<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~files/feed-premium.xsl"?>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xmlns:feedpress="https://feed.press/xmlns" xmlns:podcast="https://podcastindex.org/namespace/1.0" version="2.0">
  <channel>
    <feedpress:locale>en</feedpress:locale>
    <feedpress:newsletterId>itsfoss</feedpress:newsletterId>
    <atom:link rel="hub" href="https://feedpress.superfeedr.com/"/>
    <title>It's FOSS</title>
    <description>Making You a Better Linux User</description>
    <link>https://itsfoss.com/</link>
    <image>
      <url>https://itsfoss.com/content/images/2025/11/android-chrome-512x512.png</url>
      <title><![CDATA[It's FOSS]]></title>
      <link>https://itsfoss.com/</link>
    </image>
    <generator>Ghost </generator>
    <lastBuildDate>Tue, 06 Oct 2026 21:23:31 +0530</lastBuildDate>
    <atom:link href="https://feed.itsfoss.com/" rel="self" type="application/rss+xml"/>
    <ttl>60</ttl>
    <item>
      <title><![CDATA[Siemens Abruptly Takes Down OpenRadioss, But a Fork is Already Live]]></title>
      <description><![CDATA[Another reminder of why open source saves software from being lost forever.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17489673/siemens-openradioss-fork</link>
      <guid isPermaLink="false">6ac367647834300001c57c71</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Mon, 05 Oct 2026 20:30:15 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/opencourant-openradioss-fork-banner.png" medium="image">
        <media:description type="plain">opencourant launch banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/opencourant-openradioss-fork-banner.png" alt="opencourant launch banner" loading="lazy"></figure>
<p>The globally recognized tech and engineering company has quietly shut down the OpenRadioss project at the start of this month, keeping <a href="https://github.com/OpenRadioss/">the GitHub page</a> around but completely removing the repository.</p><p>I sound complainy because usually when an open project is discontinued, the maintainers put it into a read-only, public archive state, which allows other developers to learn and fork off it.</p><p>OpenRadioss was the open source release of <a href="https://www.siemens.com/en-us/products/simcenter/mechanical-simulation/radioss/">Radioss</a>, a finite element solver Altair Engineering developed for crash testing, blast response, impact analysis, and other structure loading scenarios.</p><p>They had released it in <a href="https://www.prnewswire.com/news-releases/industry-proven-altair-radioss-finite-element-analysis-solver-now-available-as-open-source-solution-301619986.html?utm_source=chatgpt.com">September 2022</a>, drawing in a multinational community of researchers, software developers, and industry contributors who extended the solver and built upon the code.</p><p>Siemens, which <a href="https://press.siemens.com/global/en/pressrelease/siemens-acquires-altair-create-most-complete-ai-powered-portfolio-industrial-software">acquired Altair last year</a>, kept the repo and its contents publicly available for more than a year after the acquisition before abruptly deleting it and redirecting people to its <a href="https://www.siemens.com/en-us/products/simcenter/mechanical-simulation/radioss/rd/">transition page</a> for Simcenter Radioss.</p><h2 id="a-fork-appears">A fork appears</h2>
<!--kg-card-begin: html-->
<div class="repo-stats" data-repo="https://github.com/OpenCourant/OpenCourant"></div>
<!--kg-card-end: html-->
<p><a href="https://tiuxo.com">Brian Clemens</a>, the co-founder of Rocky Linux has already got an OpenRadioss fork up and running, which carries the full OpenRadioss commit history, ships under the same <a href="https://www.gnu.org/licenses/agpl-3.0.en.html">GNU AGPLv3 license</a>, and is hosted on <a href="https://github.com/OpenCourant/OpenCourant">GitHub</a>.</p><p>It's called <a href="https://opencourant.org">OpenCourant</a>, named after mathematician Richard Courant and the <a href="https://en.wikipedia.org/wiki/Courant%E2%80%93Friedrichs%E2%80%93Lewy_condition">Courant-Friedrichs-Lewy</a> (CFL) condition, a stability criterion central to solvers like this one.</p><p>In fact, this fork owes its existence to the AGPL. You see, <strong>Siemens is legally within its rights to take down the repository</strong>, but the license applying to every commit gave anyone the right to fork, distribute, and build on the code.</p><p>It's just sad to see how abruptly the takedown was carried out; makes you think they didn't want people to get a heads-up.</p><p>Also worth noting is that <strong>OpenCourant is an independent community project</strong>, and it is actively looking for past OpenRadioss contributors to pitch in.</p><h2 id="whats-already-shipping">What's already shipping?</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/opencourant-downloads-page-1.png" class="kg-image" alt="a placeholder image that shows the opencourant download page on its website" loading="lazy" width="962" height="839" srcset="https://itsfoss.com/content/images/size/w600/2026/10/opencourant-downloads-page-1.png 600w, https://itsfoss.com/content/images/2026/10/opencourant-downloads-page-1.png 962w" sizes="(min-width: 720px) 720px"></figure><p>Initially, the upstream build pipeline that depended on proprietary Siemens infrastructure could not be transferred. That was rebuilt from scratch, and the results appear promising.</p><p>Just days since its inception, the project is <strong>already distributing Linux and Windows <em>x86_64</em> packages</strong>.</p><p>And before that, a closed-source <code>hm_reader</code> <em>input-reader</em> binary that was never committed to the git history disappeared along with the upstream OpenRadioss repository.</p><p>Thankfully, an unnamed community member who had kept a copy came forward, the OpenCourant team independently verified it, and it now ships in every build. Though they are <a href="https://github.com/orgs/OpenCourant/discussions/10">still looking for specific release archives</a> to start work on ARM64 support and improve current platform compatibility.</p><p>If you are interested in OpenCourant, then its package options include the <em>Starter</em> and <em>Engine </em>offerings in single and double precision, SMP builds, and converters for animation files and time history data.</p><p>You can download the latest builds from the <a href="https://opencourant.org/downloads/">official downloads page</a>.</p><div class="kg-card kg-button-card kg-align-center"><a href="https://opencourant.org/downloads/" class="kg-btn kg-btn-accent">OpenCourant</a></div><p><strong>If you get lost</strong>, the <a href="https://github.com/OpenCourant/OpenCourant/blob/main/INSTALL.md">INSTALL.md</a> file can be a good resource, though keep in mind it is still the OpenRadioss version, as the OpenCourant team has yet to update it to reflect the new project.</p>
<img src="https://feed.itsfoss.com/link/24361/17489673.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[Ubuntu 26.10 Will Have a Rust-based GnuPG Replacement]]></title>
      <description><![CDATA[The Rust-based OpenPGP tool lands in Ubuntu 26.10's main archive, with sq and sqv available alongside gpg and gpgv.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17489445/ubuntu-sequoia-pgp-inclusion</link>
      <guid isPermaLink="false">6ac32c547834300001c57b1d</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Mon, 05 Oct 2026 15:20:08 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-gnupg-banner.png" medium="image">
        <media:description type="plain">ubuntu gnupg and sequoia pgp banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-gnupg-banner.png" alt="ubuntu gnupg and sequoia pgp banner" loading="lazy"></figure>
<p>You already know that Canonical has been selectively replacing Ubuntu's C-based system components with Rust-written equivalents that don't compromise in terms of functionality, <em>most of the time</em>.</p><p>Now it looks like the distro's OpenPGP implementation is next, with Sequoia PGP coming preinstalled in Ubuntu 26.10. Canonical wants it to eventually replace GnuPG as the default toolchain, though that switch has not happened yet.</p><h2 id="whats-openpgp">What's OpenPGP?</h2><p>Before getting into Sequoia, it helps to know what <a href="https://www.openpgp.org">OpenPGP</a> actually is. It's not a tool but rather a widely adopted standard.</p><p>Phil Zimmermann created the original PGP in 1991, and the IETF now maintains the open version of that work. The specification defines how software should encrypt, decrypt, sign, and verify data so that any two implementations following it can work with each other's data.</p><p>On Linux, <a href="https://www.gnupg.org">GnuPG</a> has been the dominant implementation of that standard. Written in C, it implements <a href="https://www.ietf.org/rfc/rfc4880.txt">RFC 4880</a> and offers the <code>gpg</code> and <code>gpgv</code> commands on the platform. These handle everything from encryption and key management to standalone signature verification.</p><h2 id="sequoia-pgp-is-different">Sequoia PGP is different</h2><p>It was started in 2017 by three former GnuPG developers who chose to build a new OpenPGP implementation in Rust rather than keep evolving GnuPG&rsquo;s existing codebase.</p><p><a href="https://sequoia-pgp.org">Sequoia PGP</a> is designed as a library that other software can use directly, rather than a standalone command-line tool.&nbsp;<code>sq</code>&nbsp;sits on top of that for encryption, decryption, signing, and key management, and&nbsp;<code>sqv</code>&nbsp;handles signature verification, filling in for&nbsp;<code>gpg</code>&nbsp;and&nbsp;<code>gpgv</code>&nbsp;in GnuPG.</p><p>Sequoia also implements&nbsp;<a href="https://www.rfc-editor.org/rfc/rfc9580.txt">RFC 9580</a>, the 2024 revision of the OpenPGP standard, whereas GnuPG has continued from the RFC 4880 branch, pursuing its own newer extensions and the LibrePGP specification rather than adopting RFC 9580 as its primary standard.</p><h2 id="whats-already-in">What's already in?</h2><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-1.png" width="982" height="862" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/ubuntu-sequoia-pgp-1.png 600w, https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-1.png 982w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-2.png" width="982" height="788" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/ubuntu-sequoia-pgp-2.png 600w, https://itsfoss.com/content/images/2026/10/ubuntu-sequoia-pgp-2.png 982w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p>Ubuntu 26.10 "Stonking Stingray" already pulls in Sequoia PGP from <a href="https://archive.ubuntu.com/ubuntu/pool/main/r/">the main archive</a> (<em>look under rust-sequoia-xx</em>) as part of the default installation. I ran <code>sq</code> and <code>sqv</code> on a development build of <a href="https://itsfoss.com/news/ubuntu-26-10-features/">26.10</a>, and both were working correctly.</p><p>Here, <code>sq</code> acts as the main interface for encryption, decryption, signing, and key management, while <code>sqv</code> handles signature verification. And typing <code>gpg</code> and <code>gpgv</code> still routes to GnuPG, so these two OpenPGP implementations sit alongside each other.</p><p>If Sequoia PGP is made the default, you can expect those commands and other GnuPG ones to route to Sequoia instead, similar to <a href="https://itsfoss.com/sudo-vs-sudo-rs/">how we saw with sudo-rs</a>.</p><h2 id="still-a-long-way-to-go">Still a long way to go</h2><p>The <a href="https://documentation.ubuntu.com/release-notes/26.10/#an-oxidized-openpgp">release notes</a> for Ubuntu 26.10 and <a href="https://discourse.ubuntu.com/t/rust-on-ubuntu-2026-10/88671">a recent announcement</a> clearly mention that Sequoia PGP becoming Ubuntu's default OpenPGP toolchain is a future goal, <strong>not something that's already the default experience</strong>.</p><p>The <em>coreutils</em> transition started in 2025 and <a href="https://itsfoss.com/news/ubuntu-rustification-coreutils-migration/">only reached 100% with 26.10</a>. The <code>sudo-rs</code> switch was shown off well in advance before it became the default. Each of these components had to earn their place over multiple release cycles before anything changed for users.</p><p>Sequoia PGP is at the start of that process. Landing in the <em>main</em> archive is the first milestone. Whether it eventually replaces GnuPG as the default remains to be seen.</p><p>Canonical has not shared a specific inclusion timeline. Given how carefully they have moved on every other Rust transition so far, that caution is unlikely to disappear for something as foundational as OpenPGP.</p>
<img src="https://feed.itsfoss.com/link/24361/17489445.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[ORICO X50 Review: A Sleek Thunderbolt 5 SSD Enclosure]]></title>
      <description><![CDATA[A slim, silver NVMe enclosure that turns your spare SSD into fast external storage. Excellent if you have Thunderbolt 5 on your machine.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17486309/orico-x50-review</link>
      <guid isPermaLink="false">6ac2264b7834300001c577eb</guid>
      <category><![CDATA[Reviews]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Sun, 04 Oct 2026 17:33:33 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/orico-x50.jpg" medium="image"/>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/orico-x50.jpg" alt="" loading="lazy"></figure>
<p>A few months back, I reviewed the <a href="https://itsfoss.com/terramaster-d1-ssd-plus-review/">TerraMaster D1 SSD Plus</a> and liked it for what it offered. A sturdy box that gives a second life to an NVMe SSD lying around (rarity these days). </p><p>Now I have the <a href="https://oricotechs.com/products/orico-x50">ORICO X50</a> on my desk, which does the same job but promises twice the bandwidth with Thunderbolt 5.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-2.webp" class="kg-image" alt="ORICO X50 " loading="lazy" width="1000" height="750" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-2.webp 600w, https://itsfoss.com/content/images/2026/10/orico-x50-2.webp 1000w" sizes="(min-width: 720px) 720px"></figure><p>I ran the similar set of benchmarks on it on Ubuntu, and I have the numbers to share. </p><p>Here's a quick summary of my experience with the device.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-text">&#9989; Slim, good-looking aluminum body that's easy to carry<br>&#9989; Comes with an 80Gbps cable in the box<br>&#9989; Works out of the box on Linux, with full NVMe SMART data<br>&#9989; Stayed in the 60s &deg;C during a 13-minute sustained write<br>&#10062; Only 2280 NVMe SSDs; heatsink SSDs won't fit<br>&#10062; Priced well above USB4 enclosures</div></div><h2 id="orico-x50-thunderbolt-5-ssd-enclosure-specifications">ORICO X50 Thunderbolt 5 SSD enclosure specifications</h2><p>Here are the hardware specifications for ORICO X50.</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Specification</th>
<th>ORICO X50</th>
</tr>
</thead>
<tbody>
<tr>
<td><strong>Interface</strong></td>
<td>Thunderbolt 5 (80Gbps), backward compatible with Thunderbolt 4, Thunderbolt 3 and USB4</td>
</tr>
<tr>
<td><strong>Rated speed</strong></td>
<td>Up to 6000 MB/s read, 5800 MB/s write</td>
</tr>
<tr>
<td><strong>Supported SSD</strong></td>
<td>M.2 NVMe, 2280 size only (2230 not supported), M Key and B+M Key</td>
</tr>
<tr>
<td><strong>Recommended SSD</strong></td>
<td>PCIe Gen4 or Gen5</td>
</tr>
<tr>
<td><strong>Max capacity</strong></td>
<td>4TB</td>
</tr>
<tr>
<td><strong>Cooling</strong></td>
<td>Fanless, aluminum unibody with micro fins, thermal film and thermal paste</td>
</tr>
<tr>
<td><strong>Material</strong></td>
<td>Aluminum alloy</td>
</tr>
<tr>
<td><strong>Dimensions</strong></td>
<td>110 &times; 60 &times; 18.7 mm</td>
</tr>
<tr>
<td><strong>Cable</strong></td>
<td>0.5m USB-C to USB-C, 80Gbps</td>
</tr>
<tr>
<td><strong>OS support</strong></td>
<td>Windows, macOS, Linux</td>
</tr>
<tr>
<td><strong>Price</strong></td>
<td>$269.99 for the diskless version</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>ORICO also sells the X50 with a 512GB or 1TB SSD already installed. I got the empty enclosure, which is what most of you would want if you have an SSD to reuse. </p><p><strong>Pay attention to the supported SSD list</strong>. Like most enclosures of this kind, the X50 doesn't take everything. It's NVMe only, so your old SATA M.2 drive cannot be used, and it's 2280 only, so the tiny 2230 SSD in your stock won't be of much use either.</p><p>Also note that on Thunderbolt 4 hosts, the speed is limited to 40Gbps, and on Thunderbolt 3, it will drop even further.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">ORICO sent me this device for review. The views expressed are my own.</div></div><h2 id="design-and-build">Design and build</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-4.webp" class="kg-image" alt="Orico X50 SSD Enclosure" loading="lazy" width="1000" height="750" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-4.webp 600w, https://itsfoss.com/content/images/2026/10/orico-x50-4.webp 1000w" sizes="(min-width: 720px) 720px"></figure><p>The X50 is noticeably less bulky than the TerraMaster D1 SSD Plus. It's slim enough to slide into a laptop bag pocket. Although it is not as slim as my <a href="https://amzn.to/4htZNTT">Sandisk Extreme portable SSD</a>. </p><p>The silver aluminum finish looks good, and I think it would fit right into the Apple ecosystem as it matches the aesthetic.</p><p>Flip it over and you'll see fins running along the bottom. These increase the surface area for heat dissipation, and judging by my thermal numbers (more on that later), they seem to do their job. There's no fan, so it's completely silent.</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-1.jpg" class="kg-image" alt="Orico X50 bottom view" loading="lazy" width="1000" height="750" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-1.jpg 600w, https://itsfoss.com/content/images/2026/10/orico-x50-1.jpg 1000w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">Orico X50 bottom view</span></figcaption></figure><p>In the box, you get the enclosure, a fast 80Gbps USB-C cable and thermal paste. No SSD, of course, since I got the diskless version. A good cable matters with devices like these. Good of ORICO to include it in the box.</p><p>You can apply the thermal paste directly on the SSD. I did not. I wanted to take the raw numbers in the testing.</p><p>SSDs with an attached heatsink, like the <a href="https://amzn.to/4z8ZbZz">Samsung 9100 Pro Heatsink version</a>, won't fit inside the X50. Get the bare version of the SSD if you plan to use it with this enclosure.</p><h2 id="the-first-plug-in-experience">The first plug-in experience</h2><p>For my testing, I used a Crucial P3 Plus 500GB. It's a PCIe Gen4 drive rated at 4700 MB/s read and 1900 MB/s write, and it uses <a href="https://www.sandisk.com/topics/ssd/what-is-qlc">QLC NAND</a>. Keep the QLC part in mind; it matters for the sustained write results.</p><p>I tested the X50 on Ubuntu 26.04 with Linux kernel 7.0. It worked out of the box. Plugged it in, and the SSD shows up like any other drive. I formatted it as ext4 and it was mounted automatically. So, no surprises here.</p><p>Since it's a Thunderbolt device, it's worth checking with <code>boltctl</code>. It got authorized automatically and showed a 40 Gb/s link (2 lanes &times; 20 Gb/s). Interestingly, it identifies itself as "DM9002QN" from Shenzhen Dongman Technology rather than ORICO.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-boltctl.png" class="kg-image" alt="Orico X50 boltctl result" loading="lazy" width="1099" height="608" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-boltctl.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/orico-x50-boltctl.png 1000w, https://itsfoss.com/content/images/2026/10/orico-x50-boltctl.png 1099w" sizes="(min-width: 720px) 720px"></figure><p>Because the X50 tunnels PCIe over Thunderbolt, the drive shows up as a native NVMe device (<code>nvme1n1</code>), not a USB disk. That means <code>nvme smart-log</code> works directly and you get full <a href="https://linuxhandbook.com/check-ssd-health/">SMART</a> data, including temperature. No need to fiddle with USB bridge flags in <code>smartctl</code>.</p><p>This is definitely a plus for Linux users. With many USB enclosures, getting health data out of the SSD is often hit or miss.</p><h2 id="performance-the-numbers-and-the-big-caveat">Performance: the numbers and the big caveat</h2><p>Here's the thing. The X50 is a Thunderbolt 5 device, but I don't have a Thunderbolt 5 machine. My laptop is the ASUS Zenbook S14, which has Thunderbolt 4. So the link was capped at 40Gbps, half of what the X50 is designed for.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">These tests are limited by the host device. With a Thunderbolt 4 laptop, you are not seeing what the X50 can do at 80Gbps. Treat my numbers as "what you get with a Thunderbolt 4 or USB4 machine", which, honestly, is what most people have today.</div></div><p>This is often the case with storage benchmarks. The weakest link in the chain, be it the port, the cable or the SSD, decides the speed you see. The ORICO's rated 6000 MB/s needs both a Thunderbolt 5 host and a fast Gen4 or Gen5 SSD.</p><p>I used <a href="https://fio.readthedocs.io/en/latest/fio_doc.html">fio</a> for simulated tests, plus a couple of real file copy tests. Here are the results from the first run.</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Test</th>
