and optimizing a library feels like part of the hobby, a computer offers a wide field to explore. A small, purpose-configured PC can narrow the gap between a conventional computer and a dedicated component while preserving that flexibility.

The trade-off is maintenance. The more customized the system, the more responsibility you take for keeping it current and dependable. That is perfectly worthwhile for many enthusiasts. It is less appealing for those who want the music system to behave like a well-made appliance.

When a Dedicated Streamer Makes Sense

Choose a dedicated streamer when you want your digital front end to feel like the rest of your hi-fi: deliberate, dependable, and centered on playback. It is especially compelling for a living-room system, a serious two-channel setup, or any installation where the computer is not meant to be part of the furniture.

It also makes sense when source switching has become annoying. If your music lives across services, network storage, and digital radio, a unified interface removes a surprising amount of daily friction. All your music is in one place, ready to play through the system you chose for it.

Volumio approaches this idea from both directions: accessible software for listeners and builders, alongside dedicated components hand-assembled in Florence for systems where fit, finish, and musical performance matter. That bridge is useful because there is no single correct level of investment. A Raspberry Pi project, a PC-based player, and a refined streamer can all serve the same goal: a closer relationship with music.

Choose the Source That Fits Your Listening

Start with an honest look at how you listen. If your computer is already in the room, your library tools work well, and you enjoy tuning the setup, improve that path before replacing it. A better DAC connection, a quieter machine, or a more focused playback configuration may be all you need.

If you find yourself postponing listening because the computer is inconvenient, or switching among apps because your music feels fragmented, a dedicated streamer solves a more human problem than a technical one. It gives the system a center of gravity.

The best digital source is the one that disappears once the music starts. Whether that is a carefully prepared computer or a dedicated streamer, choose the approach that makes you reach for another album, not another setting.

The post Dedicated Streamer Versus Computer Audio appeared first on Volumio.

27 August, 2026 05:18AM

August 26, 2026

hackergotchi for ARMBIAN

ARMBIAN

Armbian Newsletter August 2026

Armbian Newsletter August 2026

Welcome to the latest Armbian Newsletter: your source for the latest developments, community highlights, and behind-the-scenes updates from the world of open-source ARM and RISC-V computing.

Armbian 26.8 brings a major shift to the ecosystem, focusing heavily on rebuilding and refining the core tools users interact with every day. Anchored by the Linux 7.1 kernel across the tree, this milestone release introduces three major overhauls: a redesigned armbian-install utility featuring expanded boot topologies and standalone bootloader flashing, the all-new Imager 2.0, and standardized UEFI ISO images for seamless deployment across desktop and minimal environments. Paired with expanded platform support stretching from new Rockchip and Qualcomm SBCs to gaming handhelds and 3D printer mainboards Armbian 26.8 turns raw single-board computer hardware into an accessible, enterprise-grade foundation for developers, self-hosters, and hardware enthusiasts alike.

SPONSORED
Armbian Newsletter August 2026

Join us in making open source better! Every donation helps Armbian improve security, performance, and reliability — so everyone can enjoy a solid foundation for their devices.


Armbian release 26.8
Rebuilding the tools you actually touch Kernel 7.1 across the tree, a rewritten installer, Imager 2.0, and UEFI ISO images Three rewrites in one cycle Most releases are a long list of small improvements. This one had three larger pieces landing at roughly the same time, and all
SBC storage
Modernizing SBC Storage: From Qualcomm EDL Flashing to SPI-to-NVMe Boots For years, single-board computer (SBC) storage followed a simple, predictable pattern: flash an image onto a microSD card or eMMC module, plug it in, and turn on the board. However, as modern embedded hardware approaches laptop-grade
One board, two architectures: Armbian on the Milk-V Duo S
The Milk-V Duo S is a very cheap and small board. It runs a Sophgo SG2000 with an Arm Cortex-A53 and a RISC-V C906, 512 MB of RAM, and a physical slide switch decides which one boots. Armbian now supports both architectures. PR #10326 landed the port
Armbian image writer
Armbian has this awesome Image Writer that I have to show off — it’s just too good not to. And if you haven’t checked out the Armbian website recently, do yo…

26 August, 2026 03:35PM by Michael Robinson

One board, two architectures: Armbian on the Milk-V Duo S

One board, two architectures: Armbian on the Milk-V Duo S

The Milk-V Duo S is a very cheap and small board. It runs a Sophgo SG2000 with
an Arm Cortex-A53 and a RISC-V C906, 512 MB of RAM, and a physical slide switch decides which
one boots. Armbian now supports both architectures. PR #10326 landed the port (175 files) as two thin board targets – milkv-duos-arm and milkv-duos-riscv – over a single shared family include, so the bootloader pins can&apost drift apart. PR #10510 moved the edge branch to kernel 7.1.

Standing on the shoulders of others

There are at least 2 projects the port owes a lot to: queenkjuul/milkv-duo-ubuntu (Ubuntu on a mainline kernel 7.0, RISC-V) and Fishwaldo/sophgo-sg200x-debian (Debian sid, vendor kernel 5.10). Armbian takes the mainline route, adds arm64, and builds the entire boot chain from source: no prebuilt fip.bin.

What the patches add

Kernel (57 patches per branch, one series for both architectures – the arm64
device tree includes the RISC-V ones): thermal sensor, watchdog, PWM, eFuse, DMA, MDIO mux, I2S, mailbox, the C906L coprocessor, correct eMMC and
microSD pin muxing, USB gadget mode, ramoops, and overlays for the 26-pin header (I²C, SPI, UART, PWM) and USB device mode.

U-Boot (vendor 2021.10): distroboot: the standard armbianEnv.txt + boot.scr mechanism works and overlays are chosen at boot rather than at build (like in other implementations), plus a fix for the SD slot being powered down when empty.

1050 MHz as a default RISC-V speed. Provided by a build option
SOPHGO_CPU_OVERDRIVE.

Both bootloaders ship in every image, so one image boots from microSD or eMMC – but flashing to the eMMC still requires special treatment using sophgo-emmc-install.

./compile.sh build BOARD=milkv-duos-arm BRANCH=edge

Usage example

The board runs under 1 W, so it can make a nice always-on serial console.
milkv-duos-uart turns a Duo S into a recorder for Rockchip boards (or any others!): enable the UART2 overlay, connect three pins, and it keeps a 32 MiB RAM ring buffer you can follow, dump as history, or attachand use like a normal console. This way a guest&aposs boot log can survive even it it dies.

