Bonum Certa Men Certa

Security and blobs, by Alex Oliva (GNU Linux-Libre)

posted by Roy Schestowitz on Feb 23, 2026,
updated Feb 23, 2026

Reprinted with permission from Alex Oliva.

Linux-libre turned 18 recently, and I'm told there are still some people who try to pass as security experts who disapprove of the refusal to load binary blobs that claim to fix security problems.

I kind of understand the appeal of security bug fixes, but delivering them in the form of binary blobs mean that the one who accepts them has to trust them blindly and to give up any pretense of security from the vendor, and that seems to be a problem that many pretense security conscious minds seem to disregard, for whatever reason.

At the same time they advise people to not open messages from untrusted senders, and to not install random programs even when they claim to offer security improvements. They even criticize people who fall in such traps, while pushing others to do just that!

Sure, in one case it's possibly an evil anonymous attacker, while in the other it's a well-known active corporation in the enshittocene, thus also evil. Thanks, but no, thanks, I'll take neither.

What these people don't seem to want to understand is that there is a significant risk in granting the vendor (just like to anyone else) a new round of control over your computer, especially over a component that can access pretty much everything you do. The risk is not only for your freedom, but also for your security.

When there is a known, exploitable vulnerability in your computer, plugging that hole with a blob may seem like a lesser risk than leaving it unpatched, even if the blob brings with it unknowns (other security holes), risks (new backdoors, new forms of remote control), limitations (new license restrictions, "improvements" that stop you from doing things on your computer that the vendor doesn't want you to do any more), and known downsides (slowing down your computer).

If they allowed you to inspect the changes, to choose which ones you want and which ones you don't, to make further improvements yourself, to plug holes independently from them, then the conclusion could be very different.

But they don't, because they don't respect your freedom. This means they don't want you to have defenses against their control.

They might even care about your security against others, but clearly not about your security against themselves.

If you have already mitigated the risks from the known holes that the blob purports to plug, then the only effects of the blob on you are negative: exposing you to unknowns, to risks, to limitations, and to its known downsides.

It's a net negative, even security wise.

I suppose the miscreants can't picture someone who mitigates the potential security problems brought about by CPU bugs by not allowing random programs from random third parties to be installed and run on their computers, not even through web browsers, and by only installing programs known to serve their users and from trusted sources. Some of us even audit changes ourselves!

For them, it's probably easier to tick a box and then go about recklessly running nonfree (because they run under control of the remote server) programs on their browsers, or installing and running other pieces of software remotely controlled by third parties, whose behaviors they wish to contain somehow.

But for someone who cares about freedom to the point of meticulously selecting hardware that will run with only free software, allowing such nonfree web blobs to run is undesirable to begin with. Installing nonfree programs that don't permit auditing is also out of the question.

These choices are for freedom purposes, but they are also a form of security in depth that miscreants seem unable to conceive of. That these freedom defenses also mitigate security issues is a welcome bonus.

That misguided security and freedom miscreants egg their own faces by promoting security-risking and freedom-denying blobs, because they can't see that newer blobs bring newer problems, is just priceless.

So blong,


Copyright 2007-2026 Alexandre Oliva

Permission is granted to make and distribute verbatim copies of this entire document worldwide without royalty, provided the copyright notice, the document's official URL, and this permission notice are preserved.

The following licensing terms also apply to all documents and postings in this blog that don't contain a copyright notice of their own, or that contain a notice equivalent to the one above, and whose copyright can be reasonably assumed to be held by Alexandre Oliva.

This work is licensed under the Creative Commons License BY-SA (Attribution ShareAlike) 3.0 Unported. To see a copy of this license, visit http://creativecommons.org/licenses/by-sa/3.0/ or send a letter to Creative Commons, 444 Castro Street, Suite 900, Mountain View, California, 94041, USA.

Other Recent Techrights' Posts

Almost 3 Days Later, Still Zero Press Coverage (Except One Publisher) About Mass Layoffs at Red Hat, Almost 500 People Laid Off (Over 400 for Sure)
"A document posted by FOSS advocacy site Techrights appears to be that memo and explains that Red Hat has devised a location strategy under which it has identified key sites for prioritized hiring and strategic workforce investment."
The Register MS, About 6 Million Pounds in Debt, Helps Promote Microsoft's Gartner Group and Prop Up the Ponzi Scheme of Slop Plagiarism, Fake Article Mentions "AI" About 20 Times
What was now known as The Register UK not only works against the interests of the UK; it works for charlatans and frauds
IBM 'Value' Fell 20%, The Executives Took Bonuses and Bonus Hikes
IBM is paying more and more money to the executives
More Information on IBM Red Hat Layoffs in April 2026, Hundreds of Skilled GNU/Linux Engineers Laid Off (300+ Simultaneously)
How long can the corporate media ignore IBM layoffs for?
SLAPP Censorship - Part 41 Out of 200: More Misuse of UK-GDPR (for US Citizens), More Copy-Pasting for Garrett and Graveley, Alleging That Publishing Unflattering Information is a 'Privacy' Issue
No wonder his own colleagues thought poorly of him (the junior barrister)
 