<th>ORICO X50</th>
</tr>
</thead>
<tbody>
<tr>
<td>Sequential read</td>
<td>3878 MB/s</td>
</tr>
<tr>
<td>Sequential write</td>
<td>2810 MB/s</td>
</tr>
<tr>
<td>Random read (QD32)</td>
<td>1512 MB/s (369K IOPS)</td>
</tr>
<tr>
<td>Random write (QD32)</td>
<td>1175 MB/s (287K IOPS)</td>
</tr>
<tr>
<td>Random read (QD1)</td>
<td>59 MB/s (14.4K IOPS, 34 &micro;s latency)</td>
</tr>
<tr>
<td>Mixed 70% read / 30% write</td>
<td>1483 MB/s</td>
</tr>
<tr>
<td>10GB single file copy</td>
<td>11.8 seconds</td>
</tr>
<tr>
<td>5000 small files (4KB) copy</td>
<td>17.5 seconds</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>The sequential read of 3878 MB/s is pretty much the ceiling of a 40Gbps connection. Pay attention to bits and bytes. The enclosure maxed out what my laptop could offer. The sequential write of 2810 MB/s was well above the Crucial's rated 1900 MB/s, thanks to <a href="https://www.taimitech.com/news/160.html">SLC cache</a> handling the burst.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-benchmark.png" class="kg-image" alt="Orico X50 benchamrking results" loading="lazy" width="1800" height="975" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-benchmark.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/orico-x50-benchmark.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/orico-x50-benchmark.png 1600w, https://itsfoss.com/content/images/2026/10/orico-x50-benchmark.png 1800w" sizes="(min-width: 720px) 720px"></figure><p>I ran the tests a second time to check consistency. The read numbers were pretty much identical. Random write dropped to 978 MB/s and the 10GB copy took 17.8 seconds instead of 11.8. That's because the SSD's cache probably had not fully recovered from the earlier runs.</p><h3 id="thermal-performance-during-sustained-writing">Thermal performance during sustained writing</h3><p>To see how the X50 handles heat, I wrote 250GB in one go. It took a little over 13 minutes.</p><p>The speed fell from around 2700 MB/s to about 265 MB/s within the first few seconds and stayed there till the end. Before you blame the ORICO enclosure, this is classic QLC behavior. </p><p>Once the SLC cache is full, the Crucial P3 Plus writes at its native QLC speed. In the earlier shorter run with a fresh cache, it held about 2700 MB/s for nearly 19 seconds before falling off.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-sustained-write.png" class="kg-image" alt="Sustained writing test X50" loading="lazy" width="1800" height="975" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-sustained-write.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/orico-x50-sustained-write.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/orico-x50-sustained-write.png 1600w, https://itsfoss.com/content/images/2026/10/orico-x50-sustained-write.png 1800w" sizes="(min-width: 720px) 720px"></figure><p>Let's focus on the temperature. Throughout the 13-minute write, the SSD stayed between 58&deg;C and 68&deg;C, and mostly stayed around 62 to 65&deg;C. </p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/orico-x50-temperature.png" class="kg-image" alt="ORICO X50 SSD temperature test" loading="lazy" width="1800" height="975" srcset="https://itsfoss.com/content/images/size/w600/2026/10/orico-x50-temperature.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/orico-x50-temperature.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/orico-x50-temperature.png 1600w, https://itsfoss.com/content/images/2026/10/orico-x50-temperature.png 1800w" sizes="(min-width: 720px) 720px"></figure><p>There were no sudden dips in the speed graph that would indicate thermal throttling, at least that's what I would like to think. The fins and the paste seem to be doing their work. The room temperature was around 32&deg;C, I think.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#9989;</div><div class="kg-callout-text">The X50 kept the SSD in the 60 &deg;C range during a 250GB sustained write with no visible throttling. Thermally, it's well built.</div></div><h2 id="orico-x50-vs-terramaster-d1-ssd-plus">ORICO X50 vs TerraMaster D1 SSD Plus</h2><p>Since I had reviewed the TerraMaster D1 SSD Plus earlier, a comparison was only natural. I ran the same benchmark script on it, on the same Zenbook S14.</p><p>The tests are not indentical though because I used a different SSD in each. Crucial P3 Plus 500GB in the ORICO and the WD Blue SN5000 1TB in the TerraMaster. So this is not a pure enclosure vs enclosure comparison. Take the write numbers especially with a pinch of salt.</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th></th>
<th>ORICO X50</th>
<th>TerraMaster D1 SSD Plus</th>
</tr>
</thead>
<tbody>
<tr>
<td>Interface</td>
<td>Thunderbolt 5 (80Gbps)</td>
<td>USB4 (40Gbps)</td>
</tr>
<tr>
<td>Price</td>
<td>$269.99 (sale)</td>
<td>~$110</td>
</tr>
<tr>
<td>Max capacity</td>
<td>4TB</td>
<td>8TB</td>
</tr>
<tr>
<td>Size</td>
<td>Slim (110 &times; 60 &times; 18.7 mm)</td>
<td>Bulkier</td>
</tr>
<tr>
<td>SSD in my test</td>
<td>Crucial P3 Plus 500GB</td>
<td>WD Blue SN5000 1TB</td>
</tr>
<tr>
<td>Sequential read</td>
<td>3878 MB/s</td>
<td>3323 MB/s</td>
</tr>
<tr>
<td>Sequential write</td>
<td>2810 MB/s</td>
<td>3202 MB/s</td>
</tr>
<tr>
<td>Random read (QD32)</td>
<td>1512 MB/s</td>
<td>1588 MB/s</td>
</tr>
<tr>
<td>Random write (QD32)</td>
<td>1175 MB/s</td>
<td>1470 MB/s</td>
</tr>
<tr>
<td>Random read (QD1)</td>
<td>59 MB/s</td>
<td>64 MB/s</td>
</tr>
<tr>
<td>10GB file copy</td>
<td>11.8 s</td>
<td>6.2 s</td>
</tr>
<tr>
<td>5000 small files</td>
<td>17.5 s</td>
<td>17.1 s</td>
</tr>
<tr>
<td>Sustained write (250GB)</td>
<td>~265 MB/s after cache</td>
<td>~950 MB/s after cache</td>
</tr>
<tr>
<td>Peak SSD temperature</td>
<td>68&deg;C (13+ minutes of writing)</td>
<td>59&deg;C (about 3 minutes of writing)</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>On a 40Gbps connection, both enclosures are in the same league. The ORICO had the better sequential read, which is the best indicator of what the enclosure itself can push. The TerraMaster won on writes, but that's largely down to the WD SSD having a bigger cache and faster post-cache speed than my QLC Crucial.</p><p>Basically, on a Thunderbolt 4 or USB4 laptop, you won't see much practical difference between the two. The ORICO's extra money buys you a slimmer design and headroom for Thunderbolt 5. That also keeps you future proof for the next few years.</p><h2 id="is-orico-x50-worth-it">Is ORICO X50 worth it?</h2><p>If you have NVMe SSDs lying around and want to use them as fast external storage, the X50 is a good device. It's slim, looks good, stays cool, and works on Linux without any tinkering. The native NVMe access is a nice touch for those of us who like to check drive health from the terminal.</p><p>The 2280 only support is limiting. If you have a 2230 or 2242 SSD from an older laptop or a handheld, you can't use it here. And with no SATA support, older M.2 drives are out of the picture as well.</p><p>If you have a Thunderbolt 5 machine, or you are planning to buy one in the next year or two, the X50 is a future-proof pick. Pair it with a fast Gen4 or Gen5 TLC SSD to actually get near the advertised 6000 MB/s. </p><div class="kg-card kg-button-card kg-align-center"><a href="https://oricotechs.com/products/orico-x50" class="kg-btn kg-btn-accent">Explore ORICO X50</a></div><p>I could not test it at full Thunderbolt 5 speed. If you have a Thunderbolt 5 machine and use the X50, I'd love to hear your numbers in the comments.</p>
<img src="https://feed.itsfoss.com/link/24361/17486309.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[DigitalOcean Quietly Ends Open Source Credits Program]]></title>
      <description><![CDATA[Some project maintainers have received emails that they will no longer get any more free credits from Digital Ocean.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17486227/digitalocean-open-source-credits-end</link>
      <guid isPermaLink="false">6ac1c5547834300001c57643</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Sun, 04 Oct 2026 12:41:37 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/do-end-open-source-credit-program.webp" medium="image"/>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/do-end-open-source-credit-program.webp" alt="" loading="lazy"></figure>
<p>DigitalOcean is ending its Open Source Credits program quietly:</p><blockquote>DigitalOcean has decided to sunset the Open Source Credits Program. As part of this change, we are no longer accepting new credit applications or approving credit renewals, extensions, or additional credit requests.</blockquote><p>It came to highlight from a GitHub issue where the maintainers of the Node.js project received an email from DigitalOcean notifying them about the sunset of the Open Source Credits program.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">When we first published this story, it was a speculation. Now more projects have confirmed that they have received this closure email from DigitalOcean. The article has been edited since to reflect that fact.</div></div><h2 id="what-was-the-open-source-credits-program">What was the Open Source Credits program?</h2><p>DigitalOcean is a cloud server infrastructure provider. It ran this "Open Source Credits" program and under this scheme, they gave approved open-source projects cloud credits to cover infrastructure costs. This helped project maintainers run their projects without paying the hosting bill.</p><p>For example, Node.js used DigitalOcean infrastructure for its build operations, including virtual servers, storage, snapshots and backups.</p><p>For years, DigitalOcean promoted this program and invited projects to apply to this program by sending them a message via opensource@digitalocean.com.</p><p>This seems to have changed now.</p><h2 id="sunsetting-the-open-source-credits-program">Sunsetting the Open Source Credits program</h2><p>Note that there is no official announcement on DigitalOcean's blog or social media handles. The program is being ended quietly. </p><p>The problem came to light from this <a href="https://github.com/nodejs/build/issues/4499">GitHub issue where Node.js maintainers discuss</a> this email. </p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/do-ending-open-source-credit-program.webp" class="kg-image" alt="Digital Ocean ending its Open Source Credit Program" loading="lazy" width="1521" height="798" srcset="https://itsfoss.com/content/images/size/w600/2026/10/do-ending-open-source-credit-program.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/do-ending-open-source-credit-program.webp 1000w, https://itsfoss.com/content/images/2026/10/do-ending-open-source-credit-program.webp 1521w" sizes="(min-width: 720px) 720px"></figure><p>There is <a href="https://www.reddit.com/r/digital_ocean/comments/1wuhlmf/open_source_credits_ending/">also a Reddit thread</a>, but the OP doesn't mention if they received the email themselves or which open source project they maintained.</p><p>Earlier, I had scanned Reddit, X and some other social media platforms, but there was not enough chatter about it. But more developers have confirmed receiving this email.</p><p>Gray, lead developer of Pidgin messenger, shared <a href="https://mastodon.social/@grimmy/117362067932906699">this on Mastodon</a>:</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/pidgin-do-email.webp" class="kg-image" alt="Pidgin dev received the DO email on the open source credits program" loading="lazy" width="983" height="741" srcset="https://itsfoss.com/content/images/size/w600/2026/10/pidgin-do-email.webp 600w, https://itsfoss.com/content/images/2026/10/pidgin-do-email.webp 983w" sizes="(min-width: 720px) 720px"></figure><p>Projects in the program won't receive new credits. The will have to manage with whatever credits that have been issued so far. After that, either they pay to DigitalOcean or move their projects to some other platform provider.</p><p>The mail also mentions that new projects will no longer be accepted in the program and the inbox (opensource@digitalocean.com) dedicated for this task will no longer be monitored. That closes the door for new applicants.</p><h3 id="a-mutual-partnership">A mutual partnership</h3><p>Programs such as this are a mutually beneficial arrangement. When DigitalOcean offered credits, these projects spun up their CI runners, their documentation sites, their release mirrors, and their testing environments on DigitalOcean infrastructure.</p><p>In return, they mentioned DigitalOcean in the project website and documentation. Thousands of developers learned about DigitalOcean's platform through these projects. Some become paying customers individually, whereas some bring it into the companies they worked for.</p><p>Both involved parties get something positive from Open Source Credits like programs.</p><h2 id="digitalocean-has-been-reducing-its-free-offering">DigitalOcean has been reducing its free offering</h2><p>This is not the first time DigitalOcean has trimmed its community-facing programs without a clear announcement. </p><p><a href="https://www.reddit.com/r/digital_ocean/comments/1u412e1/digitalocean_ends_github_student_pack/">Earlier this year</a>, the GitHub Student Pack credits were removed from DigitalOcean's offerings too. Students trying to redeem the standard $200 in free credits found they were no longer receiving them. Again, there were no formal announcements (because it is a bad outlook). So all you will find is community questions by confused users.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/digitalocean-student-pack-withdrawl.webp" class="kg-image" alt="DigitalOcean ends GitHub student pack participation" loading="lazy" width="1253" height="499" srcset="https://itsfoss.com/content/images/size/w600/2026/10/digitalocean-student-pack-withdrawl.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/digitalocean-student-pack-withdrawl.webp 1000w, https://itsfoss.com/content/images/2026/10/digitalocean-student-pack-withdrawl.webp 1253w" sizes="(min-width: 720px) 720px"></figure><p><a href="https://m.do.co/c/d58840562553">DigitalOcean offers $100 free credit</a> (our partner link) to every new user. This program still runs today (so far). Not sure how long this will be offered, though.</p><h2 id="node-got-digitalocean-support-back">Node got DigitalOcean support back</h2><p>In the <a href="https://github.com/nodejs/build/issues/4499">same GitHub issue</a>, Node developers discussed their exit strategy. It then led to a discussion of removing DigitalOcean from the homepage, README and partners page.</p><p>And as soon as that happened, Digita Ocean reached out with olive branch.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/twitter-do-credit-issue.webp" class="kg-image" alt="" loading="lazy" width="971" height="1143" srcset="https://itsfoss.com/content/images/size/w600/2026/10/twitter-do-credit-issue.webp 600w, https://itsfoss.com/content/images/2026/10/twitter-do-credit-issue.webp 971w" sizes="(min-width: 720px) 720px"></figure><p>Notice the use of "what version 2.0 of the program looks like" line? This is either a coverup strategy or an actual revamp of the existing program that will be more selective about which projects will be allowed in the program. </p><p>The GitHub issue was then promptly renamed from "Transitioning off of Digital Ocean" to "Solidify Digital Ocean Partnership".</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/node-digita-ocean-credit-discussion-1.webp" class="kg-image" alt="" loading="lazy" width="1524" height="661" srcset="https://itsfoss.com/content/images/size/w600/2026/10/node-digita-ocean-credit-discussion-1.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/node-digita-ocean-credit-discussion-1.webp 1000w, https://itsfoss.com/content/images/2026/10/node-digita-ocean-credit-discussion-1.webp 1524w" sizes="(min-width: 720px) 720px"></figure><h2 id="but-they-still-got-millions-to-giveaway">But they still got millions to giveaway</h2><p>It would have made sense if DigitalOcean was facing any financial constrained and this was an attempt to cut down on the expenses.</p><p>But that certainly is not the case because only a few weeks ago, <a href="https://omarchy.org/news/2026/09/digitalocean-joins-as-founding-corporate-patron/">DigitalOcean donated $3 million to the Omacom Foundation</a> (the official organization behind Omarchy Linux).</p><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://itsfoss.com/content/images/2026/10/digital-ocean-omarchy.png" class="kg-image" alt="DigitalOcean gave away $3 million to Omacom Foundation" loading="lazy" width="1348" height="533" srcset="https://itsfoss.com/content/images/size/w600/2026/10/digital-ocean-omarchy.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/digital-ocean-omarchy.png 1000w, https://itsfoss.com/content/images/2026/10/digital-ocean-omarchy.png 1348w" sizes="(min-width: 720px) 720px"><figcaption><span style="white-space: pre-wrap;">DigitalOcean gave $3 million to Omarchy Linux</span></figcaption></figure><p>It looks like DigitalOcean gave away all of its open source community budget to Omarchy? That most certainly is not the case.</p><h2 id="other-open-source-projects-might-not-be-lucky">Other open source projects might not be lucky</h2><p>Here's what's happening, in my opinion.</p><p>Free and Open Source Software movement started in the 80s. It started catching up in the mid- to-late 90s, but it was not as lucrative to coprporates because it contained "free" in its name.</p><p>So Open Source was extracted from it and enterprises liked this term over FOSS. From mid 2000s, open source 'ruled' the industry for 20 years. Companies earned brownie points for associating themselves with open source in any way possible.</p><p>They liked the idea that a community of developers worked collectively on a project that could have been utilized by them in one way or another.</p><p>In the age of AI, open source doesn't have the same edge anymore. AI can generate software on demand, can handle the works of tens or even hundreds of developers. Enterprises don't need to rely on open-source projects as much as they did in the past.</p><p>Python, Node and many other projects that AI workflow rely on still get support from corporations. But smaller, end user facing projects and the legacy ones with no usage for AI will be neglected. </p><h2 id="what-next-for-impacted-projects">What next for impacted projects?</h2><p>Node.js is a big project popular with developers of all kinds. Getting their name and link removed when their competitors, like Vercel, are still mentioned on Node.js homepage is something DigitalOcean could not afford.</p><p>But not all open source projects are going to get that kind of happy ending. The smaller projects are going to think about infrastructure bills and move.</p><p>When maintainers are already <a href="https://daniel.haxx.se/blog/2025/07/14/death-by-a-thousand-slops/">drowning in AI slop</a> pull requests and bug reports, this is going to put additional strain on the maintainers. </p><p>Gary Kramlich, Pidgin lead developer, told It's FOSS that he hadn't actually gotten credits from DigitalOcean for over a year and he had been paying from his own pockets. </p><blockquote>...we're trying to find other sponsored hosting or a colo sponsorship or anything really. But in the meantime we're re-evaluating everything we're running and cutting things...</blockquote><p>Hopefully, some newer infrastructure providers will come up with similar programs. No harm in thinking positive.</p><p><em>If you are an open source project maintainer who got this Open Source Credits program closure email, please reach out to us.</em></p>