What are your ideas for this board?

26 August, 2026 03:31PM by Łukasz Sobala

hackergotchi for Univention Corporate Server

Univention Corporate Server

AI Governance Is Key to Digital Sovereignty: How Today’s Decisions Will Shape Tomorrow’s Digital Independence

Last week, I spoke at the Bremen Fast Forward AI Festival about why digital sovereignty is being decided anew today and what role open-source AI plays in this. Here, I have summarized my key points for future reference.

Digital Sovereignty Means the Ability to Control, Shape, and Switch

In 2020, the IT Planning Council described digital sovereignty as “the capabilities and opportunities of individuals and institutions to exercise their role(s) in the digital world independently, autonomously, and securely.” In practice, this boils down to three questions: Who is in control? Who can shape the outcome? And can we switch when conditions change?

For large parts of our economy and public administration, the answer to all three questions is unfortunately: not us. From office software to cloud operations, the systems that matter most are predominantly supplied by US companies. A study commissioned by the German federal government and conducted by PwC identified these dependencies as early as 2019 and recommended building alternatives. Too little has happened since then.

Meanwhile, we can increasingly see these dependencies being used to exert political or economic pressure: the blocked email accounts of judges at the International Criminal Court, VMware price increases of up to 1,500 percent, Ukraine’s temporary loss of access to important mapping data, and much more. These are unmistakable signs of our vulnerability to coercion.

This is happening at a time of steadily increasing geopolitical tension. Russia’s war against Ukraine continues. The United States, too, is seeking to pursue its objectives by every means, including military force, while the American IT industry remains a close ally of its government. Russia, the United States, and China share one important characteristic: none of them has an interest in a strong Europe capable of determining its own course.

Open Source Is the Key

Open source provides a path to digital sovereignty. Access to the source code creates transparency and opportunities for control, makes it possible to adapt systems to specific requirements, facilitates replacement, enables reuse and further development, strengthens resilience, and improves scalability.

Ironically, hyperscalers understand this as well and use open source across a wide range of areas. The political recognition is there, too: the coalition agreement commits to digital sovereignty and open source, the EU Tech Sovereignty Package marks an important milestone, and countries such as France, Italy, and the Netherlands are already taking decisive steps toward open software.

Whether open source becomes a binding requirement in procurement will be crucial to the success of this strategy.

AI Raises the Stakes

Moving from on-premises servers to the cloud significantly increased the critical importance of digital sovereignty, because software became subject to a much greater degree of external control. AI adds another layer of dependency.

Virtually all processes in business, public administration, software development, and communication are likely to be shaped by AI in the future. Anyone who relies exclusively on so-called frontier models from a handful of providers risks losing control over their own digital processes and surrendering the data they generate themselves.

Anthropic’s temporary loss of access to its models showed how quickly this can have tangible consequences. Whoever controls the AI platforms will increasingly influence decisions, knowledge work, and innovation.

Bias is another important concern. Models form assessments based on their training data and can therefore influence public opinion. A federal lawsuit against Workday was recently allowed to proceed in the United States. The provider is accused of using AI functions that systematically disadvantage applicants on the basis of their age, background, or disability.

What matters most is not simply that bias occurs, but that closed models make it impossible to determine or correct where it comes from.

What Open-Source AI Makes Possible

Open-source AI means that models can be used, understood, reviewed, adapted, and operated independently—not merely consumed. Yet “open” does not always mean the same thing. There is a significant difference between software that is open only for operating a model, model weights that are publicly available, and training data that is accessible as well.

Several advantages stand out. Organizations become less dependent on individual providers because they can operate and further develop models themselves while keeping their data in-house. Greater transparency makes it possible to identify security issues and bias independently by analyzing the training data. Open models also support broader competition by providing a shared foundation on which many companies can build.

Performance is another argument in favor of this approach. In terms of general capabilities, open models now trail the best closed models by only a few months in many areas. At the same time, they have reached a level that is sufficient for many productive applications.

We use this approach at Univention as well. All our employees have access to open-source AI, and we are gradually connecting more of our systems to it. This allows us to work with our internal data without handing it over to an external provider.

Implementation Is What Matters Now

Whether digital sovereignty matters is no longer the question. The issue is where to begin. A pragmatic starting point is any situation in which a decision is already pending – for example, when a new solution is being introduced or a contract is up for renewal.

These are the moments when an existing dependency is either extended for several more years or dismantled. It is also important to recognize that switching is rarely free: migration, integration, operations, and training all require money, time, and expertise.

Even so, the effort is worthwhile. Open source can change two important things: resources flow into building internal capabilities and creating value in Europe instead of into licenses whose prices are set by others. In addition, an open model cannot easily be blocked or shut down.

My appeal is therefore this: whenever AI is introduced – and in most cases, its introduction should be pursued decisively – organizations should also ensure that open models can be used, whether under their own control or in trusted data centers.

Der Beitrag AI Governance Is Key to Digital Sovereignty: How Today’s Decisions Will Shape Tomorrow’s Digital Independence erschien zuerst auf Univention.

26 August, 2026 01:49PM by Peter Ganten

hackergotchi for GreenboneOS

GreenboneOS

CVE-2026-64849: SSRF Flaw in MLflow Actively Exploited

CVE-2026-64849 (CVSS 9.3, EPSS ≥ 95th pctl) is a critical-severity unauthenticated full-read server-side request forgery (SSRF) flaw [CWE-918] in MLflow webhook delivery. The CVE affects all versions prior to 3.15.0. The root cause is flawed redirect handling and DNS rebinding. The flaw is exploited by bypassing the _validate_webhook_url protections in the default MLflow Tracking Server […]

26 August, 2026 10:37AM by Joseph Lee

hackergotchi for ARMBIAN

ARMBIAN

SBC storage

Modernizing SBC Storage: From Qualcomm EDL Flashing to SPI-to-NVMe Boots

SBC storage

For years, single-board computer (SBC) storage followed a simple, predictable pattern: flash an image onto a microSD card or eMMC module, plug it in, and turn on the board. However, as modern embedded hardware approaches laptop-grade performance, that legacy approach is starting to break down.

The latest quarter of Armbian development highlights a major shift toward modern storage pipelines. By combining Qualcomm Emergency Download (EDL) flashing in Armbian Imager 2.0 with a redesigned installation engine, Armbian is making high-performance hardware far easier to set up.