Links 11/04/2026: Twitter Presence Considered Harmful to News Sites, "The Future of Everything is Lies"
Links for the day
thenextweb.com (TNW) Appears to Have Become a Slopfarm, Fake Articles About France and GNU/Linux Flood the Web
If you're not against slop, you're part of the problem
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 10, 2026
IRC logs for Friday, April 10, 2026
Three Years Ago We Disconnected From the United States, Now France Does the Same
Maybe in the coming months France will recruit loads of UNIX/Linux specialists
While Thousands of EPO Workers Are on Strike the President of the EPO, Who Bribes His Voters, Gives Himself Millions of Euros and 5,000 Euros Per Month in Housing Allowance
Campinos is immune, inherently corrupt, and habitual briber of his 'voters'
IBM and Red Hat Whistleblowers Versus a Dying Fourth Estate (Journalism Seems to Have Died as Silently as IBM RAs Go)
What a crazy world we live in!
Slopfarms We Forget About Because They Silently Die
The hard reality (for slobs and sloppers) is, slopfarms have no future
Gemini Links 10/04/2026: Flexiveganism, What Happened to Twitter, and Algorithm Fetishes
Links for the day
Links 10/04/2026: Indonesia's Social Control Media Bans Extend to Google YouTube, "I.M.F. Says Iran War Will Drag Global Growth Lower"
Links for the day
Media Blackout Regarding Mass Layoffs at Red Hat
To be very clear, what happened is certainly real
SLAPP Censorship - Part 42 Out of 200: Getting the Very Basic Technical Concepts Very Wrong, or Where Miscomprehension Begets "Plausible Deniability"
It's difficult to argue with people over things that they do not even understand
This Coming Weekend and Next Week We'll Cover EPO Scandals a Lot, There Are Still Perpetual Strikes That the Media Intentionally Avoids Covering
Expect our focus on EPO corruption to grow again
Raw: Extensive Evidence of Red Hat's Mass Layoffs in China (IBM Meets Geopolitics)
This has nothing to do with workers' performance
We'll Never Ever Do Social Control Media, Nate Silver's Article Helps Explain Why
If you want to research and publish, stay away from it
Links 10/04/2026: Pseudoscience and "Amazon Pulls Support for Perfectly Fine Older Kindles" and More Attacks on American Journalism
Links for the day
Dr. Andy Farnell Blasts Misuse of the Term "AI" to Describe Plagiarism, Plunder, and Misinformation
Dr. Stallman wrote about it back in the early 1980s
A Sign of Progress?
We'll solve war hunger and colonise Mars soon, according to men who never graduated from College
The Slop Delusion: This Morning We Broke Story on Red Hat Layoffs in Two Posts, Google is Already Plagiarising Them With Slop and Getting the Basic Facts Wrong
Google does not have "AI"; it has slop, which means it scrapes other people's work, then imitates it poorly
"IBM is Constantly Laying Off People" (Not Just in Red Hat)
IBM as a company is collapsing
Many Layoffs at IBM Red Hat, as the Rumours Said
Red Hat mass layoffs [...] "this was a difficult decision to make."
Microsoft, Drowning in Net Debt, Will Make Many More Cuts
The company is a net negative to society
April 15: Richard Stallman to Speak at the University of Texas in Austin, Texas
Next Wednesday in the afternoon Dr. Stallman will speak in a US college for the second time this year and for the second time in nearly 8 years
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 09, 2026
IRC logs for Thursday, April 09, 2026
Gemini Links 10/04/2026: Cycling, Slop, and Software to Keep Photos Organised
Links for the day
Henry Abbott (TrueHoop) Says Microsoft Taken Public by Alvin Bernard "Buzzy" Krongard (in New Interview About Jeffrey Epstein)
He has claimed that the man who took Microsoft public was a banker and also connected to the CIA (former Executive Director)
Quick Roundup of "Linux" Slop
Today we saw a slopfarm again in Google News
Links 09/04/2026: Microsoft Attacking VeraCrypt and "Canada’s New Surveillance Law"
Links for the day
Gemini Links 09/04/2026: Shopping, LLMs That Ruin the Net, and Moving to GNU/Linux
Links for the day
Links 09/04/2026: TikTok Sets Up Another Outpost in Finland (EU), "Trump Attacks On Public Media Blocked by Judge"
Links for the day
Microsoft's DevDiv Executive Has Quit (Is GitHub on the Chopping Block?)
CodePlex all over again?
Chatbots (or LLMs) Are Killing Us, and We Ought to Talk About It
We need to talk (to each other, not to bots)
Microsoft Also Fires Senior Executives
Microsoft is a very feeble company pretending to be a giant
Microsoft Windows in Ireland: From 90% to Just 16%
When it comes to Ireland's Web usage, not much of it is from Windows anymore
SLAPP Censorship - Part 40 Out of 200: Putting Forth Frivolous Claim Only a Few Days Before Running Out of Time (12 Months)
my response to a frivolous claim from Graveley
IBM Layoffs by Performance Improvement Plan (PIP) and More Evidence of Layoffs at HashiCorp After IBM Took Over
Notice how the media does not cover IBM layoffs
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, April 08, 2026
IRC logs for Wednesday, April 08, 2026
Gemini Links 09/04/2026: On the Radio, Boogie Notes, Slop in Search Engines and USENET
Links for the day