<img src="https://feed.itsfoss.com/link/24361/17486227.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[We View Consumer Data as Toxic Waste]]></title>
      <description><![CDATA[Obscura VPN splits your identity from your browsing across two independent companies so neither can see both. Founder Carl Dong on trust, QUIC, reproducible builds, and why the no-logs promise stopped being enough.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17484548/obscura-carl-dong</link>
      <guid isPermaLink="false">6ac09a607834300001c57212</guid>
      <category><![CDATA[Interview🎙️]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Sat, 03 Oct 2026 13:17:16 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/obscura-carl-dong-1-.webp" medium="image">
        <media:description type="plain">Obscura VPN's Carl Dong</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/obscura-carl-dong-1-.webp" alt="Obscura VPN&#039;s Carl Dong" loading="lazy"></figure>
<p>The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.</p><p>For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.</p><p><a href="https://obscura.com/">Obscura VPN</a> is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by <a href="https://mullvad.net/en">Mullvad</a>. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.</p><p>The person behind it is <a href="https://www.linkedin.com/in/carldong/" rel="noreferrer">Carl Dong</a>, a former top-5 Bitcoin Core contributor who signs off his own website as "head-janitor" and "I fight for the users." I sent him a set of questions around Obscura. Here's the conversation.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/obscura-carl.webp" class="kg-image" alt="Obscura team" loading="lazy" width="1200" height="1200" srcset="https://itsfoss.com/content/images/size/w600/2026/10/obscura-carl.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/obscura-carl.webp 1000w, https://itsfoss.com/content/images/2026/10/obscura-carl.webp 1200w" sizes="(min-width: 720px) 720px"></figure><h3 id="you-went-from-being-a-top-contributor-to-bitcoin-core-to-founding-a-vpn-company-what-convinced-you-the-vpn-space-needed-rebuilding-rather-than-just-improving">You went from being a top contributor to Bitcoin Core to founding a VPN company. What convinced you the VPN space needed rebuilding rather than just improving?</h3><p>"Don't Trust, Verify" is a cornerstone of the cypherpunk principles I grew up with. I see this Trust Minimization as crucial when building human-centric, security- and privacy-critical technologies. Yet the VPN industry is riddled with scandals (e.g., Onavo), broken promises, and "no-log" pinky promises. This never sat right with me.</p><p>When I saw what Apple's iCloud Private Relay was doing under the hood, I saw what the next generation of VPNs would look like: VPNs that are verifiably private and that outsmart internet censorship. I wanted to make this a reality outside of Apple's walled garden. The world doesn't need another VPN company; it needs a totally new approach to privacy.</p><h3 id="your-whole-pitch-takes-direct-aim-at-the-no-logs-model-everyone-else-uses-why-has-that-promise-become-inadequate">Your whole pitch takes direct aim at the "no-logs" model everyone else uses. Why has that promise become inadequate?</h3><p>The VPN industry is living in the past. Three conglomerates dominate and give the illusion of choice, while betraying their users' trust and operating a payola scheme using media cut-outs to push their talking points. The no-logs pinky-promise has never been adequate for software that can access the entirety of your internet traffic, and verges on being useless in 2026 when LLM-driven cyberattacks run rampant.</p><p>At the end of the day, even honest VPN providers who abide by their no-logs policy can be hacked. Users are waking up to this, and there's been an increasing call within the cybersecurity community to stop using VPNs altogether. Obscura is a direct answer to this: you no longer have to trust any single company's word for your internet privacy. That's the way it should have always been.</p><h3 id="walk-our-readers-through-the-two-party-relay-in-plain-terms-how-does-it-actually-change-the-trust-model-compared-to-a-normal-multi-hop-vpn">Walk our readers through the two-party relay in plain terms. How does it actually change the trust model compared to a normal multi-hop VPN?</h3><p>When you use a traditional VPN, a single company sees your identity (via your connecting IP + your payment information) and your internet traffic. Using a multi-hop option doesn't change the fact that it's still a single company, and oftentimes just adds additional latency for no good reason.</p><p>With Obscura's Two-Party Relay, we use a fully independent company (Mullvad) as our second exit hop, with Obscura as the first hop. All of your internet traffic is encrypted to a key controlled by Mullvad's servers, and only relayed through Obscura's servers. That way, Obscura's relay servers never see your actual internet traffic, and Mullvad's exit servers never see your identity (connecting IP or payment information).</p><p>For those familiar with Tor, it's like if Tor only had 2 hops, but the hops were dedicated, high-performance hops optimized for maximum speed and reliability.</p><h3 id="a-skeptic-could-say-youve-just-moved-the-trust-problem-around-now-users-trust-two-companies-instead-of-one-and-the-two-of-you-could-collude-or-be-compelled-together-how-do-you-respond">A skeptic could say you've just moved the trust problem around. Now users trust two companies instead of one, and the two of you could collude or be compelled together. How do you respond?</h3><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/obscura-2-hops.png" class="kg-image" alt="Obscura 2 hops" loading="lazy" width="2000" height="570" srcset="https://itsfoss.com/content/images/size/w600/2026/10/obscura-2-hops.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/obscura-2-hops.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/obscura-2-hops.png 1600w, https://itsfoss.com/content/images/2026/10/obscura-2-hops.png 2011w" sizes="(min-width: 720px) 720px"></figure><p>I'd first lightheartedly point out that using traditional VPNs is just moving trust from your (possibly regulated) ISP to a single wholly unregulated private company. &#128518;</p><p>In all seriousness though, our goal with Obscura is to make sure there's no single party that can jeopardize your internet privacy. No one entity should have that power. With Obscura, as long as either Obscura or Mullvad isn't compromised, no one can correlate your personal identity with your internet activity. This is strictly better than trusting either your ISP or a traditional VPN's pinky-promise.</p><h3 id="lets-get-technical-your-stealth-protocol-is-built-on-quic-to-mimic-http3-traffic-why-quic-specifically-and-how-does-it-hold-up-against-serious-censorship">Let's get technical. Your stealth protocol is built on QUIC to mimic HTTP/3 traffic. Why QUIC specifically, and how does it hold up against serious censorship?</h3><p>We chose QUIC not only because it looks like HTTP/3, but also because its Unreliable Datagram extension allows us to avoid the TCP-over-TCP meltdown problem that plagues TCP-based VPNs. I'd encourage folks to <a href="https://obscura.com/blog/bootstrapping-trust/#obfuscation-without-tcp-over-tcp-meltdown">read this for more details</a>.</p><p>As for outsmarting censorship, QUIC has been notably harder for middleboxes to do Deep Packet Inspection on. QUIC allows messages to be fragmented and shuffled across UDP datagrams, which means censorship systems have to reassemble them, making it far more costly. I don't know of any QUIC censorship system currently deployed that does reassembly. <a href="https://gfw.report/publications/usenixsecurity25/en/#sec:7-circumvention">More information can be found here</a>.</p><h3 id="you-accept-monero-and-bitcoin-over-lightning-need-no-email-and-log-in-with-just-a-random-account-number-but-obscura-still-sees-the-users-connecting-ip-how-anonymous-can-a-user-really-be-and-wheres-the-honest-limit">You accept Monero and Bitcoin over Lightning, need no email, and log in with just a random account number. But Obscura still sees the user's connecting IP. How anonymous can a user really be, and where's the honest limit?</h3><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/obscura-payment-methods.png" class="kg-image" alt="Obscura payment methods" loading="lazy" width="2000" height="659" srcset="https://itsfoss.com/content/images/size/w600/2026/10/obscura-payment-methods.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/obscura-payment-methods.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/obscura-payment-methods.png 1600w, https://itsfoss.com/content/images/size/w2400/2026/10/obscura-payment-methods.png 2400w" sizes="(min-width: 720px) 720px"></figure><p>We view consumer data as toxic waste. We don't want it, don't need it, and do as much as possible to make sure you don't have to give us any. Aside from what you mentioned, our website is also accessible over Tor.</p><p>But you're absolutely right. We can still see the user's connecting IP address. That will not change unless humanity completely rethinks the OSI stack, which will make the IPv6 transition look like a walk in the park. &#128518;</p><p>The fact that we can't avoid seeing your connecting IP address is the point of Obscura though: if we have to see it, then the most private thing to do is to completely decouple that information from your internet traffic. That's what our Two-Party Relay does.</p><h3 id="youve-open-sourced-the-client-and-talk-a-lot-about-reproducible-builds-clearly-something-you-carried-over-from-bitcoin-core-for-a-non-developer-why-do-reproducible-builds-matter-for-a-vpn">You've open-sourced the client and talk a lot about reproducible builds, clearly something you carried over from Bitcoin Core. For a non-developer, why do reproducible builds matter for a VPN?</h3><p>I did a lot of reproducible builds work for Bitcoin Core, so this is near and dear to my heart. I believe that reproducible builds matter for any piece of open-source security-critical software. Even if the published source code is not malicious, that says nothing about the app you download. It essentially answers this question: does the app that I download correspond to the source code that is on GitHub (or whatever other forge you may use).</p><p>For Bitcoin Core, a malicious app could mean loss/theft of funds. For VPNs, a malicious app has access to the entirety of your internet traffic and can leak that regardless of the security of your VPN provider.</p><p>At Obscura, we of course take reproducible builds seriously. We already have a prototype for Android reproducible builds, and are looking to make other platforms work as well.</p><h3 id="obscura-is-8month-and-reviewers-note-that-stacking-two-providers-can-cost-more-than-one-beyond-the-privacy-story-how-do-you-make-the-economics-work-as-a-small-team-without-vc-pressure-to-monetize-users">Obscura is $8/month, and reviewers note that stacking two providers can cost more than one. Beyond the privacy story, how do you make the economics work as a small team without VC pressure to monetize users?</h3><p>First, we have no user data to monetize. Second, I think in the tech world we've vastly overcomplicated our businesses. For a business to work, you need your costs to be lower than your revenue over time. That's it. We aren't going to construct a massive data center. We aren't going to put tens of millions into R&amp;D in a lab in Switzerland. We're a small group of six people, working remotely, charging fair prices. As long as we keep our customers happy, we don't have anything to worry about. My goal was never to compare yachts with Bezos.</p><h3 id="theres-a-classic-tension-between-maximum-privacy-and-everyday-usability-with-tor-as-the-usual-cautionary-tale-where-do-you-draw-that-line">There's a classic tension between maximum privacy and everyday usability, with Tor as the usual cautionary tale. Where do you draw that line?</h3><p>The goal is for my mom to use Obscura, and she does! (Hopefully not just because I'm her son.)</p><p>I don't think that tension between privacy and usability is always inherent: a VPN doesn't have to be complicated. You should flip a switch and it should just work and you should forget you have it on. The goal is to be seamless. Power users and technical folks who want more should always have the ability to tinker, and we offer that, but the goal is to build a product so good that both feel right at home.</p><p>Oftentimes we've also found that giving users a choice is the way to go: while cryptocurrencies may be the most private way to pay for Obscura, my mom is likely to want a credit card option. &#128516;</p><h3 id="looking-at-the-next-few-years-with-encryption-under-legislative-pressure-and-tracking-everywhere-what-worries-you-most-about-online-privacy">Looking at the next few years, with encryption under legislative pressure and tracking everywhere, what worries you most about online privacy?</h3><p>Every day there is another story about a country or international body proposing new rules that jeopardize the open and free internet we all love. Sometimes these are well-meaning protections that legislators don't fully grasp the ramifications of; other times their motivations are less noble.</p><p>What all these scenarios have in common is that, somewhere along the way, behavior that was once considered odd and Orwellian became normalized. You go grab a coffee and you give them your phone number, then you download an app (and allow location permissions), and before you know it companies know every aspect of your life.</p><p>Then when you read about how the government can legally purchase this data from data brokers, you start to appreciate just how much of your life can be reconstructed to where you essentially have given away every aspect of your privacy for a free coffee on your birthday. (I'm as guilty as anyone.) So what really worries me is our own complicity in trading privacy for convenience. And I hope with Obscura and other smaller privacy-focused start-ups we can make an easier, simpler to use tech that helps protect people and allows them to make better privacy decisions where there is no trade-off between convenience and privacy.</p><h3 id="finally-a-fun-one-your-site-has-a-cursed-knowledge-page-whats-the-most-cursed-thing-youve-learned-about-how-the-internet-actually-works-since-starting-obscura">Finally, a fun one. Your site has a "<a href="https://obscura.com/cursed-knowledge/">Cursed Knowledge</a>" page. What's the most cursed thing you've learned about how the internet actually works since starting Obscura?</h3><p>I think the TLS SNI extension has gotta be one of the most cursed things about how the internet works.</p><p>Most people assume that if a connection is encrypted by TLS, then it's fully encrypted. What they don't know is that there's a part of every TLS connection called the SNI where the server's domain name is in plaintext, completely unencrypted! In fact, ISPs and middleboxes often use this as a way to enact internet censorship, since it's a much more reliable mechanism than trying to match connections with DNS requests.</p><p>Last year, Obscura was erroneously blocked by a few US ISPs, and SNI was exactly what they used. Of course, using a VPN protects you against that, but it's still quite cursed that TLS has this at all. Hopefully Encrypted Client Hello gets adopted soon so that we can have actual secure TLS!</p><hr><p>Whether Obscura's split-trust model is right for you is up to you to decide, but it's definitely a different approach to a problem the VPN world has glossed over for years. The client is open source, so you don't have to take any of this on faith. You can read the code, check your exit hop's key against Mullvad's published list, and verify the claims yourself.</p><p>You can learn more at <a href="https://obscura.com/">obscura.com</a>, and the source is up on <a href="https://github.com/Sovereign-Engineering/obscuravpn-client">GitHub</a>.</p>
<img src="https://feed.itsfoss.com/link/24361/17484548.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[YT-DLP is Being Treated as a Piracy Tool By The IFPI]]></title>
      <description><![CDATA[Their submission to the EU's piracy watchlist places the open source tool in the same category as illegal downloading websites.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17483251/yt-dlp-ifpi-piracy-watchlist</link>
      <guid isPermaLink="false">6abe26737834300001c4af03</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Thu, 01 Oct 2026 20:55:37 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/yt-dlp-ifpi-banner.png" medium="image"/>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/yt-dlp-ifpi-banner.png" alt="" loading="lazy"></figure>