Direct Qualcomm flashing with Imager 2.0

As boards like the Radxa Dragon Q6A and Q8B bring Qualcomm Snapdragon chips to developers, standard image writers no longer work. These devices require low-level vendor tools to write to storage before an operating system can even start.

Armbian Imager 2.0 now handles EDL flashing directly over USB without third-party software, automatically tailoring the setup to the specific hardware:

Radxa Dragon (Q6A & Q8B): Flashes directly to high-speed UFS storage, setting up the board’s custom UEFI boot environment.(Note: Users will need to enter the UEFI menu and set the boot order manually after flashing to boot from UFS).

Arduino Qualcomm Boards: Flashes directly to onboard eMMC storage, setting up a U-Boot environment.

Because EDL writes straight to the main storage, it leaves external SPI flash completely untouched, providing a clean, single-step recovery or setup process.

Decoupling boot files for faster drives

On powerful boards like those using the Rockchip RK3588, running an entire system from an SD card or eMMC creates a storage bottleneck. The ideal setup separates where the board starts from where it runs: loading basic boot files from tiny onboard memory (SPI NOR flash), then handing the heavy lifting off to a fast NVMe SSD or SATA drive.

26 August, 2026 03:37AM by Michael Robinson

hackergotchi for Deepin

Deepin

August 25, 2026

hackergotchi for ARMBIAN

ARMBIAN

Armbian release 26.8

Rebuilding the tools you actually touch

Armbian release 26.8

Kernel 7.1 across the tree, a rewritten installer, Imager 2.0, and UEFI ISO images

Three rewrites in one cycle

Most releases are a long list of small improvements. This one had three larger pieces landing at roughly the same time, and all three touch parts of Armbian that people use directly rather than parts they only read about in changelogs.

The installer was rewritten. Armbian Imager reached 2.0. And our CI moved out of the repository it had outgrown into one built for the job. None of these were planned to coincide; they simply reached the point where postponing them again would have cost more than doing them.

The installer rewrite is the one I expect people to notice first. It now ships as an armbian-config module, which means it is unit-tested, the same way the rest of armbian-config is tested, rather than living as a script that everyone was slightly afraid to touch. It can target SPI and MTD, treats eMMC and NVMe as separate flows instead of pretending they are the same thing, can flash a bootloader on its own, and — this one is overdue — reports when a bootloader write fails instead of printing "Done." and leaving you to find out at the next boot.

As always, every image in this release was manually validated for basic functionality. The automation keeps improving, but a board that boots in CI and a board that boots on a desk are still two different things.

Igor
Project Manager

Changes overview

This release advances on three fronts: kernel and firmware baselines moved forward across the entire tree, the tooling around installing and writing images was rebuilt, and the build and CI infrastructure was restructured onto Debian Trixie with a weekly stable cadence.

Kernels and firmware

Mainline support moves to 7.1 stable, with 7.2 available on edge branches for rockchip64, meson64, mvebu64, sunxi and bcm2711. U-Boot went to v2026.07 across most of boards, including the Rockchip RK35xx family, Amlogic, i.MX6, and the mvebu.

A number of long-carried patches were finally dropped this cycle because upstream fixed them properly — the 8250 DMA reopen crash, the SysRq-via-BREAK handling, several sunxi and meson64 patches. Carrying fewer patches is not a headline feature, but it is what makes the next kernel bump cheaper than the last one.

Wireless driver cleanup

The rtl8852bs, rtl8189es, rtl8192eu and uwe5622 drivers now live in dedicated Armbian repositories, build against up to 7.2, and are several thousand compiler warnings quieter than they were in June. That work was not cosmetic: going through the warnings surfaced a use-after-free in the uwe5622 probe path, a NULL dereference on efuse allocation failure, a leaked path reference, and a handful of unbounded copies in ioctl handlers. Vendor Wi-Fi blobs have been the least-inspected code in the tree for years. They are meaningfully less so now.

Incoming hardware

New this cycle: Anbernic RG DS and RG Vita Pro, Radxa Cubie A7Z and Dragon Q6A/Q8B, Seeed reComputer RK3576 and RK3588 DevKits, TI BeagleBadge and TMDS64EVM, Orange Pi 4 Pro and Zero 3W, Sovol Zero and SV08, Walnut Pi Box and 1B, EmbedFire LubanCat 5IO, LuckFox Nova, SpacemiT K3 Pico-ITX, Milk-V DuoS, Avnet MaaXBoard 8ULP, NanoPi NEO3 Plus, KICKPI K3B, Graperain G3568 v2, EASY EAI Nano, Mellow Fly C5, CIX P1, Xiaomi Pad 6S Pro and Tanix TX6S. Fourteen existing boards were promoted to standard support, a few dropped to community support, and Banana Pi R2 came back from the dead on 6.18.

Imager and image formats

Armbian Imager 2.0 adds QDL and UFS flashing for Qualcomm targets, pulls the board registry from the Armbian API rather than shipping a copy that goes stale, and enumerates devices more carefully on both Windows and Linux.

UEFI images can now be built as bootable live ISOs through the new image-output-iso extension. This makes Armbian directly usable over IPMI virtual CD and in cloud environments where an ISO is the only accepted input. The download and redirector infrastructure was extended to carry those ISOs alongside the compressed raw images.

Build framework and CI

CI moved out of armbian/os into its own armbian/ci repository. Runners register through NetBox, each one carrying its own proxy and cache export configuration, and a watchdog automatically retries runs killed by stalled runners rather than leaving a red cross for someone to notice in the morning. Stable builds now run weekly.

The default build host and Docker base image are Debian Trixie, which forced a long tail of fixes to older U-Boot trees against GCC 14 and SWIG 4.3 — the kind of work that is invisible when it succeeds. riscv64 images are now generated natively, and kernel patch rewriting runs in parallel with stricter From-header hygiene.

Every board, every promotion and every one of the 787 merged pull requests is listed in the release notes.

Thank you

787 pull requests went into this release, from long-standing team members and from people who showed up once to fix a device tree on a board nobody else owns. Both matter. The wireless cleanup in particular was one contributor deciding that thousands of warnings were worth working through, one file at a time.

And to our partners and donors — hardware, infrastructure, engineering time, and money — thank you. The infrastructure work in this release is expensive in exactly the way that is hard to fundraise for, and it happened because you make it possible.

25 August, 2026 08:49PM by Michael Robinson

hackergotchi for ZEVENET

ZEVENET

NetScaler Vulnerability CVE-2026-8452: What It Means for ADC Security

Security vulnerabilities in Internet-facing infrastructure call for a clear operational response: determine whether your environment is exposed and, if it is, apply the vendor’s remediation.

The recent NetScaler vulnerability CVE-2026-8452 is no exception. NetScaler describes it as a memory overflow affecting ADC and Gateway appliances under specific Gateway or AAA configurations. Subsequent independent security research has gone further, analyzing a SAML-related memory corruption and demonstrating unauthenticated remote code execution.

Those descriptions are related, but they are not identical. Understanding the difference is important both for assessing the incident accurately and for considering its broader implications for ADC security.

For organizations running affected NetScaler systems, the immediate priority is the vendor’s security guidance and the relevant software updates. Beyond remediation, however, the incident raises a useful architectural question: which responsibilities should an Internet-facing ADC perform, and how should application delivery, application security and identity functions be separated?

What is the NetScaler CVE-2026-8452 vulnerability?

NetScaler’s official security bulletin was initially published on June 30, 2026. It describes CVE-2026-8452 as a memory overflow vulnerability that can lead to unpredictable or erroneous behavior and Denial of Service.

The stated precondition is that the appliance is configured as a Gateway — including SSL VPN, ICA Proxy, CVPN or RDP Proxy — or as an AAA virtual server. NetScaler assigns it a CVSS v4.0 base score of 8.8, classified as High.

The supported releases identified as affected are:

Product / branch Affected versions
NetScaler ADC and NetScaler Gateway 14.1 Before 14.1-72.61
NetScaler ADC and NetScaler Gateway 13.1 Before 13.1-63.18
NetScaler ADC FIPS 14.1 Before 14.1-72.61 FIPS
NetScaler ADC FIPS and NDcPP 13.1 Before 13.1-37.272

 

NetScaler recommends upgrading affected systems to the corresponding fixed releases as soon as possible. Its bulletin also provides configuration checks that administrators can use to determine whether an appliance meets the CVE-2026-8452 preconditions.

That is the vendor-confirmed description. The discussion around SAML and pre-authentication remote code execution comes from subsequent independent research.

What did security researchers find?

On August 14, 2026, watchTowr Labs published a technical analysis based on differences between vulnerable and patched NetScaler builds. While testing a vulnerable NetScaler 13.1 appliance configured to use SAML, the researchers identified a remotely reachable memory corruption in SAML processing and demonstrated a path to pre-authentication remote code execution.

There is one important nuance. watchTowr believes the issue it analyzed corresponds to CVE-2026-8452, but it cannot confirm that mapping with absolute certainty because several vulnerabilities were fixed in the same NetScaler update. The researchers themselves reflect this uncertainty by referring to “CVE-2026-8452(?)” in their analysis.

The incident has also attracted attention beyond the original advisory. On August 17, the Canadian Centre for Cyber Security reported that open-source information indicated exploitation of CVE-2026-8452 in the wild and recommended that affected organizations apply the vendor’s updates.

Why does the architecture behind the vulnerability matter?

The important point for ADC teams is that the issue described in the independent research is not related to the basic task of distributing traffic between backend servers. It appears in SAML authentication processing.

SAML, or Security Assertion Markup Language, is an XML-based standard used to exchange authentication and authorization information between an Identity Provider (IdP) and a Service Provider (SP). It is widely used for enterprise Single Sign-On.

Whether an ADC participates directly in that authentication process depends on how the platform is designed and configured.

That distinction matters because two ADC platforms can provide similar application-delivery capabilities while handling identity in very different ways. A vulnerability affecting one vendor’s authentication-processing path therefore does not automatically imply that another ADC exposes the same component or code path.

This is where the SKUDONET architecture becomes relevant.

How does SKUDONET handle SAML differently?

SKUDONET does not place the ADC inside the SAML authentication and identity-validation chain described in the independent NetScaler research.

Authentication remains the responsibility of the application, its SAML Service Provider and the Identity Provider.

A typical architecture is:

User
SKUDONET ADC / WAF
Application / SAML Service Provider
↕
Identity Provider

The Identity Provider and Service Provider remain responsible for authenticating the user and validating SAML assertions. SKUDONET, meanwhile, handles the application-delivery layer: balancing, inspecting, protecting and delivering application traffic.

For this reason, SKUDONET is not affected by CVE-2026-8452, and the SAML authentication-processing path analyzed by watchTowr is not part of SKUDONET’s ADC architecture.

This should not be interpreted as a claim that SKUDONET — or any other Internet-facing software — is immune to vulnerabilities. It means that the specific component and processing path involved in this incident are not present in SKUDONET.

Can SKUDONET inspect SAML traffic without processing authentication?

Yes. Participating in SAML authentication and inspecting the traffic that carries SAML messages are two different responsibilities.

SAML messages are based on XML and are normally transported over HTTP or HTTPS. SKUDONET’s Web Application Firewall can inspect HTTP requests and structured request payloads before they reach the protected application.

The WAF uses ModSecurity as its inspection engine. XML request bodies can be parsed and inspected so that security policies can evaluate their structure and content.

For a SAML endpoint behind SKUDONET, the processing path is:

Incoming SAML/XML request
SKUDONET ADC
WAF inspection
XML parsing and security rules
Application / SAML Service Provider
Identity validation

The distinction is deliberate: the WAF does not replace the cryptographic validation of a SAML assertion. That remains the responsibility of the identity layer.

Instead, the WAF provides an independent application-security layer that can inspect HTTP/S and XML traffic before it reaches the component responsible for identity processing.

For SAML security, those layers are complementary rather than interchangeable.

What does CVE-2026-8452 tell us about ADC security architecture?

One lesson from this incident is that ADC security should not be evaluated only by counting available security features.

It also matters where those capabilities are implemented and which component is responsible for each function. Separation of responsibilities does not mean removing integrated application-security functionality.

SKUDONET can combine application delivery and application protection through capabilities such as load balancing and WAF inspection while leaving identity authentication and cryptographic SAML validation to the application and identity infrastructure.

Put simply:

  • ADC: application delivery
  • WAF: application security and traffic inspection
  • IdP / SP: authentication and identity validation

This architecture does not eliminate vulnerabilities; no Internet-facing architecture can reasonably make that claim. What it does is establish defined functional boundaries.