<p><a href="https://github.com/yt-dlp/yt-dlp">yt-dlp</a> has over 195,000 stars on GitHub, supports thousands of platforms, and is actively maintained by a global developer community. Unfortunately, the <a href="https://www.ifpi.org">IFPI</a> would like to see it on the EU's piracy watchlist.</p><p>Just so you know, the International Federation of the Phonographic Industry (IFPI) represents around 8,000 music labels across 70 countries.</p><p>In its submission to the EU's <a href="https://policy.trade.ec.europa.eu/consultations/public-consultation-counterfeit-and-piracy-watch-list-2_en">Counterfeit and Piracy Watch List</a> consultation, the group calls yt-dlp "<em>a major problem for the music industry</em>" and names four of its maintainers by their GitHub handles.</p><h2 id="a-piracy-watch-list">A Piracy Watch List?</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/eu-counterfeit-piracy-watch-list.png" class="kg-image" alt="eu's public consultation on the counterfeit and piracy watch list webpage showing some key details" loading="lazy" width="1068" height="757" srcset="https://itsfoss.com/content/images/size/w600/2026/10/eu-counterfeit-piracy-watch-list.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/eu-counterfeit-piracy-watch-list.png 1000w, https://itsfoss.com/content/images/2026/10/eu-counterfeit-piracy-watch-list.png 1068w" sizes="(min-width: 720px) 720px"></figure><p>Run by the European Commission's Directorate-General for <a href="https://commission.europa.eu/about/departments-and-executive-agencies/trade-and-economic-security_en">Trade and Economic Security</a>, the Watch List identifies online services and physical marketplaces outside the EU reported to engage in or facilitate copyright infringement.</p><p>While it sounds serious, the undertaking isn't meant to gather legal findings and does not mandate any form of direct action. It's closer to a naming exercise intended to pressure operators and governments outside the EU into addressing the identified services.</p><p>The 2027 edition is being compiled from submissions received through September 2026, with the final list expected in Q2 2027.</p><h2 id="what-does-their-submission-say">What does their submission say?</h2><p>IFPI's submission <a href="https://circabc.europa.eu/ui/group/e9d50ad8-e41f-4379-839a-fdfe08f0aa96/library/e53b2892-0fcb-4405-b8ac-75c02d8273e8/details">covers a wide range</a> of copyright enforcement concerns, from AI music generators and <a href="https://nordvpn.com/cybersecurity/glossary/cyberlocker/">cyberlockers</a> to streaming fraud services and domain registrars. yt-dlp appears under the "<em>stream ripping</em>" section, grouped with commercial websites like <em>Y2mate</em> and <em>Savefrom</em>.</p><p>They describe the tool as an application that retrieves content by parsing web page data and interacting with platform playback endpoints, with GitHub serving as the primary delivery method for its source code, pre-compiled binaries, and installation instructions.</p><p>IFPI names four of the project's maintainers by their GitHub handles: <a href="https://github.com/pukkandan">pukkandan</a>, who founded the project and led it between 2021 and 2024, and some core maintainers mentioned in the project's <a href="https://github.com/yt-dlp/yt-dlp/blob/master/Maintainers.md" rel="noreferrer">Maintainers.md</a> file, like <em>coletdjnz</em>, <em>bashonly</em>, and <em>Grub4K</em>.</p><p>The same submission also flags <em>X</em>, <em>Discord</em>, <em>Telegram</em>, and <em>Vimeo</em> as platforms facilitating copyright infringement at scale.</p><h2 id="its-a-tool-not-a-service">It's a tool, not a service</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/yt-dlp-github-repo.png" class="kg-image" alt="the yt-dlp github repo" loading="lazy" width="1856" height="779" srcset="https://itsfoss.com/content/images/size/w600/2026/10/yt-dlp-github-repo.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/yt-dlp-github-repo.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/yt-dlp-github-repo.png 1600w, https://itsfoss.com/content/images/2026/10/yt-dlp-github-repo.png 1856w" sizes="(min-width: 720px) 720px"></figure>
<!--kg-card-begin: html-->
<div class="repo-stats" data-repo="https://github.com/yt-dlp/yt-dlp"></div>
<!--kg-card-end: html-->
<p>The Watch List, as described by the European Commission, targets online service providers and physical marketplaces located outside the EU. <strong>yt-dlp fits neither description in any conventional sense</strong>.</p><p>IFPI acknowledges this by noting that the project's open source nature, its <a href="https://unlicense.org">Unlicense</a> licensing, and an extensive international developer community make it "<em>difficult to contain and/or remove</em>."</p><p>From their point of view, there's no central domain to block, no payment processor to cut off, and no hosting provider to strongarm into complying with a takedown request.</p><p>The source code is distributed globally and can be compiled by anyone with the skills to do so. But <strong>that doesn't mean yt-dlp is a piracy platform</strong>.</p><p>It's a command-line tool for downloading audio and video content, and categorizing it alongside dedicated ripping or piracy websites conflates a general-purpose downloader with services whose primary purpose is facilitating unauthorized copying.</p><h2 id="closing-thoughts">Closing thoughts</h2><p>The Watch List has been used in connection with enforcement against commercial stream-ripping platforms before.</p><p><em>Y2mate.com</em> and eleven other stream-ripping sites <a href="https://www.ifpi.org/ifpi-shuts-down-y2mate-com-and-11-other-major-stream-ripping-sites-in-landmark-action-in-vietnam/" rel="noreferrer">were shut down in Vietnam</a> in 2025, and Y2mate had previously appeared on the list.</p><p>Before that, in 2024, <a href="https://www.heise.de/en/news/OLG-Hamburg-Uberspace-liable-for-hosting-Youtube-DL-10179284.html" rel="noreferrer">a German court</a> held the host provider for <em>youtube-dl.org</em> liable in connection with facilitating circumvention. This shows that grouping an open source command-line tool with those commercial services in the same breath does not, by itself, make the tool one of those.</p><p><em>Via: </em><a href="https://torrentfreak.com/ifpi-wants-open-source-youtube-downloader-yt-dlp-on-eu-piracy-watch-list/"><em>TorrentFreak</em></a></p>
<img src="https://feed.itsfoss.com/link/24361/17483251.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[FOSS Weekly #26.40: NixOS is European Choice, Firefox Nova and Features, Free Terminal Course, Homelab Improvements and More]]></title>
      <description><![CDATA[European governments are betting on NixOS to reduce their dependency on big tech.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17483196/foss-weekly-26-40</link>
      <guid isPermaLink="false">6abcc37a6214c9000176ab8c</guid>
      <category><![CDATA[Newsletter ✉️]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Thu, 01 Oct 2026 18:36:54 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/foss-weekly.webp" medium="image">
        <media:description type="plain">FOSS Weekly</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/foss-weekly.webp" alt="FOSS Weekly" loading="lazy"></figure>
<p>Canonical is moving Ubuntu's kernel update cycle <a href="https://itsfoss.com/news/ubuntu-kernel-sru-cycle-update/">from four weeks to two</a>, with the expected result being a kernel release landing every week due to cycle overlap. They did this because AI-assisted vulnerability hunting is causing CVEs to land faster than the old timeline could respond to.</p><p>They have also enabled <a href="https://lists.ubuntu.com/archives/ubuntu-announce/2026-September/000328.html">upgrades from Ubuntu 24.04 LTS to Ubuntu 26.04.1</a>. And the delayed beta release of Ubuntu 26.10 should arrive today.</p><p>AlmaLinux <a href="https://itsfoss.com/news/almalinux-software-certification-launched/">now has software certification</a>, which means publishers can list products and users can confirm what runs on their hardware, with everything going into a public catalog with a free read-only API facilitating bulk data export.</p><p>GhostBSD's lead developer is building <a href="https://itsfoss.com/news/ghostbsd-new-desktop/">a new desktop called Mocka</a> to eventually replace MATE. It is built from scratch with no shared code from the MATE project, and the name comes from a typo. </p><p><a href="https://itsfoss.com/news/postmarketos-nura-rebranding/">postmarketOS is now Nura</a>. The rename has been in the works since March 2025, drew over 300 community submissions, and went through a trademark review and a vote before it was finalized. On the same note, <a href="https://itsfoss.com/news/f-droid-revamp/">F-Droid has a major revamp</a>. In case you did not know, F-Droid is the FOSS alternative to Google Play Store.</p><p>openSUSE is consolidating its distro lineup. Leap Micro, the separate immutable flavor for container and edge workloads, is going away, and <a href="https://itsfoss.com/news/opensuse-leap-immutable/">Leap 16.1 absorbs its functionality</a> via an optional installer mode.</p><p><strong>This edition of FOSS Weekly is supported by </strong><a href="https://dawarich.app/"><strong>Dawarich</strong></a><strong>, an open source alternative to Google Timeline.</strong></p>
<!--kg-gated-block:begin nonMember:true memberSegment:"status:free" --><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal    " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p dir="ltr"><span style="white-space: pre-wrap;">Dawarich is a private alternative to Google Timeline.</span><br><br><span style="white-space: pre-wrap;">Google killed browser Timeline and is limiting data retention. You can import your entire location history into Dawarich in minutes. It is private and encrypted. No ads. No data selling.</span><br><br><span style="white-space: pre-wrap;">It is open source and can also be self-hosted. Or, you can opt for their encrypted service.</span></p>
                        </div>
                    
                    
                        <a href="https://dawarich.app/" class="kg-cta-button " style="background-color: #000000; color: #ffffff;">
                            Try Dawarich Today
                        </a>
                        
                    </div>
                
            </div>
        </div><!--kg-gated-block:end-->
<h2 id="%F0%9F%A7%A0-what-we%E2%80%99re-thinking-about">&#129504; What We&rsquo;re Thinking About</h2><p>The Netherlands is building <a href="https://itsfoss.com/news/netherlands-dawo-initiative/">a NixOS-powered work environment</a> after watching Microsoft cut off ICC access in 2025. Though it turns out France's digital agency <a href="https://itsfoss.com/news/france-nixos-move/">had beat them to it</a>, already running their own version of NixOS on internal workstations.</p><h2 id="%F0%9F%90%A7-tuxdle-is-rising">&#128039; Tuxdle is rising</h2><p>Last week I shared my weekend project, <a href="https://tuxdle.com/">Tuxdle</a>. It's a word game where you have to guess the Linux term within six attempts. The game has gained good popularity. We are getting more than 500 plays every day. A good number for a game that is less than a week old.</p><p>I have made some enhancements to the game. You can see your stats and you can also see stats on the day's puzzle. That tells you how many people played the game and how many people actually solved it. Streak badges have also been added. </p><p>Want more fun and challenges? On Linux Handbook, we have <a href="https://linuxhandbook.com/ctf/command-conqueror/">created a fun Capture the Flag game</a>. You have 10 levels to solve. When you solve a level, the next level gets unlocked. The challenges run in custom docker containers. Everything on your system really. No sign up is needed.</p><h2 id="%F0%9F%A7%AE-linux-tips-tutorials-and-learnings">&#129518; Linux Tips, Tutorials, and Learnings</h2><p>I am also enhancing the user experience on the It's FOSS website. One of the first things I did was organize the series/courses in a proper format.</p><p>If you visit the <a href="https://itsfoss.com/linux-terminal-basics/">terminal course</a> or <a href="https://itsfoss.com/bash-scripting-tutorial/" rel="noreferrer">bash scripting course</a>, you will see the chapters in the series in the left sidebar. This will give you easier navigation.</p><p>There are many Linux distros that don't provide a dock by default, and if you want one, there's no dearth of options: Latte for KDE users, Cairo for old-school animations, and Dash to Dock for GNOME users; <a href="https://itsfoss.com/best-linux-docks/">there's something for every taste and desktop setup</a>.</p><p>You've seen "<em>upstream</em>" and "<em>downstream</em>" in patch notes, bug trackers, and forum replies without it ever being fully explained. We have already tackled <a href="https://itsfoss.com/upstream-and-downstream-linux/">what the terms actually mean</a>, both for the kernel and for applications, and why it matters when you're deciding where to file a bug report.</p><h2 id="%F0%9F%91%B7-ai-homelab-and-hardware-corner">&#128119; AI, Homelab and Hardware Corner</h2><p>One of the biggest annoyances of homelab is accessing services by using IP address and port number. I fixed this by <a href="https://itsfoss.com/homelab-internal-domain-setup/" rel="noreferrer">giving a custom domain name to every service I run</a>. I used AdGuard as DNS and Nginx Proxy Manager for reverse proxy. And the end result is that I can use Jellyfin by typing jellyfin.internal instead of typing 192.168.0.23:8097.</p><p>Most SBC projects end with your drawer filling up with HATs for different use cases. Vicharak's <a href="https://itsfoss.com/news/vicharak-axon-lite/">Axon-Lite tries a different approach</a> where it offers swappable interface modules for voice, vision, sensing, and AI data.</p><h2 id="%E2%9C%A8-apps-and-projects-highlights">&#10024; Apps and Projects Highlights</h2><p>Firefox's <a href="https://itsfoss.com/news/firefox-nova-redesign/">Nova redesign is finally here</a>, and it looks good! There's also a neat toggle for anyone who doesn't prefer it's pill-shapedness.</p><h2 id="%F0%9F%93%BD%EF%B8%8F-videos-for-you">&#128253;&#65039; Videos for You</h2><p>And here's <a href="https://www.youtube.com/watch?v=JexmcIMCwq8">21 useful Firefox features</a> to give you a reminder why this browser keeps coming back, even after the wrong turns it has taken these past few years.</p><figure class="kg-card kg-embed-card"><iframe width="200" height="113" src="https://www.youtube.com/embed/JexmcIMCwq8?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen="" title="Firefox Can Do More Than You Think: 21 Useful Features"></iframe></figure><div class="kg-card kg-button-card kg-align-center"><a href="https://www.youtube.com/@itsfoss" class="kg-btn kg-btn-accent">Subscribe to It's FOSS YouTube Channel</a></div><h2 id="%F0%9F%92%A1-quick-handy-tip">&#128161; Quick Handy Tip</h2><figure class="kg-card kg-video-card kg-width-regular" data-kg-thumbnail="https://itsfoss.com/content/media/2026/09/copy-date-kde-plasma_thumb.jpg" data-kg-custom-thumbnail="">
            <div class="kg-video-container">
                <video src="https://itsfoss.com/content/media/2026/09/copy-date-kde-plasma.webm" poster="data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7" width="836" height="545" playsinline="" preload="metadata" style="aspect-ratio: 836 / 545; background: transparent url('https://itsfoss.com/content/media/2026/09/copy-date-kde-plasma_thumb.jpg') 50% 50% / cover no-repeat;"></video>
                <div class="kg-video-overlay">
                    <button class="kg-video-large-play-icon" aria-label="Play video">
                        <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24">
                            <path d="M23.14 10.608 2.253.164A1.559 1.559 0 0 0 0 1.557v20.887a1.558 1.558 0 0 0 2.253 1.392L23.14 13.393a1.557 1.557 0 0 0 0-2.785Z"></path>
                        </svg>
                    </button>
                </div>
                <div class="kg-video-player-container">
                    <div class="kg-video-player">
                        <button class="kg-video-play-icon" aria-label="Play video">
                            <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24">
                                <path d="M23.14 10.608 2.253.164A1.559 1.559 0 0 0 0 1.557v20.887a1.558 1.558 0 0 0 2.253 1.392L23.14 13.393a1.557 1.557 0 0 0 0-2.785Z"></path>
                            </svg>
                        </button>
                        <button class="kg-video-pause-icon kg-video-hide" aria-label="Pause video">
                            <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24">
                                <rect x="3" y="1" width="7" height="22" rx="1.5" ry="1.5"></rect>
                                <rect x="14" y="1" width="7" height="22" rx="1.5" ry="1.5"></rect>
                            </svg>
                        </button>
                        <span class="kg-video-current-time">0:00</span>
                        <div class="kg-video-time">
                            /<span class="kg-video-duration">0:16</span>
                        </div>
                        <input type="range" class="kg-video-seek-slider" max="100" value="0">
                        <button class="kg-video-playback-rate" aria-label="Adjust playback speed">1&times;</button>
                        <button class="kg-video-unmute-icon" aria-label="Unmute">
                            <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24">
                                <path d="M15.189 2.021a9.728 9.728 0 0 0-7.924 4.85.249.249 0 0 1-.221.133H5.25a3 3 0 0 0-3 3v2a3 3 0 0 0 3 3h1.794a.249.249 0 0 1 .221.133 9.73 9.73 0 0 0 7.924 4.85h.06a1 1 0 0 0 1-1V3.02a1 1 0 0 0-1.06-.998Z"></path>
                            </svg>
                        </button>
                        <button class="kg-video-mute-icon kg-video-hide" aria-label="Mute">
                            <svg xmlns="http://www.w3.org/2000/svg" viewbox="0 0 24 24">
                                <path d="M16.177 4.3a.248.248 0 0 0 .073-.176v-1.1a1 1 0 0 0-1.061-1 9.728 9.728 0 0 0-7.924 4.85.249.249 0 0 1-.221.133H5.25a3 3 0 0 0-3 3v2a3 3 0 0 0 3 3h.114a.251.251 0 0 0 .177-.073ZM23.707 1.706A1 1 0 0 0 22.293.292l-22 22a1 1 0 0 0 0 1.414l.009.009a1 1 0 0 0 1.405-.009l6.63-6.631A.251.251 0 0 1 8.515 17a.245.245 0 0 1 .177.075 10.081 10.081 0 0 0 6.5 2.92 1 1 0 0 0 1.061-1V9.266a.247.247 0 0 1 .073-.176Z"></path>
                            </svg>
                        </button>
                        <input type="range" class="kg-video-volume-slider" max="100" value="100">
                    </div>
                </div>
            </div>
            
        </figure><p>In KDE Plasma, you can copy a wide range of time/date formats to the clipboard by right-clicking on the Clock widget in the panel.</p><p>All you have to do is right-click on the digital clock in the panel, hover your mouse cursor over the "Copy to Clipboard" option, and click on the format you want copied.</p>
<!--kg-gated-block:begin nonMember:true memberSegment:"status:free" --><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal    " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p><span style="white-space: pre-wrap;">Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content. </span></p><p><span style="white-space: pre-wrap;">If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.</span></p>
                        </div>
                    
                    
                        <a href="https://itsfoss.com/membership/" class="kg-cta-button " style="background-color: #000000; color: #ffffff;">
                            Join It's FOSS Plus
                        </a>
                        
                    </div>
                
            </div>
        </div><!--kg-gated-block:end-->
<h2 id="%F0%9F%8E%8B-fun-in-the-fossverse">&#127883; Fun in the FOSSverse</h2><p>Sharpen your networking command knowledge by <a href="https://itsfoss.com/quiz/the-networking-command-crossword/">completing this crossword</a>!</p><p>Linux is for power users. &#128170;</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/meme81.jpg" class="kg-image" alt="linux sudo meme" loading="lazy" width="1440" height="1440" srcset="https://itsfoss.com/content/images/size/w600/2026/09/meme81.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/09/meme81.jpg 1000w, https://itsfoss.com/content/images/2026/09/meme81.jpg 1440w" sizes="(min-width: 720px) 720px"></figure><p><strong>&#128467;&#65039; Tech Trivia</strong>: On September 27, 1983, <a href="https://www.stallman.org">Richard Stallman</a> announced the <a href="https://www.gnu.org/home.en.html">GNU Project</a>, an effort to build a completely free Unix-compatible operating system. It helped spark the free software movement and popularize copyleft through the <a href="https://en.wikipedia.org/wiki/GNU_General_Public_License">GPL</a>, shaping how software is shared, modified, and built collaboratively.</p><p><strong>&#129489;&zwj;&#129309;&zwj;&#129489; From the Community</strong>: Neville <a href="https://itsfoss.community/t/the-case-for-small-well-written-programs/16286">is making the case</a> for small, well-written programs; do you have an opposing view to present?</p>
<img src="https://feed.itsfoss.com/link/24361/17483196.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[F-Droid's New App Shows it Isn't Going Anywhere]]></title>
      <description><![CDATA[The Compose-based 2.0 app release marks the largest update in the storefront's history.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17483121/f-droid-revamp</link>
      <guid isPermaLink="false">6abdf5347834300001c4ad5a</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Thu, 01 Oct 2026 16:03:52 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/f-droid-2-0-banner.png" medium="image">
        <media:description type="plain">f-droid 2.0 release banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/f-droid-2-0-banner.png" alt="f-droid 2.0 release banner" loading="lazy"></figure>
<p>Since 2010, <a href="https://f-droid.org">F-Droid</a> has been the go-to place for downloading free and open source apps for Android. Its client app is the one people interact with the most, and it has received many upgrades over the years.</p><p>But now it's time for a massive rewrite that has emerged from more than a year of development and numerous test releases.</p><h2 id="a-comprehensive-redesign">A comprehensive redesign</h2><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-2-0-discover.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-2-0-discover.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-2-0-discover.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-2-0-discover.jpg 1214w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-2-0-categories.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-2-0-categories.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-2-0-categories.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-2-0-categories.jpg 1214w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-2-0-updates.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-2-0-updates.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-2-0-updates.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-2-0-updates.jpg 1214w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p>Kotlin replaces the original Java codebase, and the interface has been rebuilt on <a href="https://developer.android.com/compose">Jetpack Compose</a>. The result is an app that follows <em>Material Design</em> throughout, so that it looks and behaves like it belongs on a modern Android device.</p><p><strong>The app's bottom bar now has three sections</strong>: <em>Discover</em> for browsing, <em>Search</em> for queries and quick access to categories, and <em>My Apps</em> for tracking installed apps, updates, and issues. </p><p>You will also find that the <em>Settings</em> menu has moved to the top-right, being placed alongside the new <em>Repositories</em> menu.</p><p>Coming back to the <strong>Discover</strong> page, it has been configured to highlight newly added apps, recently updated ones, and the most downloaded ones in the repository. Related categories are grouped together, making it easier to browse the full catalog without getting lost in a long list.</p><p><strong>Search</strong> now handles categories, app descriptions, and translated content in addition to app names, and results for <em>Chinese</em>, <em>Japanese</em>, and <em>Korean</em> queries have improved. Your search history is also saved for future queries.</p><p>Filtering has been reworked too; results can be narrowed by anti-features, device compatibility, and category all at once.</p><h2 id="what-elses-changed">What else's changed?</h2><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-old-1.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-old-1.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-old-1.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-old-1.jpg 1214w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-old-2.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-old-2.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-old-2.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-old-2.jpg 1214w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/10/f-droid-old-3.jpg" width="1214" height="2534" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/10/f-droid-old-3.jpg 600w, https://itsfoss.com/content/images/size/w1000/2026/10/f-droid-old-3.jpg 1000w, https://itsfoss.com/content/images/2026/10/f-droid-old-3.jpg 1214w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption><p><i><em class="italic" style="white-space: pre-wrap;">This is how the old F-Droid app looks in comparison.</em></i></p></figcaption></figure><p>The app now <strong>checks for updates in the background by default</strong>, removing the need for the <em>pull-to-refresh</em> gesture that used to trigger repository scans. Of course the manual check is still available from the <em>My Apps</em> page once you go into the three-dot menu.</p><p>Similarly, the app hiding feature for changing F-Droid's logo to a calculator app has been moved into the <em>Settings</em> menu under "<em>App Icon</em>," and the <em>Nearby</em> app sharing tool has been temporarily removed.</p><p>Concluding their announcement, F-Droid stated that:</p><blockquote>F-Droid 2.0 represents a major milestone, but it is not the end of the story. Rebuilding the app has given us a stronger foundation, yet there is still plenty of work ahead.<br><br>As the rollout reaches more users, we expect to learn a great deal from real-world usage. Community feedback has shaped F-Droid 2.0 from its earliest design discussions through many alpha and RC releases, and it will continue to guide future improvements.</blockquote><h2 id="a-looming-threat">A looming threat</h2><p>Last year <a href="https://itsfoss.com/news/new-android-sideloading-rules/">in August</a>, Google announced that starting 2027, every Android app developer would need to register with the company, providing government-issued ID, signing key evidence, and a fee.</p><p>This way, apps from unregistered developers would be blocked from running on certified Android devices.</p><p>Of course F-Droid didn't sit by idly; one of their board members, Marc Prud'hommeaux, launched the <a href="https://keepandroidopen.org/">Keep Android Open</a> campaign in response, which has since brought together over 70 organizations from 20+ countries.</p><p>Its signatories include big names like the Electronic Frontier Foundation, the Free Software Foundation, KDE, Proton, Codeberg, VideoLAN, LineageOS, CryptPad and the Tor Project.</p><p>Seeing that we are shy of the 90-day mark for this absurd lockdown to occur, F-Droid introducing such a major update only strengthens their stance of not backing down to Google's strongarming tactics.</p><h2 id="get-f-droid-20">Get F-Droid 2.0</h2><p>This revamp <strong>is rolling out gradually</strong> over the coming weeks, so if you haven't received this on your existing installation, <strong>just wait</strong>. For new installations, it is a similar situation, as the latest stable release is still <em>v1.23.2</em>.</p><p>On the other hand, if you can't be bothered with practicing the virtue of patience, then you could download the latest 2.0 beta build from the <a href="https://f-droid.org/packages/org.fdroid.fdroid/">packages portal</a>.</p><div class="kg-card kg-button-card kg-align-center"><a href="https://f-droid.org/packages/org.fdroid.fdroid/" class="kg-btn kg-btn-accent">F-Droid 2.0</a></div>
<img src="https://feed.itsfoss.com/link/24361/17483121.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[How I Fixed the Biggest Annoyance of My Homelab]]></title>
      <description><![CDATA[Tired of remembering IP addresses and port numbers for your self-hosted services? Here's how I moved my homelab to clean .internal hostnames.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17482986/homelab-internal-domain-setup</link>
      <guid isPermaLink="false">6abdd7c67834300001c4aca0</guid>
      <category><![CDATA[Homelab]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Thu, 01 Oct 2026 13:46:12 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/10/homelab-internal-domain-setup-1.png" medium="image">
        <media:description type="plain">Internal domain name setup in homelab</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/10/homelab-internal-domain-setup-1.png" alt="Internal domain name setup in homelab" loading="lazy"></figure>
<p>My homelab started small, and so did the annoyance. </p><p>To open Jellyfin, I typed <code>192.168.0.x:8097</code>. For Home Assistant, it was another IP and <code>:8123</code>. For Karakeep, Ollama and the rest, even more IP and port combinations to either remember or bookmark.</p><p>The bookmarks weren't reliable either. My <a href="https://itsfoss.com/zimacube-2-review/" rel="noreferrer">ZimaCube</a> got its IP address from the router like any other device. Swap a cable or let it reconnect, and it mostly came back with a different IP, breaking every bookmark and config pointing to it. That's worse for Jellyfin because typing a full combination IP address and port number with a TV remote will give you a taste of medieval torture. </p><p>So, one weekend I decided to fix it. I started with assigning dedicated IP address to my Zima devices (<a href="https://amzn.to/46Z2N4v">ZimaBoard</a> and <a href="https://www.awin1.com/cread.php?awinmid=42286&amp;awinaffid=429005&amp;ued=https%3A%2F%2Fwww.zimaspace.com%2Fproducts%2Fcube-personal-cloud" rel="noreferrer">ZimaCube</a>) but ended up with a full network clean up.</p><p>Now my setup is smooth with all the regular services running with a .internal domain. Now I just type <code>jellyfin.internal</code> in the browser. No IP, no port number. Saved me a midlife crisis. </p><h2 id="my-setup-before-and-after">My setup, before and after</h2><p>Here's what my network looked like before the cleanup. The router from my ISP feeds a TP-Link router, which runs the homelab network, with a OneMesh node extending the Wi-Fi. </p><p>ZimaBoard consumes less power and runs services like Jellyfin that need to be on all the time. ZimaCube is a powerful device, and with Nvidia Ada RTX on it, I use it for local AI exploration. To cut down on my electricity bill, I only turn it on when I need it.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/homelab-before.png" class="kg-image" alt="My original homelab setup before the DNS changes" loading="lazy" width="2000" height="1058" srcset="https://itsfoss.com/content/images/size/w600/2026/10/homelab-before.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/homelab-before.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/homelab-before.png 1600w, https://itsfoss.com/content/images/2026/10/homelab-before.png 2080w" sizes="(min-width: 720px) 720px"></figure><p>And here's what it looks like now. Both Zima devices have fixed IPs, the ZimaBoard handles DNS and the reverse proxy, and every service has a proper name. </p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/homelab-after.png" class="kg-image" alt="my homelab setup after dns and reverse proxy manager" loading="lazy" width="2000" height="1154" srcset="https://itsfoss.com/content/images/size/w600/2026/10/homelab-after.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/homelab-after.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/homelab-after.png 1600w, https://itsfoss.com/content/images/2026/10/homelab-after.png 2080w" sizes="(min-width: 720px) 720px"></figure><h2 id="the-idea-in-a-nutshell-adguard-as-dns-and-nginx-proxy-manager">The idea in a nutshell: AdGuard as DNS and Nginx Proxy Manager</h2><p>The whole setup rests on two pieces working together. AdGuard Home, running as the network's DNS server, turns a name like <code>jellyfin.internal</code> into an IP address. </p><p>Nginx Proxy Manager then looks at which name you asked for and forwards the request to the right port. Because AdGuard can only work on the IP address, not port numbers.</p><p>Once that's in place, adding a new service is a two-step routine: one DNS rewrite in AdGuard, one proxy host in Nginx Proxy Manager. That's it.</p><div class="kg-card kg-callout-card kg-callout-card-red"><div class="kg-callout-emoji">&#128679;</div><div class="kg-callout-text">This is <i><em class="italic" style="white-space: pre-wrap;">my</em></i> setup, built around my routers, my Zima devices, and the services I run in my homelab. Take inspiration from it and use it as a reference, but don't copy it blindly. Your IP addresses, ports, router menus and commands will almost certainly be different.</div></div><h2 id="step-1-give-the-core-devices-fixed-ips">Step 1: Give the core devices fixed IPs</h2><p>Everything in this setup depends on IP addresses that never change. If the DNS server's IP changes, the entire setup breaks. So the first job was setting DHCP reservations on the router.</p><p>On my TP-Link, this lives under <strong>Advanced -&gt; Network -&gt; DHCP Server -&gt; Address Reservation</strong>. </p><p>It actually shows me the connected device and gives the option to reserve the IP from there itself.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/homelab-internal-domain-setup.png" class="kg-image" alt="reserving ip address for devices on local" loading="lazy" width="1109" height="423" srcset="https://itsfoss.com/content/images/size/w600/2026/10/homelab-internal-domain-setup.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/homelab-internal-domain-setup.png 1000w, https://itsfoss.com/content/images/2026/10/homelab-internal-domain-setup.png 1109w" sizes="(min-width: 720px) 720px"></figure><p>That may not always be the case for all the routers. So, you can find the MAC address on Linux with:</p><pre><code class="language-bash">ip link show
</code></pre><p>That will show the MAC address of the current device. You can use a <a href="https://itsfoss.com/basic-linux-networking-commands/" rel="noreferrer">networking command</a> like arp to scan the mac address of other devices connected to your network. The best place still is the router for this activity because it sees all the connected devices to the network anyways.</p><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-emoji">&#128161;</div><div class="kg-callout-text">I also moved the start of the DHCP pool to <code spellcheck="false" style="white-space: pre-wrap;">192.168.0.10</code>, so no phone or laptop ever grabs an IP I've reserved. </div></div><p>Here's the addressing scheme I ended up with:</p>
<!--kg-card-begin: html-->
<table>
<thead>
<tr>
<th>Device</th>
<th>IP</th>
<th>Notes</th>
</tr>
</thead>
<tbody>
<tr>
<td>Router</td>
<td>192.168.0.1</td>
<td>Homelab network gateway</td>
</tr>
<tr>
<td>ZimaBoard</td>
<td>192.168.0.4</td>
<td>Runs 24x7, hosts AdGuard and Nginx Proxy Manager</td>
</tr>
<tr>
<td>ZimaCube 2 Pro</td>
<td>192.168.0.5</td>
<td>Not always on, runs heavier services</td>
</tr>
<tr>
<td>Dynamic pool</td>
<td>192.168.0.10 to 253</td>
<td>Phones, laptops, everything else</td>
</tr>
</tbody>
</table>
<!--kg-card-end: html-->
<p>I have also assigned fixed IPs to Raspberry Pi and other SBCs in this setup. They are used for running local AI harnesses like Nanoclaw and Hermes agents. I am also setting up Frigate for the cameras. I will share my experience with those things in some later article.</p><p>Note that some devices may need to be rebooted or renew its DHCP lease to pick up the reserved IP.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">Since I used ZimaOS, things were more click click and install. For other setup, you will have to install and <a href="https://adguard-dns.io/kb/adguard-home/getting-started/">setup AdGuard DNS</a> and Nginx Proxy Manager. Instructions can be found on their respective websites.</div></div><h2 id="step-2-install-adguard-home-on-the-always-on-box">Step 2: Install AdGuard Home on the always-on box</h2><p>AdGuard Home becomes the DNS server for the entire homelab network, so it has to be up all the time. My ZimaBoard runs 24x7 while the ZimaCube doesn't, so the choice was easy.</p><p>In the ZimaOS App Store, I installed the <strong>AdGuard Home (HOST)</strong> variant, not the regular one. Host networking lets AdGuard bind directly to port 53 and see the real IPs of clients. With Docker's default bridge network, traffic gets NATed through the container and you lose both.</p><p>The install shows a tips popup with a config script. Its <code>wget</code> command failed on my system with a "Can't be verbose and quiet at the same time" error, so I ran the same script with <code>curl</code> instead:</p><pre><code class="language-bash">sudo bash -c "$(curl -fsSL https://raw.githubusercontent.com/bigbeartechworld/big-bear-scripts/master/generate-adguard-home-config/run.sh)"
</code></pre><p><strong>Don't skip <code>sudo</code> here</strong>. Without it, the script fails to create directories but still prints a success message. </p><p>I accepted the default config path, restarted the app from the ZimaOS dashboard, and opened <code>http://192.168.0.4:3000</code> manually. Clicking the app icon doesn't work for host-mode apps.</p><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-emoji">&#128161;</div><div class="kg-callout-text">AdGuard offers <a href="https://adguard-dns.io/license.html?aid=135612&amp;promoCode=ITSFOSS20" rel="noreferrer">AdGuard DNS</a> as a paid cloud service. But its open source equivalent is free to install and use on your own device. That's what I used here.</div></div><h3 id="when-ports-are-already-taken">When ports are already taken</h3><p>The setup wizard asks for an admin port and a DNS port, and both clashed with something. Port 80 for the web UI was taken, so I set AdGuard's admin UI to <code>3786</code> instead.</p><p>Port 53 was more surprising. Unusual, right? Turns out I had a Pi-hole container running that I had completely forgotten about. I found it with:</p><pre><code class="language-bash">sudo docker ps --format "{{.Names}}: {{.Ports}}"