A security issue affecting one type of functionality does not automatically mean that every ADC platform contains the same component or processes the same information in the same way.

Determining whether another ADC would be exposed to the same vulnerability therefore requires understanding its architecture and processing path, not simply comparing feature names.

What should organizations review after an ADC security incident?

The first response to a vulnerability should be operational, not commercial. Organizations running an affected NetScaler configuration should identify exposed systems and follow the vendor’s remediation guidance.

Once that immediate work is complete, some security and infrastructure teams may also use the incident as an opportunity to review how responsibilities are distributed across their architecture.

Useful questions include:

  • Which Internet-facing components process authentication?
  • Which components terminate or inspect application traffic?
  • Where does identity validation occur?
  • Which services provide remote access?
  • How are application-delivery and security policies managed?
  • How dependent is the environment on platform-specific configuration?

That review does not automatically imply replacing an ADC. For many organizations, applying the relevant fixes and retaining the current architecture will be the appropriate response.

For others, security reviews may coincide with broader considerations around licensing, operational complexity, infrastructure strategy, vendor dependency or future architecture.

If that wider evaluation is already taking place, our guide to NetScaler alternatives covers the platform-comparison perspective separately from this technical vulnerability analysis.

Keeping those two topics separate is deliberate: a vulnerability should be understood and remediated on its technical merits, while a platform decision should consider the broader requirements of the infrastructure.

If an ADC reassessment leads to migration, configuration is usually the hard part

A NetScaler migration usually is not about replacing an appliance; it is about replacing years of application-delivery configuration.

A mature NetScaler environment can contain hundreds of interconnected objects, including:

  • Content Switching virtual servers
  • Load Balancing virtual servers
  • Content Switching policies
  • Service groups
  • Services and backend servers
  • Persistence configurations
  • Health monitors
  • SSL certificates
  • SNI configurations
  • Host and URL routing rules
  • Network dependencies

Those objects cannot necessarily be treated as isolated lines of configuration because their relationships define how applications are actually delivered.

Recreating those dependencies manually on another ADC can require considerable engineering effort and introduce migration risk. That is why an ADC migration is more than a syntax-conversion exercise: the intent behind the existing configuration also needs to be understood.

SKUDONET is developing NetScaler-to-SKUDONET migration technology that analyzes existing configurations and identifies how their objects and relationships can be translated into the corresponding SKUDONET architecture.

For example:

NetScaler
Content Switching vServer
Content Switching policies
Load Balancing vServers
Service Groups
Services / Backends
Health monitoring

These relationships can be analyzed against the corresponding SKUDONET farms, services, routing rules, backends and health-checking configuration.

The objective is to preserve the existing application-delivery logic while changing the ADC platform wherever an equivalent is supported.

The migration process can analyze dependencies, identify supported equivalences, highlight potential migration risks and distinguish between what can be translated automatically and what needs human review.

SKUDONET’s migration tooling is currently being validated against real-world NetScaler environments containing more than 650 configuration objects, including complex relationships between Content Switching virtual servers, Load Balancing virtual servers, policies, service groups, services, certificates, persistence, health monitoring and backend infrastructure.

For organizations with an active migration project, configuration analysis can form part of a technical assessment to understand feasibility, dependencies and potential migration effort before production changes are planned.

Frequently asked questions about CVE-2026-8452

What is CVE-2026-8452?

CVE-2026-8452 is a memory overflow vulnerability affecting specific NetScaler ADC and NetScaler Gateway versions and configurations. NetScaler states that it can cause unpredictable or erroneous behavior and Denial of Service when an appliance is configured as a Gateway or AAA virtual server.

For the main supported branches, affected versions include NetScaler ADC and Gateway 14.1 before 14.1-72.61 and 13.1 before 13.1-63.18, together with the corresponding affected FIPS and NDcPP releases.

Is CVE-2026-8452 a SAML vulnerability?

NetScaler’s official bulletin does not specifically describe CVE-2026-8452 as a SAML vulnerability.

Independent researchers at watchTowr analyzed a SAML-processing memory corruption and demonstrated pre-authentication remote code execution, which they believe corresponds to CVE-2026-8452. They also explicitly acknowledge that the public information does not allow definitive attribution.

Is CVE-2026-8452 being exploited?

The Canadian Centre for Cyber Security updated its advisory on August 17, 2026, stating that open-source reporting indicated CVE-2026-8452 was being exploited in the wild.

Organizations operating affected NetScaler configurations should follow the vendor’s guidance and apply the relevant updates.

Is SKUDONET affected by CVE-2026-8452?

No. CVE-2026-8452 applies to NetScaler products, and the SAML authentication-processing component described in the independent research is not part of SKUDONET’s ADC architecture.

With SKUDONET, authentication and SAML assertion validation remain the responsibility of the application, Service Provider and Identity Provider.

Can SKUDONET protect an application that uses SAML?

Yes. Applications using SAML can be delivered through SKUDONET.

Since SAML messages are XML and are commonly transported over HTTP/S, the SKUDONET WAF can inspect structured request traffic before it reaches the application. The WAF does not replace SAML signature or identity validation, which remain the responsibility of the identity layer.

Can an existing NetScaler configuration be assessed for migration to SKUDONET?

SKUDONET is developing migration technology that analyzes NetScaler configuration objects and their dependencies to identify supported equivalents, potential migration risks and areas requiring manual review.

The tooling is currently being validated against real-world environments containing more than 650 interconnected NetScaler configuration objects.

Already evaluating a NetScaler migration?

If your organization is actively reassessing its ADC strategy, the first step is to understand the scope, dependencies and migration requirements of your current environment.

Talk to the SKUDONET team about your NetScaler environment. As part of a migration assessment, we can determine whether configuration analysis is appropriate and evaluate how existing application-delivery logic could map to SKUDONET.

This gives your infrastructure team a clearer view of migration feasibility and potential effort before making changes to production.

25 August, 2026 12:33PM by Isabel Perez

hackergotchi for ARMBIAN

ARMBIAN

Github Highlights

Github Highlights

This week&aposs changes center on expanded board and platform support, a modernized build and release pipeline anchored on Debian Trixie and ISO output, and a substantial documentation and release-process overhaul.

On the hardware side, the EmbedFire LubanCat 4 (RK3588S) and Xiaomi Pad 6S Pro (sheng) join as new boards, Tanix TX6S is promoted to Supported, and Banana Pi R2 (MT7623) returns with kernel 6.18, edge 7.1, and U-Boot 2026.07. The reComputer RK3588 moves to the Panthor open-source GPU stack, NanoPCT6 U-Boot advances to v2026.07, and reComputer RK3576/RK3588 receives U-Boot fixes for SPI boot, NVMe, and rockusb. Several Rockchip and Qualcomm device trees are corrected, and RTL8852BS, RTL88x2CS, and related wireless drivers are refreshed with substantial warning cleanup.

Build infrastructure sees the official host and default Docker image switch to Debian Trixie, Ubuntu Noble dropped from release and SDK targets, and image signing extended to every format. UEFI current/edge targets now ship as ISO for both minimal and desktop variants, nightly builds are restricted to platinum boards, and SDK CI moves to self-hosted runners with auto-retry and dispatch-driven index updates. A weekly stable build with automatic version bump is now scheduled.

Documentation and release tooling receive extensive rework: armbian-config pages are reorganized under /config/ with per-subcategory splits, per-app SEO pages and category hubs are emitted, and the manual changelog is replaced by per-release pages with a quarterly digest published to docs.armbian.com. Release-summary generation now groups by source repository, recovers PR links, and is anchored to release windows.

#Armbian #EmbeddedLinux #Rockchip #DebianTrixie #ReleaseEngineering

Changes

25 August, 2026 11:59AM by Michael Robinson

hackergotchi for GreenboneOS

GreenboneOS

The Cyber Resilience Act at Two Weeks: What’s Actually Ready, and What Isn’t

Two weeks before Article 14 reporting becomes mandatory, the infrastructure behind it is still under construction. The Commission’s guidance is approved but not yet formally in force. The reporting platform is in testing, not live. Not one harmonised standard has a citation in the Official Journal. Each of those gaps puts more weight on the […]

25 August, 2026 11:37AM by Greenbone AG

hackergotchi for Volumio

Volumio

Hi Fi Streaming for Better Sound at Home

A favorite record can reveal a system’s character in seconds: the weight of a kick drum, the air around a vocal, the way a cymbal fades rather than simply stops. Hi fi streaming is about preserving those details while making your complete music collection easier to enjoy. It brings subscription services, radio, and locally stored albums to the hi-fi system you already value, without turning listening into a sequence of app changes and connection workarounds.

For some listeners, the appeal begins with access to millions of tracks. For others, it is finally hearing a carefully collected library through the main system rather than from a computer or phone. The best result is both: all your music in one place, presented with the care your speakers, amplifier, and room deserve.

What hi fi streaming actually means

Streaming is often mistaken for a simple handoff from a phone to a speaker. A hi-fi streamer does more. It is a dedicated network music player designed to retrieve music from a streaming service or local storage, organize it in a useful interface, and send an audio signal to a DAC or integrated amplifier.

That dedicated role matters. A phone is a remarkably capable device, but it is also managing notifications, calls, background processes, battery life, and an interface built for dozens of unrelated tasks. A purpose-built music player is focused on playback. It can sit quietly in the rack, remain available whenever you want to listen, and be controlled from a phone, tablet, or computer without making that device the source of the music.

The phrase also implies intent. Hi fi streaming is not automatically better because a file has a large number printed beside it. Sound quality comes from the whole playback chain: the source material, network player, digital output or internal DAC, analog circuitry, amplifier, speakers, and room. The goal is not to chase specifications in isolation. It is to create a reliable, natural path from music to listener.

The signal path matters, but so does the experience

A streamer usually receives music over Ethernet or Wi-Fi. It may play files from network-attached storage, a USB drive, or a shared computer folder. It then either converts the digital signal to analog internally or passes it to an external DAC through USB, coaxial, optical, or AES/EBU, depending on the component.

There is no single correct arrangement. If you own an integrated amplifier with an excellent DAC section, a digital transport streamer can be the sensible choice. If your amplifier is purely analog, or if you want to simplify the system, a streamer with a strong built-in DAC may be a better fit. Separating the streamer and DAC can offer more flexibility for future changes, while an all-in-one design reduces cables and boxes.

The listening interface deserves equal attention. If finding an album requires moving between a service app, a local-library app, and a separate remote-control app, the system gradually becomes less inviting. A unified music player should let you search across services and personal files, browse artists and genres, build playlists, and return to recent favorites from one familiar place. Convenience is not separate from serious listening. It is what makes serious listening happen more often.

Start with the music you actually use

Before comparing formats, outputs, or chassis materials, consider your everyday listening. Do you primarily use TIDAL, Qobuz, Spotify, internet radio, or a mix of each? Do you have thousands of downloaded albums, live recordings, rare releases, and rips that cannot be found on a subscription service? The answers should shape the streamer, not the other way around.

Local libraries remain one of the strongest reasons to choose dedicated streaming hardware. They preserve ownership and often contain the versions listeners know best: an original master, a favorite CD rip, a bootleg, or a carefully tagged classical collection. Good library management makes these files feel like an extension of the streaming catalog rather than a neglected archive on a hard drive.

Metadata is central here. Artist names, album artists, composers, release dates, genre tags, artwork, and track numbers determine whether a collection is a pleasure to explore or a confusing wall of filenames. A capable platform can help organize the experience, but clean tags still pay off. Spending an evening correcting a few important albums may improve daily listening more than changing an accessory.

Lossless quality is useful, not a finish line

Lossless streaming has made excellent source material widely available. With a compatible service and device, the digital data can arrive without the information discarded by traditional lossy compression. That is meaningful, especially with resolving equipment and recordings you know well.

Still, lossless is not a guarantee of superior sound. The mastering of an album often has a greater influence than its file resolution. A well-mastered CD-quality recording can sound more convincing than a poorly mastered high-resolution version. Some releases are offered in multiple editions, and the one with the biggest numbers is not always the most musical.

High-resolution playback can be worthwhile when the recording and master support it, but it should not become a distraction from the fundamentals. Stable playback, a well-designed DAC, sensible gain structure, speaker placement, and room acoustics all have a voice in the final result. Trust familiar music and sustained listening over quick comparisons.

Build for reliability first

The best streaming system is one you never hesitate to use. That begins with a stable network. Ethernet is often the simplest answer for a fixed hi-fi installation because it offers a consistent wired connection and avoids local wireless congestion. Wi-Fi can work very well when a cable is impractical, particularly with a strong router and good signal near the listening room.