</code></pre><p>Pi-hole and AdGuard do the same job, so there was no point running both. I removed Pi-hole.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/adguard-homelab-setup.webp" class="kg-image" alt="" loading="lazy" width="2000" height="1147" srcset="https://itsfoss.com/content/images/size/w600/2026/10/adguard-homelab-setup.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/adguard-homelab-setup.webp 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/adguard-homelab-setup.webp 1600w, https://itsfoss.com/content/images/2026/10/adguard-homelab-setup.webp 2001w" sizes="(min-width: 720px) 720px"></figure><h2 id="step-3-point-the-network-at-adguard">Step 3: Point the network at AdGuard</h2><p>AdGuard was running, but no device was using it yet. On my TP Link, I went to <strong>Advanced -&gt; Network -&gt; Internet</strong>, expanded Advanced Settings, and switched DNS Address to "Use the Following DNS Addresses". </p><p>Primary DNS is AdGuard at <code>192.168.0.4</code>, and secondary is <code>1.1.1.1</code>. Here. 192.168.0.4 is the IP address of the ZimaBoard that has AdGuard running on it.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/tplink-adguard-dns-setup.png" class="kg-image" alt="AdGuard setup as DNS in the router" loading="lazy" width="1563" height="589" srcset="https://itsfoss.com/content/images/size/w600/2026/10/tplink-adguard-dns-setup.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/tplink-adguard-dns-setup.png 1000w, https://itsfoss.com/content/images/2026/10/tplink-adguard-dns-setup.png 1563w" sizes="(min-width: 720px) 720px"></figure><p>Here's what this setting actually does. Devices on the network still use the router as their DNS server, and the router forwards their queries to AdGuard. That's why AdGuard's query log mostly shows the router as the client, not individual devices. For per-device stats, setting AdGuard's IP in the DHCP Server page should work, so that the router hands it to devices directly. </p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">The <code spellcheck="false" style="white-space: pre-wrap;">1.1.1.1</code> secondary is a safety net, so the internet doesn't go dark when the ZimaBoard is down. It comes with a trade-off, though. DNS clients don't always wait for the primary to fail before trying the secondary. When a query goes to Cloudflare instead, the ad slips through and <code spellcheck="false" style="white-space: pre-wrap;">.internal</code> names don't resolve, since Cloudflare has no idea they exist. If you notice a hostname failing occasionally, this is the likely culprit.</div></div><h3 id="when-a-device-ignores-the-new-dns">When a device ignores the new DNS</h3><p>While testing, I manually set <code>192.168.0.4</code> as DNS on a Linux laptop through GNOME's network settings. <code>dig @192.168.0.4 google.com</code> worked, but browser traffic never showed up in AdGuard's log. Running <code>resolvectl status</code> revealed the system was still using the router, as GNOME hadn't applied the change to the live connection.</p><p>Reconnecting to Wi-Fi fixed it. The more dependable way is doing it through <code>nmcli</code>:</p><pre><code class="language-bash">nmcli connection modify "&lt;connection-name&gt;" ipv4.dns "192.168.0.4"
nmcli connection modify "&lt;connection-name&gt;" ipv4.ignore-auto-dns yes
nmcli connection down "&lt;connection-name&gt;" &amp;&amp; nmcli connection up "&lt;connection-name&gt;"
</code></pre><h2 id="step-4-create-the-internal-names-with-dns-rewrites">Step 4: Create the .internal names with DNS rewrites</h2><p>This is where the hostnames come to life. In AdGuard, go to <strong>Filters -&gt; DNS rewrites -&gt; Add DNS rewrite</strong>, enter a domain like <code>jellyfin.internal</code>, and point it to an IP address.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/adguard-dns-rewrite.png" class="kg-image" alt="AdGuard DNS rewrites" loading="lazy" width="1616" height="928" srcset="https://itsfoss.com/content/images/size/w600/2026/10/adguard-dns-rewrite.png 600w, https://itsfoss.com/content/images/size/w1000/2026/10/adguard-dns-rewrite.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/adguard-dns-rewrite.png 1600w, https://itsfoss.com/content/images/2026/10/adguard-dns-rewrite.png 1616w" sizes="(min-width: 720px) 720px"></figure><p>Here's the thing. ZimaBoard runs multiple services. DNS rewrite only accepts IP address, not port numbers. If I have to add jellyfin.internal and homeassistant.internal in the DNS, both will be pointed to the same 192.168.0.4 IP address. And they won't be resolved.</p><p>I mean, I could do <code>zimaboard.internal:8097</code> and that would land me on Jellyfin but what's the point? A proper <code>jellyfin.internal</code> is what I would want. We need the port numbers.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/adguard-dns-rewrites.webp" class="kg-image" alt="AdGuard DNS rewrites" loading="lazy" width="1991" height="999" srcset="https://itsfoss.com/content/images/size/w600/2026/10/adguard-dns-rewrites.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/adguard-dns-rewrites.webp 1000w, https://itsfoss.com/content/images/size/w1600/2026/10/adguard-dns-rewrites.webp 1600w, https://itsfoss.com/content/images/2026/10/adguard-dns-rewrites.webp 1991w" sizes="(min-width: 720px) 720px"></figure><p>This is why we need a proxy manager to properly map the domain names with both IP addresses and the port numbers. But a proxy manager cannot act as DNS and hence we need both AdGuard DNS in combination with a tool like <a href="https://nginxproxymanager.com/" rel="noreferrer">Ngnix Proxy Manager</a>.</p><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">Why <code spellcheck="false" style="white-space: pre-wrap;">.internal</code>? A good option was <code spellcheck="false" style="white-space: pre-wrap;">.local</code> but it is reserved for mDNS (Bonjour, Avahi), so many devices resolve it outside your DNS server, which could lead to inconsistent results. <code spellcheck="false" style="white-space: pre-wrap;">.lan</code> and <code spellcheck="false" style="white-space: pre-wrap;">.home</code> aren't reserved and could become real domains someday, just like <code spellcheck="false" style="white-space: pre-wrap;">.dev</code> did when Google bought it. <code spellcheck="false" style="white-space: pre-wrap;">.home.arpa</code> is official but clunky to type. In 2024, <a href="https://www.icann.org/en/board-activities-and-meetings/materials/approved-resolutions-special-meeting-of-the-icann-board-29-07-2024-en#section2.a">ICANN permanently reserved</a> <code spellcheck="false" style="white-space: pre-wrap;">.internal</code> for private networks. It's short, readable, and will never clash with a real website. And it fits the entire homelab narrative.</div></div><h2 id="step-5-use-the-port-numbers-with-nginx-proxy-manager">Step 5: Use the port numbers with Nginx Proxy Manager</h2><p>DNS only translates a name into an IP. It knows nothing about ports. To make <code>http://jellyfin.internal</code> work without <code>:8097</code>, something has to listen on port 80, check which hostname was requested, and forward it to the right port. That's a reverse proxy.</p><p>I'd have preferred <a href="https://caddyserver.com/">Caddy</a>, as that's what I use on some of my servers. But Caddy wasn't available as a one-click app in ZimaOS and I want to keep everything in Zima ecosystem. So I opted for <a href="https://nginxproxymanager.com/">Nginx Proxy Manager</a> (NPM) as it does the same job with a web interface instead of a config file. <em>Like AdGuard, it went on the always-on ZimaBoard</em>.</p><h3 id="port-80-issue-again">Port 80 issue, again</h3><p>NPM needs ports 80, 443 and 81 (its own admin UI). Port 80 was taken again, this time by <code>zimaos-gateway</code>, the process serving the ZimaOS dashboard for ZimaBoard. I confirmed it with:</p><pre><code class="language-bash">sudo ss -tulpn | grep :80
</code></pre><p>The tempting fix is giving NPM a different port, but that defeats the whole purpose. You'd be back to typing port numbers. </p><p>Instead, I moved the ZimaOS dashboard to port <code>8888</code> from its <strong>Settings</strong> page. That was easy and that's why I like ZimaOS. It makes managing homelab a lot easier.</p><p>Anyways, the NPM install dialog still complained about port 80 for a while, and a full ZimaBoard reboot cleared that stale check.</p><h3 id="adding-proxy-hosts">Adding proxy hosts</h3><p>Once installed, NPM's admin UI is at <code>http://192.168.0.4:81</code>. Log in with the default <code>admin@example.com</code> and <code>changeme</code>, and it asks you to set new credentials right away.</p><p>To add a service, go to <strong>Hosts -&gt; Proxy Hosts -&gt; Add Proxy Host</strong> and fill in the details.</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/ngnix-proxy-manager-settings.webp" class="kg-image" alt="Nginx Proxy Manager Settings" loading="lazy" width="1426" height="1101" srcset="https://itsfoss.com/content/images/size/w600/2026/10/ngnix-proxy-manager-settings.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/ngnix-proxy-manager-settings.webp 1000w, https://itsfoss.com/content/images/2026/10/ngnix-proxy-manager-settings.webp 1426w" sizes="(min-width: 720px) 720px"></figure><ol><li><strong>Domain Names:</strong> the hostname, like <code>jellyfin.internal</code></li><li><strong>Scheme:</strong> <code>http</code></li><li><strong>Forward Hostname / IP:</strong> the IP of the device running the service</li><li><strong>Forward Port:</strong> the service's actual port, like <code>8097</code></li><li><strong>Websockets Support:</strong> on (Jellyfin and Home Assistant need it for live updates, and it doesn't hurt the rest so I always enable it)</li></ol><div class="kg-card kg-callout-card kg-callout-card-blue"><div class="kg-callout-emoji">&#128203;</div><div class="kg-callout-text">I left the SSL tab alone, since this traffic never leaves my home network. </div></div><p>Save it, open <code>http://jellyfin.internal</code> in a new tab, and there it is. No port number.</p><p>Here's how my proxy hosts look right now:</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/10/nginx-proxy-manager-setup.webp" class="kg-image" alt="Nginx Proxy Manager" loading="lazy" width="1200" height="698" srcset="https://itsfoss.com/content/images/size/w600/2026/10/nginx-proxy-manager-setup.webp 600w, https://itsfoss.com/content/images/size/w1000/2026/10/nginx-proxy-manager-setup.webp 1000w, https://itsfoss.com/content/images/2026/10/nginx-proxy-manager-setup.webp 1200w" sizes="(min-width: 720px) 720px"></figure><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-emoji">&#128161;</div><div class="kg-callout-text">The "Public" access label might look scary, but it only means NPM doesn't add its own login prompt. These names resolve only through my AdGuard, so nobody outside my network can reach them. To access it from outside, a service like Tailscale should be used.</div></div><h2 id="troubleshooting-afterwards">Troubleshooting afterwards</h2><p>Network setup never goes 100% trouble free. I did a face a couple of issues. Here are at least two that I recall (and have recorded):</p><h3 id="home-assistant-threw-a-400-error">Home Assistant threw a 400 error</h3><p>Everything worked except Home Assistant, which returned <code>400: Bad Request</code> through <code>homeassistant.internal</code>. Direct access on port 8123 was fine. Home Assistant rejects proxied requests unless it explicitly trusts the proxy, as protection against spoofed headers.</p><p>The fix goes in Home Assistant's <code>configuration.yaml</code>:</p><pre><code class="language-yaml">http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 172.17.0.3   # NPM container's IP on the Docker bridge network
</code></pre><p>I found the NPM container's IP with <code>sudo docker inspect nginxproxymanager | grep IPAddress</code>, then restarted Home Assistant with <code>sudo docker restart homeassistant</code>. </p><p>One catch: this IP can change if the NPM container gets recreated. Trusting the whole bridge subnet (<code>172.17.0.0/16</code>) instead of a single IP is more durable.</p><h3 id="netflix-stopped-working-on-the-tv">Netflix stopped working on the TV</h3><p>Shortly after switching DNS, Netflix on my smart TV refused to connect. AdGuard's query log showed two blocked domains in red: <code>logs.netflix.com</code> and <code>nrdp26.logs.netflix.com</code>. They're telemetry endpoints, but the Netflix app treats them as part of its connectivity check.</p><p>You can unblock an entry from the query log's menu in AdGuard, or add allowlist rules under <strong>Filters -&gt; Custom filtering rules</strong>:</p><pre><code class="language-text">@@||logs.netflix.com^
@@||nrdp26.logs.netflix.com^
</code></pre><p>Restart the app on the TV and it should work again. </p><div class="kg-card kg-callout-card kg-callout-card-green"><div class="kg-callout-emoji">&#128161;</div><div class="kg-callout-text">If something else breaks after you enable AdGuard, the query log is the first place to look.</div></div><h3 id="port-conflicts">Port conflicts</h3><p>Port conflicts came up three times during this project, so this little drill is worth keeping handy. To see which process is using a port:</p><pre><code class="language-bash">sudo ss -tulpn | grep :&lt;port&gt;
</code></pre><p>The process name in the output tells you who the culprit is. If it says <code>docker-proxy</code>, check which container it belongs to:</p><pre><code class="language-bash">sudo docker ps --format "{{.Names}}: {{.Ports}}"
</code></pre><p>Then decide whether to remove the conflicting container or move the <em>other</em> service to a different port. Just don't remap the port of the thing you're trying to make port-free, like NPM.</p><p>One more thing to keep in mind: all of this works only inside your home network. The <code>.internal</code> names exist only in your AdGuard, so they won't resolve when you're outside, unless you bring a VPN into the picture.</p><h2 id="adding-a-new-service-later">Adding a new service later</h2><p>This is where all the effort I put in this setup pays off. When I deployed Karakeep a few days later, giving it a proper name took just two steps:</p><ol><li>In AdGuard, add a DNS rewrite: <code>karakeep.internal</code> pointing to the ZimaBoard (<code>192.168.0.4</code>).</li><li>In Nginx Proxy Manager, add a proxy host: <code>karakeep.internal</code> forwarding to the service's IP and port (<code>14592</code> in my case).</li></ol><p>If the service does its own host validation, like Home Assistant, it may also need to trust the proxy.</p><h2 id="wrapping-up">Wrapping up</h2><p>I did all this a few months ago and it has been running smoothly so far. HTTPS for the <code>.internal</code> names would be nice to have. Perhaps I will think about implementing it some weekend.</p><p>I am sure there are other, perhaps better (?) ways of doing this. For now, this setup works for me, and I no longer have to remember a single IP address or port number in my homelab. I hope it gives you a few ideas for taming your own.</p><p>I welcome your questions and suggestions. What else could I do here? What would you like to do about a similar setup?</p>
<img src="https://feed.itsfoss.com/link/24361/17482986.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[Local AI Weekly #4: The Fine Print of Running AI Locally]]></title>
      <description><![CDATA[There is a local desktop AI assistant for KDE Plasma.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17481812/local-ai-weekly-4</link>
      <guid isPermaLink="false">6abd024a6214c9000176ac83</guid>
      <category><![CDATA[Newsletter ✉️]]></category>
      <dc:creator><![CDATA[Abhishek Prakash]]></dc:creator>
      <pubDate>Wed, 30 Sep 2026 20:55:06 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/local-ai-weekly-4.png" medium="image">
        <media:description type="plain">local ai weekly</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/local-ai-weekly-4.png" alt="local ai weekly" loading="lazy"></figure>
<p>Welcome to Local AI Weekly #4.</p><p>"Local AI" keeps meaning different things these days. Sometimes the model runs on your computer. Sometimes only the app does, while the model and your chat still run elsewhere.</p><p>There are lots of such "local AI" tools that are not really local. Before you pick a local AI tool, ask three things: where does inference happen, what account or network service is still required, and what does the license let you do? The best local AI tool is the one that doesn't need any of that.</p><h2 id="%F0%9F%A7%AA-on-my-bench">&#129514; On my bench</h2><p>Team It's FOSS has moved from Discord to Buzz for internal chat. <a href="https://buzz.xyz/">Buzz</a>, from Jack Dorsey of Twitter fame, is a decentralized communication tool for humans and agents. Agents can run on remote servers or a local harness over ACP.</p><p>It has quirks. Clipboard screenshots won't paste into chat, and desktop notifications only fire for direct messages. Manageable for now.</p><h2 id="%F0%9F%94%8D-discover-ai-tools">&#128269; Discover AI tools</h2><p>Kubutu developer Rick Timmis is working on <a href="https://meetklara.ai/">Klara</a>, a local desktop AI assistant for KDE Plasma. The idea is to let you control the desktop via voice input. It is a work in progress for now.</p><p><a href="https://github.com/CopilotKit/openmuse?ref=itsfoss.com">OpenMuse</a> is an MIT-licensed personal-agent app with a browser worker, durable tasks, and an optional Docker-based Linux computer. You can host it yourself, but setup still needs a CopilotKit Intelligence key, and open-ended tasks default to cloud providers. You can point it at an OpenAI-compatible endpoint, but there's no documented native Ollama path. Self-hosted software, not an assured offline agent.</p><h2 id="%F0%9F%8E%AB-get-mcp-certified">&#127915; Get MCP Certified</h2><p>The Linux Foundation now offers AI certifications. The <a href="https://www.awin1.com/cread.php?awinmid=85919&amp;awinaffid=429005&amp;ued=https%3A%2F%2Ftraining.linuxfoundation.org%2Fcertification%2Fmodel-context-protocol-associate-mcpa%2F&amp;ref=itsfoss.com">Model Context Protocol Associate</a> one could interest you if you're building MCP integrations, or want an AI credential on your resume. I plan to take it just for the sake of learning new skills.</p><div class="kg-card kg-button-card kg-align-center"><a href="https://www.awin1.com/cread.php?awinmid=85919&amp;awinaffid=429005&amp;ued=https%3A%2F%2Ftraining.linuxfoundation.org%2Fcertification%2Fmodel-context-protocol-associate-mcpa%2F&amp;ref=itsfoss.com" class="kg-btn kg-btn-accent">Explore MCPA Certification</a></div><h2 id="%F0%9F%93%A1-open-model-news">&#128225; Open Model News</h2><p><a href="https://huggingface.co/blog/manjunathshiva/opendecider-beats-laya-and-jev?ref=itsfoss.com">OpenDecider</a> is a more modest use for local models: answer bounded questions, like which queue a ticket should go to, instead of writing long replies. Its nano model is about 400M parameters; the 4B small model is a Qwen-based adapter. The author says both were distilled from larger teachers, and reports <a href="https://huggingface.co/manjunathshiva/opendecider-nano?ref=itsfoss.com">2.0 GiB for nano</a> and <a href="https://huggingface.co/manjunathshiva/opendecider-small?ref=itsfoss.com">8.9 GiB for small</a> in the tested setups.</p><p>Basically, you don't always need a giant model to route routine requests. A small student model can be the triage step ahead of a slower agent. </p><h2 id="%F0%9F%91%80-big-tech-watch">&#128064; Big Tech Watch</h2><p>NVIDIA's September <a href="https://blogs.nvidia.com/blog/local-ai-ifa-next-gen-agents-nv-pair-rtx-spark/?ref=itsfoss.com">PAIR announcement</a> also promises easier local-model setup in Hermes and OpenClaw. The one-click Hermes path launched on Windows, with Linux "coming soon." Don't confuse that future path with the Linux PAIR beta available now.</p><p>NVIDIA also quotes up to 1.9x throughput from llama.cpp optimizations on an RTX 5090. That's a vendor number on specific hardware, not a speedup I'd expect on yours.</p><h2 id="%F0%9F%97%82-ai-jargon-distillation">&#128450; AI Jargon: Distillation</h2><p>Imagine you have a giant, super-smart teacher who knows everything about the world. This teacher has a massive brain, but its so big that it can only stay inside a giant school building.</p><p>AI distillation is like that big teacher sharing all their secrets with a little kid (the student).</p><p>Instead of making the kid read millions of textbooks, the big teacher says: "Don't worry, just watch how I solve these puzzles, and listen to how I think."</p><p>The little kid watches closely and learns the teacher's smart shortcuts. Soon, the kid becomes almost as smart as the teacher, but with a much smaller brain!</p><p>You can learn more about <a href="https://www.ibm.com/think/topics/knowledge-distillation">distillation here</a>. And you will see that teacher-student is kind of official term in this context.</p><h2 id="%F0%9F%98%82-meme">&#128514; Meme</h2><p>When the open-weights drop looks a little too familiar...</p><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/ai-meme-1.jpeg" class="kg-image" alt="AI meme" loading="lazy" width="1841" height="1849" srcset="https://itsfoss.com/content/images/size/w600/2026/09/ai-meme-1.jpeg 600w, https://itsfoss.com/content/images/size/w1000/2026/09/ai-meme-1.jpeg 1000w, https://itsfoss.com/content/images/size/w1600/2026/09/ai-meme-1.jpeg 1600w, https://itsfoss.com/content/images/2026/09/ai-meme-1.jpeg 1841w" sizes="(min-width: 720px) 720px"></figure><h2 id="%E2%9A%A1-quick-tip-back-up-your-hermes-agent-before-you-need-to-rebuild-the-harness">&#9889; Quick Tip: Back up your Hermes agent before you need to rebuild the harness</h2><p>Last issue: <code>ollama ps</code>, to see if your model was really on the GPU. This week, make sure you could rebuild the setup around it too.</p><p>If you run Hermes, run <code>hermes backup</code>. It writes a ZIP of your Hermes home, config and state included, restored later with <code>hermes import path/to/backup.zip</code>. <code>hermes backup --keep N</code> caps retained backups, and a <a href="https://hermes-agent.nousresearch.com/docs/guides/cron-script-only?ref=itsfoss.com">script-only cron job runs</a> it on schedule without starting an agent.</p><p>Then move one encrypted copy off the machine. That archive can hold credentials, sessions, memory, and config, so don't drop the raw ZIP in Git, even a private repo. It won't be wise.</p><div class="kg-card kg-cta-card kg-cta-bg-grey kg-cta-minimal    " data-layout="minimal">
            