Avoid assuming that every network issue is an audio issue. Dropouts are more commonly caused by weak Wi-Fi coverage, crowded router settings, or an overworked network than by a streamer itself. Start by placing the router well, updating its firmware, and using a wired connection where it makes sense. Expensive network accessories are rarely the first move when basic coverage has not been addressed.

Power supply design also matters, though its importance depends on the component and system. Quiet, stable power can support the performance of sensitive digital and analog circuits. A thoughtfully engineered external linear power supply may be a meaningful upgrade for compatible equipment, but it should follow a system that is already working reliably. Solve everyday usability before pursuing finer refinements.

Choose control that keeps you close to the music

A good controller should disappear quickly. You should be able to choose an album from the sofa, queue a discovery from a radio station, or move from a local jazz recording to a newly released orchestral album without interrupting the mood. Multiroom support may matter for a whole-home setup, while a single focused listening room may benefit most from a clean, responsive interface and dependable playback.

Voice control can be useful in casual settings, but it is not essential to a satisfying hi-fi experience. Many listeners prefer a visual interface that shows credits, artwork, formats, and queue information. Others want a tactile remote for the simplest commands. It depends on how you listen and who shares the system.

This is where an ecosystem can make a tangible difference. Volumio brings streaming services, local libraries, connected devices, and playback control into one music-first environment, while giving listeners a path from a Raspberry Pi project to dedicated components hand-assembled in Florence. The common idea is straightforward: technology should reduce friction between you and the next song.

A sensible path to a better setup

If you are beginning, connect a capable streamer to the DAC already in your amplifier or receiver, use the streaming service you know, and spend time with familiar albums. If your library is important, add it early and make sure the browsing experience feels natural. Once the basics are established, compare connection types or DAC options based on the needs of your system rather than online consensus.

For builders, software support and device compatibility are as important as the board itself. A small computer can become a genuinely rewarding network player when the operating system, audio output, and control interface are designed to work together. For established systems, dedicated hardware can offer quieter operation, better connectivity, stronger construction, and a more refined everyday experience.

Give yourself permission to stop optimizing and listen. Put on an album you have lived with for years, let it play past the tracks you usually test, and notice whether the system makes you want to hear one more side, one more movement, one more song. That is the standard a hi-fi streaming setup should meet.

The post Hi Fi Streaming for Better Sound at Home appeared first on Volumio.

25 August, 2026 05:15AM

August 24, 2026

Volumio Primo Plus Wins EISA Streamer Award 2026-2027

We are proud to announce that the Volumio Primo Plus is the winner of the 2026-2027 EISA Streamer award. Primo Plus is all about streaming quality audio with utmost clarity, and depth through its dual mono ESS design, low noise power architecture, and precision clocking. 

The DAC streamer was designed to enhance the original Primo, elevating performance by combining 2 x ESS ES9039Q2M in a dual mono layout with upgraded OPAMPs, an ultra-low noise dual linear power supply, refined filtering, and a high-precision clock that cuts jitter and lifts overall resolution.

EISA Awards

In case you haven’t heard about them before, the EISA (Expert Imaging and Sound Association) represents the biggest worldwide editorial collaboration of consumer electronics. Currently with over 50 international expert magazines, every year they gather and select the best consumer electronic products, giving the EISA award to only the very best products in their category.

Primo Plus is the third Volumio product to receive an EISA award. The Volumio Rivo accepted the 2023-2024 EISA award for best digital player. Rivo delivers the best digital signal with utmost simplicity, providing top-notch digital streams to your DAC or integrated amplifier without any fuss. We are incredibly honored to receive a third award from EISA.

About Primo Plus

Engineered to extract the absolute purest signal from your music, the Primo Plus begins with a high-precision clock that minimizes phase noise and jitter for a remarkably stable, clean performance. Its sophisticated power design employs LC filtering alongside independent regulation for the analog and digital sections, protecting micro-details and maintaining effortless control.

You can tailor your listening experience using eight selectable DAC filters, or bypass them entirely with NOS mode for a pure, unprocessed sound. With a fully balanced output stage ensuring exceptional channel separation, and an integrated volume control, you can connect the Primo Plus directly to your power amp for a sleek, ultra-high-performance system.

Primo Plus: Advanced listening experience, studio-grade playback

Volumio Primo Plus is all about tailoring the audio to your ears. Tweak and fine-tune your sound using the selectable DAC filters, or let the pre-automated system handle the heavy lifting. With the fully balanced architecture and integrated capabilities, Primo Plus is more than just a streamer. It is a true game-changer, combining advanced audio technology, effortless ease of use, and uncompromising playback to enhance your listening experience.

Learn more about the Primo Plus and what makes it an award-winning streamer.

The post Volumio Primo Plus Wins EISA Streamer Award 2026-2027 appeared first on Volumio.

24 August, 2026 12:57PM by Priyal Talwar

hackergotchi for GreenboneOS

GreenboneOS

CVE-2026-19478: GitLab CE/EE GraphQL Unauthenticated Flaw Actively Exploited

GitLab has released fixes for CVE-2026-19478 (CVSS 9.4, EPSS 0.7% (51st percentile)), a critical-severity code injection flaw [CWE-94]. The vulnerability affects the GraphQL directive in GitLab Community Edition (CE) and Enterprise Edition (EE). According to GitLab, the flaw can allow an unauthenticated attacker to remotely modify or delete public projects and user data under certain […]

24 August, 2026 11:33AM by Joseph Lee

hackergotchi for Deepin

Deepin

August 23, 2026

hackergotchi for Volumio

Volumio

Best DACs for Network Streaming Explained

A great network streamer can put an extraordinary catalog at your fingertips, but the DAC is where those digital files become music in your room. The best DACs for network streaming are not simply the models with the highest sample-rate figure or the longest specification sheet. They are the ones that suit your streamer, amplifier, speakers, listening habits, and priorities.

For some systems, that means a transparent standalone DAC that lets a dedicated transport do its best work. For others, it means choosing a streamer with a well-executed DAC already inside it, reducing boxes and cables without giving up musical involvement. The right choice begins with understanding what the DAC actually contributes.