            <div class="kg-cta-content">
                
                
                    <div class="kg-cta-content-inner">
                    
                        <div class="kg-cta-text">
                            <p dir="ltr"><span style="white-space: pre-wrap;">If you have not subscribed to Local AI Weekly yet, you can </span><a href="https://itsfoss.com/local-ai-weekly/" rel="noreferrer" class="cta-link-color"><span style="white-space: pre-wrap;">subscribe from this page</span></a><span style="white-space: pre-wrap;">.</span></p>
                        </div>
                    
                    
                        <a href="https://itsfoss.com/local-ai-weekly/" class="kg-cta-button " style="background-color: #000000; color: #ffffff;">
                            Subscribe to Local AI Weekly
                        </a>
                        
                    </div>
                
            </div>
        </div><p>See you next week.</p>
<img src="https://feed.itsfoss.com/link/24361/17481812.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[Microsoft Has Made WSL Containers Available to Everyone]]></title>
      <description><![CDATA[Previously in public preview, it now offers new commands, Consommé networking, and Intune registry controls.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17480952/wslc-general-availability</link>
      <guid isPermaLink="false">6abc959f6214c9000176aa56</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Wed, 30 Sep 2026 17:49:57 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/wslc-general-availability-banner.png" medium="image">
        <media:description type="plain">wsl containers banner shown with a laptop and two miniature containers</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/wslc-general-availability-banner.png" alt="wsl containers banner shown with a laptop and two miniature containers" loading="lazy"></figure>
<p>Announced via a two-part series of blogs, Microsoft has moved WSL containers (WSLC) out of public preview and into <a href="https://blogs.windows.com/windowsdeveloper/2026/09/29/wsl-containers-now-generally-available/">general availability</a>. Let's take a look at what it offers.</p><p>The new release comes with <code>wslc.exe</code>, a dedicated command-line tool for Linux container workflows on Windows. It ships with a built-in alias, <code>container.exe</code>, for those who prefer that syntax.</p><p>A Windows API also ships alongside it, giving native Windows applications a way to spin up and manage containers directly from code, as well as some new commands that include <code>wslc events</code> for tracking container activity, and <code>--mount</code> and <code>--stop-timeout</code> flags on <code>create</code> and <code>run</code> operations.</p><p>Networking is handled through a new model called <a href="https://github.com/microsoft/WSL/blob/master/src/windows/common/ConsommeNetworking.h">Consomm&eacute;</a>, where container traffic leaves the virtual machine as <a href="https://en.wikipedia.org/wiki/Ethernet_frame">Ethernet frames</a> and is picked up by a Windows process running under the calling user's account. That process handles DNS, routing, and port mapping, letting traffic pass through VPNs and firewalls like any other Windows process.</p><p><strong>For organizations</strong>, Microsoft Intune has gained two new settings specific to WSL containers. The first lets administrators enable or disable access to the WSLC feature entirely across managed devices. The second is a container registry allow list, which restricts image pulls to a defined set of approved sources.</p><p>Microsoft Defender for Endpoint's WSL plugin has also been extended to cover container activity. It can retrieve process, file, and network events from inside WSLC, connecting them back to the Windows host.</p><h2 id="what-is-wslc">What is WSLC?</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/wslc-3-0-1.png" class="kg-image" alt="wslc --version and wslc --help command outputs" loading="lazy" width="988" height="951" srcset="https://itsfoss.com/content/images/size/w600/2026/09/wslc-3-0-1.png 600w, https://itsfoss.com/content/images/2026/09/wslc-3-0-1.png 988w" sizes="(min-width: 720px) 720px"></figure><p>First you have to know about <a href="https://itsfoss.com/wsl/">WSL</a>, which stands for <em>Windows Subsystem for Linux</em>, that lets developers run Linux environments directly on Windows without needing to partition their drive or setting up a separate Linux machine.</p><p>Since WSL 2, it has shipped with a real Linux kernel inside a managed virtual machine, giving users access to Linux tools, distributions, and command-line workflows from within Windows.</p><p><a href="https://learn.microsoft.com/en-us/windows/wsl/tutorials/wsl-containers">WSLC</a> extends this further by adding a dedicated layer for creating and managing Linux <a href="https://en.wikipedia.org/wiki/Containerization_(computing)">containers</a> within that same WSL environment, making containerized workflows a native part of the setup.</p><p>It also separates container operations from the main WSL service by routing them through a dedicated child process, <code>wslcsession.exe</code>, which runs under the current user's account. This keeps each session isolated and container operations in a less privileged state than the WSL service itself.</p><p>For developers already working inside WSL, this means containerized applications can run in the same environment without reaching for a separate tool. The Windows API exposure also means native Windows applications can interact with containers programmatically.</p><p>Microsoft's <a href="https://devblogs.microsoft.com/commandline/wslc-architecture-deep-dive/">WSLC architecture deep dive</a> is a must-read if you want to know more.</p><h2 id="get-it-now">Get it now</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/wsl-3-0-1-update-2.png" class="kg-image" alt="wsl 3.0.1 release" loading="lazy" width="925" height="457" srcset="https://itsfoss.com/content/images/size/w600/2026/09/wsl-3-0-1-update-2.png 600w, https://itsfoss.com/content/images/2026/09/wsl-3-0-1-update-2.png 925w" sizes="(min-width: 720px) 720px"></figure><p>Running <code>wsl --update</code> in your terminal pulls in the latest WSL release, which includes WSL containers. Once updated, <code>wslc</code> is ready to use.</p><p>You can use these new commands to manage your containers. &#128071;</p><table>
<thead>
<tr>
<th>Command</th>
<th>What it does</th>
</tr>
</thead>
<tbody>
<tr>
<td><code>wslc container restart</code></td>
<td>Restart a container.</td>
</tr>
<tr>
<td><code>wslc container cp</code></td>
<td>Transfer files to and from a container as a tar archive.</td>
</tr>
<tr>
<td><code>wslc system info</code></td>
<td>Check the state of your WSLC environment.</td>
</tr>
<tr>
<td><code>wslc network connect</code> / <code>wslc network disconnect</code></td>
<td>Join or remove a container from a network.</td>
</tr>
<tr>
<td><code>wslc network create</code></td>
<td>Create a network, with support for custom driver options.</td>
</tr>
</tbody>
</table>
<p>For the full changelog and access to the source, head to WSL 3.0.1's release page on <a href="https://github.com/microsoft/WSL/releases/tag/3.0.1">GitHub</a>.</p>
<!--kg-card-begin: html-->
<div class="repo-stats" data-repo="https://github.com/microsoft/WSL/"></div>
<!--kg-card-end: html-->

<img src="https://feed.itsfoss.com/link/24361/17480952.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[The Netherlands Picked NixOS. France Was Already Using It]]></title>
      <description><![CDATA[France’s digital agency has been using NixOS on internal workstations for months through Sécurix, its open-source, security-hardened configuration.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17478137/france-nixos-move</link>
      <guid isPermaLink="false">6abbb4e72f4ed5000173a292</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Wed, 30 Sep 2026 08:03:37 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/france-securix-nix-os-banner.png" medium="image">
        <media:description type="plain">france securix nixos banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/france-securix-nix-os-banner.png" alt="france securix nixos banner" loading="lazy"></figure>
<p>When we heard about the Netherlands' DAWO initiative, <a href="https://itsfoss.com/news/netherlands-dawo-initiative/">a formal mandate</a> to replace outside software across Dutch public institutions with a NixOS-powered platform, we asked ourselves: <em>How could France miss out on this?</em></p><p>Turns out, they didn't. <a href="https://www.numerique.gouv.fr/numerique-etat/dinum/?ref=itsfoss.com">DINUM</a>, the country's Interministerial Directorate for Digital Affairs, has been running its own NixOS-based workstation setup on internal machines for months now.</p><h2 id="s%C3%A9curix-and-its-nixos-bet">S&eacute;curix and its NixOS Bet</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/dinum-securix-github-repo.png" class="kg-image" alt="github repo for the securix project from dinum" loading="lazy" width="1847" height="773" srcset="https://itsfoss.com/content/images/size/w600/2026/09/dinum-securix-github-repo.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/dinum-securix-github-repo.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/09/dinum-securix-github-repo.png 1600w, https://itsfoss.com/content/images/2026/09/dinum-securix-github-repo.png 1847w" sizes="(min-width: 720px) 720px"></figure><p>DINUM has developed <a href="https://cloud-gouv.github.io/securix/en/">S&eacute;curix</a>, a security-hardened NixOS setup aimed at system administrators. It builds on top of NixOS without forking it, applying the security guidelines published by <em>ANSSI</em>, France's national cybersecurity authority.</p><p>The project is MIT licensed, lives under the <a href="https://github.com/cloud-gouv/securix">cloud-gouv</a> GitHub organization, and is currently in alpha, with v0.20.1 being its newest release having been introduced just a few hours ago.</p><p>According to Emilien Ercolani of <a href="https://www.thestack.technology/frances-shift-from-us-technology-starts-with-250-dinum-machines-and-nixos/">The Stack</a>, who attended a DINUM briefing in April, they are targeting implementation across ~250 of their staff's workstations. This comes after a successful pilot run across 70 machines.</p><p>In its current avatar, <strong>S&eacute;curix uses FIDO2 hardware security keys as the main login method</strong>, supports TPM2 and YubiKey, and leans on NixOS's <a href="https://reproducible.nixos.org">reproducible build</a> model.</p><p>Keep in mind that <strong>this is not meant to be a Linux distro</strong> but rather a foundation from which workstations can be operated and managed centrally.</p><p>Alongside it, DINUM has published <a href="https://github.com/cloud-gouv/bureautix-example">Bureautix</a>, a companion reference template for regular office workstations. It ships with KDE Plasma, LibreOffice, ONLYOFFICE, and WPS Office.</p><p>The docs <a href="https://cloud-gouv.github.io/securix/en/deployment/initialization/prepare-repo.html?highlight=bur#fork-bureautix-example">describe it</a> as a "<em>dummy example</em>" that organizations are meant to fork and adapt privately, not a separately running system.</p><h2 id="why-is-nixos-the-go-to">Why is NixOS the go-to?</h2><p>The project itself has a European origin. <a href="https://edolstra.github.io">Eelco Dolstra</a> created it at Utrecht University in the Netherlands, and the <a href="https://nixos.org/community/">NixOS Foundation</a> is a Dutch nonprofit. For European governments, <strong>the appeal is obvious</strong>.</p><p>Mainstream Linux distro offerings like <strong>Fedora</strong> trace back to Red Hat, which is owned by the US-based IBM; <strong>openSUSE</strong> is tied to the Luxembourg-based SUSE; and <strong>Ubuntu</strong> is from England's Canonical.</p><p>The underlying approach here seems to be avoiding projects that are based in foreign countries that could be forced to comply with the whims of their leaders.</p><p>From what I can see, <a href="https://itsfoss.com/news/france-government-linux-switch/">France</a>, the Netherlands, and <a href="https://itsfoss.com/news/denmark-road-traffic-authority-ditches-microsoft/">Denmark</a> are each taking a different path to the same place. In the end, if one wants control over their infrastructure, vendor-neutral and reproducible is the way to go.</p><hr><p><strong>Suggested Read &#128214;: </strong>postmarketOS is no more; not in that sense! It has <a href="https://itsfoss.com/news/postmarketos-nura-rebranding/">undergone a rebrand</a>.</p>
<img src="https://feed.itsfoss.com/link/24361/17478137.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[openSUSE Leap is The Immutable Distro Now, Leap Micro is Out]]></title>
      <description><![CDATA[Starting with Leap 16.1, the separate immutable flavor will cease to exist.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17477655/opensuse-leap-immutable</link>
      <guid isPermaLink="false">6abb8e812f4ed5000173a199</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Tue, 29 Sep 2026 21:35:38 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/opensuse-leap-immutable-banner.png" medium="image">
        <media:description type="plain">opensuse leap immutable banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/opensuse-leap-immutable-banner.png" alt="opensuse leap immutable banner" loading="lazy"></figure>
<p>openSUSE is known for shipping four main Linux distributions. <a href="https://get.opensuse.org/leap/">Leap</a> is the stable, fixed-release option built on the same source as SUSE Linux Enterprise (<em>SLES</em>). <a href="https://get.opensuse.org/tumbleweed/">Tumbleweed</a> is the rolling release for those who want the latest packages. <a href="https://get.opensuse.org/microos/">MicroOS</a> is the immutable, rolling variant that tracks Tumbleweed.</p><p>And finally there's <a href="https://get.opensuse.org/leapmicro/" rel="noreferrer">Leap Micro</a>, the immutable, fixed-release counterpart to Leap, built for container hosts, edge devices, and virtual machine workloads. Its job was to bring immutability as well as stability to openSUSE without affecting Leap itself.</p><p>That separation <a href="https://news.opensuse.org/2026/09/28/leap-161-rc/">is ending</a> as the project has now decided to ship <a href="https://itsfoss.com/immutable-linux-distros/">immutable Linux</a> as a separate mode inside the main Leap installer.</p><h2 id="a-new-mode">A new mode</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/opensuse-leap-16-1-immutable.png" class="kg-image" alt="the immutable mode in agama installer for opensuse leap 16.1" loading="lazy" width="1504" height="830" srcset="https://itsfoss.com/content/images/size/w600/2026/09/opensuse-leap-16-1-immutable.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/opensuse-leap-16-1-immutable.png 1000w, https://itsfoss.com/content/images/2026/09/opensuse-leap-16-1-immutable.png 1504w" sizes="(min-width: 720px) 720px"></figure><p>Leap Micro existed as its own product because immutable systems required a separate installation path. With Leap 16.1, the Agama installer has gained an "<em>Immutable</em>" mode option that can be toggled on during setup.</p><p>If you go with that, your system will be configured to have a read-only root filesystem with transactional updates and snapshot-based rollback. The technical foundation is identical to what Leap Micro offered; the difference is that it now lives inside Leap rather than alongside it.</p><p>System updates run through <code>transactional-update</code>, which applies changes in a new snapshot before the reboot, letting you roll back when a bad update causes issues. For installing new software, <strong>Podman</strong> and <strong>Distrobox</strong> cover containers, while <strong>Flatpak</strong> handles desktop apps.</p><p>Don't worry, you can still opt for the usual desktop experience if you choose the "<em>Standard</em>" mode.</p><p>And thanks to this, <strong>there will be no Leap Micro 6.3 or 7.0 releases</strong> as they have decided that Leap Immutable is the successor for anyone running container workloads, edge deployments, or setups that benefit from atomic updates.</p><p>For existing Leap Micro 6.2 users, the project offers the experimental <a href="https://github.com/openSUSE/opensuse-migration-tool">openSUSE Migration Tool</a> as a path forward.</p>
<!--kg-card-begin: html-->
<div class="repo-stats" data-repo="https://github.com/openSUSE/opensuse-migration-tool"></div>
<!--kg-card-end: html-->