What a DAC changes in a streaming system

A digital-to-analog converter receives the streamer’s digital signal and turns it into the analog signal your amplifier can use. That simple description hides a great deal of engineering: clock management, power regulation, digital filtering, analog output stages, and circuit layout all influence the final result.

A good DAC should not impose a personality on every recording. It should preserve the timing, tonal color, space, and dynamic contrast already present in the music. When a system gets this right, bass lines are easier to follow, vocal phrasing feels more natural, and dense arrangements remain intelligible instead of becoming a flat wall of sound.

That does not mean every listener wants the same presentation. Some prefer a highly revealing sound with sharply defined transients. Others value a more relaxed, full-bodied character that makes long listening sessions inviting. Neither preference is wrong. The best choice is the one that makes you want to play one more album.

Start with your streamer, not the DAC chip

It is easy to compare converter chips and assume that a particular name or number tells the whole story. In practice, the chip is only one part of the design. Two DACs built around the same chip can sound noticeably different because their power supplies, clocks, output stages, and implementation choices differ.

Begin with the digital outputs on your network streamer. USB is often the most flexible connection for high-resolution playback and can carry PCM and DSD formats at high rates. AES/EBU is a balanced professional-style connection valued for its secure locking connector and excellent noise rejection. Coaxial S/PDIF is widely available, dependable, and capable of superb sound. Optical can be useful where electrical isolation is the priority, though it may have more limited format support depending on the equipment.

If your streamer offers a dedicated USB audio output, look for a DAC with a well-designed asynchronous USB input. In this arrangement, the DAC controls the timing of the data transfer rather than relying on the source device’s clock. This can help reduce timing errors and gives the DAC’s own clocking architecture a more central role.

Integrated DAC or separate components?

An integrated streamer-DAC is the elegant answer for listeners who want fewer components and a simpler system. It combines network playback, control, and conversion in one chassis, often with a shorter signal path and less cable clutter. For a second system, a compact listening room, or anyone who wants excellent playback without building a rack full of equipment, this approach makes a great deal of sense.

A separate streamer and DAC offers more freedom. You can select a digital transport for its interface, software experience, and isolation, then pair it with a DAC chosen for its analog character and connectivity. It also makes future upgrades more focused. If streaming technology evolves, you can replace the transport while keeping a DAC you already love.

The trade-off is that separate components require more care. Digital cable choice, placement, power quality, and gain matching can all matter. This is not a reason to avoid separates. It is simply a reason to choose them with purpose rather than assuming more boxes automatically mean better sound.

The features that matter most

Format compatibility matters, but only in proportion to the music you play. A DAC that handles high-resolution PCM files and the formats supported by your preferred services will cover the needs of most listeners. Native DSD capability may be relevant if you own a library in that format, but it should not outweigh more fundamental qualities such as a quiet analog stage and stable operation.

Pay closer attention to inputs and outputs. A DAC with USB, coaxial, optical, and AES/EBU inputs gives a system room to grow and can accommodate a CD transport, television, or computer alongside your streamer. Balanced XLR outputs are useful when your amplifier supports them, especially with longer cable runs. Well-designed RCA outputs remain an excellent choice for many systems.

Volume control deserves particular thought. Some DACs offer a variable output that can feed a power amplifier directly. This can create a remarkably clean, minimal system, but only if the DAC’s volume implementation is genuinely strong and your sources are limited. A dedicated preamplifier may still be preferable when you need multiple analog inputs, tone shaping, or a particular kind of drive and presence in the system.

Do not underestimate power and isolation

Network playback joins sensitive audio circuitry with processors, wireless radios, Ethernet connections, and switching power supplies. A thoughtfully designed DAC protects its analog section from unwanted electrical noise through careful grounding, shielding, regulation, and component layout.

This is one reason specifications alone cannot tell the whole story. A very low distortion measurement is valuable, but it does not fully describe how a DAC handles a complex recording at realistic volume. Listen for the quiet between notes, the stability of an image, and whether cymbals retain texture without becoming brittle.

External power supplies can be worthwhile in the right design, but they are not a universal upgrade. First make sure the DAC itself is a strong match for your system. Better fundamentals will usually bring greater rewards than adding accessories to compensate for a poor fit.

How to audition the best DACs for network streaming

When possible, audition with familiar music, not only demonstration tracks. Choose a sparse vocal recording, an acoustic piece with natural decay, a rhythmically demanding track, and a densely arranged song you know well. These reveal different strengths.

Keep volume levels closely matched. A slightly louder component often appears more detailed or exciting, even when it is not more accurate. Give each DAC enough time, too. Initial impressions are useful, but the better question is whether you remain engaged after an hour of listening.

Listen for musical clues rather than hi-fi fireworks. Does a piano have convincing weight and harmonic complexity? Can you follow the bass player without losing the kick drum? Do voices feel placed in a believable space? Is the presentation involving at low volume as well as loud? A DAC that impresses immediately but becomes fatiguing is rarely the long-term answer.

Match the DAC to the rest of the chain

A revealing DAC can be wonderful with warm, forgiving speakers and an amplifier with good tonal density. In an already forward or highly detailed system, the same DAC may push the sound toward fatigue. Conversely, a smoother DAC can bring balance to bright room acoustics, but may feel too soft in a heavily damped room or with laid-back speakers.

Consider your amplifier’s input sensitivity and the DAC’s output voltage as well. Most combinations work without issue, but a mismatch can leave you with a narrow useful range on the volume control or excessive gain. If you use a tube amplifier, a high-efficiency speaker, or a direct-to-amp setup, this detail becomes especially relevant.

Your room remains part of the system. Before replacing a capable DAC in search of more bass or a wider soundstage, check speaker placement, seating position, and basic room treatment. Those changes can be more dramatic than a component swap.

A better way to choose

Set a clear budget for the complete digital front end, including the streamer, DAC, and the connections required to use them properly. Then decide what matters most: maximum simplicity, broad connectivity, a direct-to-amplifier path, upgrade flexibility, or a particular sonic balance.

For listeners building a refined streaming system, the most satisfying result often comes from treating software and hardware as one experience. A platform such as Volumio can bring local files and favorite streaming services into one focused interface, while a carefully chosen DAC gives that library the scale, color, and emotional immediacy it deserves.

Trust the listening experience over feature anxiety. The right DAC will make technology recede, leaving the performance in front of you and the next record already calling from the queue.

The post Best DACs for Network Streaming Explained appeared first on Volumio.

23 August, 2026 05:12AM