<h2 id="anything-else">Anything else?</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/opensuse-leap-16-1.png" class="kg-image" alt="opensuse leap 16.1 desktop" loading="lazy" width="1920" height="1080" srcset="https://itsfoss.com/content/images/size/w600/2026/09/opensuse-leap-16-1.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/opensuse-leap-16-1.png 1000w, https://itsfoss.com/content/images/size/w1600/2026/09/opensuse-leap-16-1.png 1600w, https://itsfoss.com/content/images/2026/09/opensuse-leap-16-1.png 1920w" sizes="(min-width: 720px) 720px"></figure><p>As this is a new Leap release, there's a lot packed in other than the new mode. You get a range of upgrades that include <a href="https://itsfoss.com/news/kde-plasma-6-6-release/">KDE Plasma 6.6</a> with its OCR support in Spectacle and accessibility upgrades, as well as <a href="https://itsfoss.com/news/gnome-48-features/">GNOME 48</a> with its HDR support and the new default audio player.</p><p>The latter is the same version that shipped with Leap 16.0 but with a <em>gnome-shell</em> bug fix patch bundled in. The openSUSE devs are staging the GNOME upgrade gradually over the next couple of releases rather than jumping versions all at once.</p><p>You can expect the stable release of Leap 16.1 to land the same day as SLES 16.1.</p><h2 id="get-the-rc">Get the RC</h2><p>For now, only the release candidate (<em>RC</em>) is available, with the project committed to publishing one RC build a week before they reach Gold Master Candidate (<em>GMC</em>) status.</p><p>You will find RC images for <em>x86_64</em>, <em>aarch64</em>, <em>ppc64le</em>, and <em>s390x</em> from <a href="https://get.opensuse.org/leap/16.1/">the Leap website</a>.</p><div class="kg-card kg-button-card kg-align-center"><a href="https://get.opensuse.org/leap/16.1/" class="kg-btn kg-btn-accent">openSUSE Leap 16.1</a></div>
<img src="https://feed.itsfoss.com/link/24361/17477655.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[Firefox in a New Skin! Nova Redesign Has Become The Default]]></title>
      <description><![CDATA[Six months after the mockups leaked, the Firefox 157 release is the one that got it done.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17478367/firefox-nova-redesign</link>
      <guid isPermaLink="false">6abb5d3c2f4ed50001739f44</guid>
      <category><![CDATA[First Look]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Tue, 29 Sep 2026 19:24:55 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/firefox-nova-banner.png" medium="image">
        <media:description type="plain">firefox nova redesign banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-banner.png" alt="firefox nova redesign banner" loading="lazy"></figure>
<p>Firefox has a new look that brings it up to 2026 web browser standards, where having a clean, minimal user experience is a growing phenomenon.</p><p>Called "<em>Nova</em>," <a href="https://itsfoss.com/news/firefox-nova-leak/">the redesign leaked</a> before an official announcement was ever made, with Mozilla playing catch-up a few months later via <a href="https://blog.mozilla.org/en/firefox/new-firefox-design/">a technical blog</a> outlining how they were approaching this major transition.</p><p>That transition turned out to be more work than the mockups made it look.</p><h2 id="six-months-after-the-leak">Six months after the leak</h2><p>When the internal design files were made public in March, the mockups looked unlike any Firefox build before it. The tab bar, toolbar, and address bar were pulled into a single floating island at the top, with a visible gap between them and the page below.</p><p>Web content got the same treatment in those designs, sitting inside a rounded container lifted away from the browser's edges rather than running along with them. But the thing is, <strong>neither idea made it into the final release</strong>.</p><p>What we see in <a href="https://www.firefox.com/en-US/firefox/157.0/releasenotes/">Firefox 157</a> is more refined. Tabs, menus, and the address bar are noticeably rounder, with a subtle gradient on the active tab that adds warmth to the interface.</p><h2 id="come-have-a-look">Come, have a look</h2><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-old-homepage.png" width="1462" height="938" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-old-homepage.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-old-homepage.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-old-homepage.png 1462w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-homepage.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-homepage.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-homepage.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-homepage.png 1464w" sizes="(min-width: 720px) 720px"></div></div></div><figcaption><p><i><em class="italic" style="white-space: pre-wrap;">Firefox Nova is on the right.</em></i></p></figcaption></figure><p>I pitched Firefox 156 against 157 to see what changed, and I came out impressed.</p><p>Opening a new browser tab showed me where the most effort was put, with the tab bar being visibly rounder and the address bar corners being softer, giving the interface a very polished look.</p><p>Before this, <strong>I was already beginning to dislike the flat/bland look Firefox had</strong>; it bugged me whenever I would return from using another browser like Vivaldi or Chrome.</p><p>You see, both of them have already embraced a pill-shaped design philosophy that I quite like.</p><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-old-loading-website-1.png" width="1462" height="938" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-old-loading-website-1.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-old-loading-website-1.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-old-loading-website-1.png 1462w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-loading-website.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-loading-website.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-loading-website.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-loading-website.png 1464w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p>Loading up a website was more of the same, with the slimmer footprint of the interface leaving the webpage more real estate to use, and the toolbar has fewer dividing lines between its elements than before.</p><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-old-settings-menu.png" width="1462" height="938" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-old-settings-menu.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-old-settings-menu.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-old-settings-menu.png 1462w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-settings-menu.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-settings-menu.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-settings-menu.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-settings-menu.png 1464w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p><strong>The settings menu has also been refreshed</strong>. In 156, the sidebar was presented as a compact list with fairly simple content panels. In 157, those panels sit inside rounded cards, with sections that give each settings area more visual room and better readability.</p><h2 id="what-elses-new">What else's new?</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-tab-management.png" class="kg-image" alt="firefox nova tab management" loading="lazy" width="1500" height="960" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-tab-management.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-tab-management.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-tab-management.png 1500w" sizes="(min-width: 720px) 720px"></figure><p><a href="https://itsfoss.com/firefox-tab-groups/">Tab Groups</a> has changed considerably since I last used it. The Nova redesign has given it a more complete feel compared to when the feature first landed in Firefox 138. </p><p>Back then, groups showed as colored labeled strips in the tab bar, and management options were limited to naming and collapsing. While the feature worked, it felt like an early implementation.</p><p>Now, tab groups sit more naturally in the tab bar, and switching between them or collapsing one out of the way feels less clunky and more intuitive to use.</p><p>The "<em>List all tabs</em>" button has been changed too, featuring a different icon (<em>instead of the downward arrow</em>) and visual style that ties well into the overall pill-shaped design. You can use it to get a full view of every tab across all groups at once.</p><figure class="kg-card kg-gallery-card kg-width-wide kg-card-hascaption"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-compact-density.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-compact-density.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-compact-density.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-compact-density.png 1464w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-new-themes.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-new-themes.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-new-themes.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-new-themes.png 1464w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-window-switcher.png" width="618" height="483" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-window-switcher.png 600w, https://itsfoss.com/content/images/2026/09/firefox-nova-window-switcher.png 618w"></div></div></div><figcaption><p><i><em class="italic" style="white-space: pre-wrap;">Compact density, new themes, and window switcher.</em></i></p></figcaption></figure><p>A feature that <a href="https://support.mozilla.org/en-US/kb/compact-mode-workaround-firefox">was stripped out</a> back in 2021 has made a return. Compact mode is now available in <code>Settings &gt; Appearance</code> under the "<em>Window densit</em>y" selector in addition to the <em>Automatic</em>, <em>Standard</em>,<em> </em>and <em>Touch</em> options.</p><p>You will also find many new themes that can be installed via the <em>Add-ons manager</em>, as well as a new Classic/Smart Window switcher button on top-right for quickly switching between traditional and <a href="https://itsfoss.com/firefox-smart-window/">AI-powered browsing</a>.</p><h2 id="you-can-disable-it">You can disable it</h2><figure class="kg-card kg-gallery-card kg-width-wide"><div class="kg-gallery-container"><div class="kg-gallery-row"><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-disable-1.png" width="1464" height="929" loading="lazy" alt="firefox nova about:config page" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-disable-1.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-disable-1.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-disable-1.png 1464w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-disable-2.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-disable-2.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-disable-2.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-disable-2.png 1464w" sizes="(min-width: 720px) 720px"></div><div class="kg-gallery-image"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-disable-3.png" width="1464" height="929" loading="lazy" alt="" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-disable-3.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-disable-3.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-disable-3.png 1464w" sizes="(min-width: 720px) 720px"></div></div></div></figure><p>If you are not impressed by what Nova has to offer, then you could disable it to get back the old Firefox experience, and it's quite simple to do. In the address bar, type <code>about:config</code>, and accept the scary-looking warning.</p><p>Now, go into the search bar and type this "<em>browser.nova.enabled</em>" without the quotes. The final step is to either double-click on the entry or on the "<em>Toggle</em>" button to move Nova's activation state to "<em>False</em>."</p><p>That's it; you have successfully reverted to the earlier design.</p><h2 id="download-firefox">Download Firefox</h2><figure class="kg-card kg-image-card kg-card-hascaption"><img src="https://itsfoss.com/content/images/2026/09/firefox-nova-installation.png" class="kg-image" alt="firefox installation ubuntu 26.04 lts" loading="lazy" width="1572" height="982" srcset="https://itsfoss.com/content/images/size/w600/2026/09/firefox-nova-installation.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/firefox-nova-installation.png 1000w, https://itsfoss.com/content/images/2026/09/firefox-nova-installation.png 1572w" sizes="(min-width: 720px) 720px"><figcaption><i><em class="italic" style="white-space: pre-wrap;">This is how I installed the DEB file from the FTP mirror.</em></i></figcaption></figure><p>This is the obligatory installation section of the article, where you will find that Firefox can be downloaded from the <a href="https://www.firefox.com/en-US/thanks/">official website</a>. Though, when I was testing the redesign, I had to rely on Mozilla's <a href="https://ftp.mozilla.org/pub/firefox/releases/157.0/">FTP mirror</a> to get the Firefox 157 release early.</p><p>I went with the package meant for my test setup: <code>linux-x86_64 &gt; en-US &gt; firefox-157.0.deb</code></p><p>If you are on Debian or <a href="https://itsfoss.com/debian-based-distros/">any of its derivatives</a>, like Ubuntu, you can add <a href="https://support.mozilla.org/en-US/kb/install-firefox-linux#w_install-firefox-deb-package-for-debian-based-distributions" rel="noreferrer">the APT repository</a> to get it installed.</p><p><strong>And for existing users</strong>, by the time you read this, the various mainstream Linux distributions (<em>e.g., Ubuntu/Fedora</em>) should already be serving this redesign as part of a routine system update.</p><div class="kg-card kg-button-card kg-align-center"><a href="https://www.firefox.com/en-US/thanks/" class="kg-btn kg-btn-accent">Firefox</a></div><hr><p><strong>Suggested Read &#128214;:</strong><em> </em><a href="https://itsfoss.com/news/firefox-smart-window-mistral/"><em>Smart Window users now get to use French AI</em></a><em>.</em></p>
<img src="https://feed.itsfoss.com/link/24361/17478367.gif" height="1" width="1"/>]]></content:encoded>
    </item>
    <item>
      <title><![CDATA[postmarketOS is No More, At Least Under That Name]]></title>
      <description><![CDATA[It took the project 1.5 years before settling on 'Nura' as its new identity.]]></description>
      <link>https://feed.itsfoss.com/link/24361/17476371/postmarketos-nura-rebranding</link>
      <guid isPermaLink="false">6aba2e9f2f4ed50001739ba9</guid>
      <category><![CDATA[News]]></category>
      <dc:creator><![CDATA[Sourav Rudra]]></dc:creator>
      <pubDate>Mon, 28 Sep 2026 19:15:56 +0530</pubDate>
      <media:content url="https://itsfoss.com/content/images/2026/09/postmarketos-nura-rebrand-banner.png" medium="image">
        <media:description type="plain">postmarketos nura rebrand banner</media:description>
      </media:content>
      <content:encoded><![CDATA[<figure><img src="https://itsfoss.com/content/images/2026/09/postmarketos-nura-rebrand-banner.png" alt="postmarketos nura rebrand banner" loading="lazy"></figure>
<p>postmarketOS, the <a href="https://itsfoss.com/android-distributions-roms/" rel="noreferrer">Linux-based operating system</a> that many of you turn to for reviving your old smartphones, has undergone <a href="https://nura.eco/blog/2026/09/27/nura-rename/">a name change</a>, and it is now called "<strong><em>Nura</em></strong>."</p><p>This was announced during the project's conference recently, where the rebranding closed a long-running process that started last year <a href="https://nura.eco/blog/2025/03/04/pmOS-update-2025-02/#post-the-market-a-new-fame">in March</a>, drawing more than 300 name submissions from the community.</p><p>It took a dedicated selection team and a trademark review aimed at accommodating languages from every continent to ensure that the new name didn't have any offensive meanings across different cultures.</p><h2 id="postmarketos-had-to-go">postmarketOS had to go</h2><figure class="kg-card kg-image-card"><img src="https://itsfoss.com/content/images/2026/09/nura-webpage.png" class="kg-image" alt="nura homepage showing the new branding for postmarketos" loading="lazy" width="1293" height="718" srcset="https://itsfoss.com/content/images/size/w600/2026/09/nura-webpage.png 600w, https://itsfoss.com/content/images/size/w1000/2026/09/nura-webpage.png 1000w, https://itsfoss.com/content/images/2026/09/nura-webpage.png 1293w" sizes="(min-width: 720px) 720px"></figure><p>The old name worked against the project in ways that compounded over time.</p><p>It was long, difficult to pronounce across many languages, and its mid-word capitalization had no obvious logic for anyone coming to it fresh. The project says that people were mischaracterizing it as "<em>PostmarketOS</em>," "<em>Postmarketos</em>," and "<em>post-market OS</em>."</p><p>Then there was <strong>the problem of scope</strong>; initially, when the project was focused on reviving old smartphones, it was an appropriate moniker to flaunt. But when PINE64 began shipping phones with postmarketOS pre-installed, it became a liability as they couldn't trademark a descriptive name.</p><p>That left the project with no legal standing to protect its identity against misrepresentation.</p><p>With Nura,<strong> a trademark application has already been filed</strong>, though it has not yet appeared in public trademark databases so far (<em>I searched </em><a href="https://tmsearch.uspto.gov/search/search-information"><em>USPTO</em></a><em> and </em><a href="https://www.euipo.europa.eu/en/trade-marks/before-applying/availability"><em>EUIPO</em></a>).</p><h2 id="whats-nura">What's Nura?</h2><p><a href="https://nura.eco">Nura</a> is short for <a href="https://en.wikipedia.org/wiki/Nuraghe">Nuraghe</a>, which are granite constructions scattered across Sardinia, Italy, with some of these being traced as far back as 3000 BC. Many of those structures are still standing, giving us a glimpse of what the Nuragic civilization built back in the day.</p><p>The project draws inspiration from that, seeing longevity as a direct match for its own goal of keeping smartphones useful for a decade or more.</p><p>The name itself came from Davide Depau, who submitted it during the project's open call for community contributions.</p><p>The selection team, consisting of Pablo C. G&oacute;mez, Pan Ortiz, Ranny Bergamotte, and Sriram Ramkrishna, worked through more than 300 submissions and narrowed the field to four finalists.</p><p>The team voted, and Nura won.</p><p>They also went for the <code>.eco</code> domain knowingly, as it is reserved for organizations committed to positive environmental change and comes with enforceable policies against <a href="https://www.un.org/en/climatechange/science/climate-issues/greenwashing">greenwashing</a>.</p><h2 id="the-projects-current-status">The project's current status</h2><p>The new website presents a very straight-forward look at <a href="https://nura.eco/state/">Nura's status</a>, mentioning that it works best for people willing to learn how it works, contribute to testing, or help with development.</p><p>Its current release is <a href="https://nura.eco/install/">v26.06</a>, and for anyone getting started with Linux on mobile, the project points to second-hand Snapdragon 845 or Snapdragon 410/412-powered devices as the most sensible entry points.</p><p>Currently supported devices include the Fairphone 4, OnePlus 6 and 6T, PINE64 PinePhone and PinePhone Pro, Purism Librem 5, and several older Samsung and Xiaomi devices.</p><hr><p><strong>Suggested Read &#128214;:</strong> Your search for a Linux phone <a href="https://itsfoss.com/linux-phones/">ends here</a>.</p>
<img src="https://feed.itsfoss.com/link/24361/17476371.gif" height="1" width="1"/>]]></content:encoded>
    </item>
  </channel>
</rss>
