Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Richard Hughes

@hughsie@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

I write free software. Firmware troublemaker.

0 Followers
0 Following
50 Posts
Joined October 11, 2018
Website:
https://hughsie.com/
GitHub:
https://github.com/hughsie
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

Both #Dell and #Lenovo have agreed to be premier sponsors for the #LVFS as part of our new sustainability effort. Over 145 million firmware updates have been deployed now, from over a hundred different vendors to millions of different Linux devices.

With the industry support from Lenovo and Dell (and #Framework, OSFF, and of course both the Linux Foundation and Red Hat) we can build this ecosystem stronger and higher than before; we can continue the great work we've done long into the future.

mastodon.social
164
6
81
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago

There are two types of people: Those that understand why your audio stutters when deploying an efivar-based certificate update (e.g. dbx) and those that don't.

Both are interesting at parties, but never ask the first type to explain what they do as a job.

18
3
6
0
Open post
Richard Hughes @hughsie@mastodon.social
· 1mo ago
Replying to
@whitequark@social.treehouse.systems I think calling it cursed is certainly negative, and I wouldn't want that feedback on any of the code I've written -- usually done with constraints and requirements that might not be immediately obvious. Maybe stick to pulling people up, rather than pushing them down.
2
2
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

I'm at #PremDay at Paris and just walked past two people in the hallway I've never met in my life talking excitedly about #LVFS and #fwupd. I know it's an unusual niche open source project but it was a super proud moment for me.

Open source maintenance is 99% fixing bugs and little things like this make it all worthwhile. Thanks those 2 random people!

mastodon.social
37
2
7
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago

I've just released https://github.com/hughsie/libxmlb/releases/tag/0.3.29 and https://github.com/fwupd/fwupd/releases/tag/2.1.7 with lots of great fixes and a smattering of new functionality. Enjoy!

github.com
8
0
4
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago
Replying to
@drwhax@infosec.exchange a lot of us at Red Hat have been working at 100% for the last 6 months on basically this. I personally spend ~2h/day on AISLE and Mythos reports and getting fixes upstream.
7
1
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 3mo ago
It seems the AI slop issues for fwupd just slowed down after all the Mythos fixes went in, rather than stopped. I guess we need to document that low severity "theoretical" security issues found using AI without a reproducer are not going to get CVEs. Does anyone see any problem in something like: https://github.com/fwupd/fwupd/pull/10604/changes -- it's wildly opinionated but perhaps pragmatic. Opinions welcome.
github.com
9
7
6
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago
I'm pleased to announce that #NVIDIA is now supporting the #LVFS as a premier sponsor. The rollout of the NVIDIA DGX Spark firmware using #fwupd is going very well indeed, with downloads continuing to increase every day. This now takes us to 4 OEMs sponsoring LVFS, which means we've successfully reached the funding target we set for ourselves last year. More exciting announcements coming soon!
4
0
4
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago

If anyone has an ideological problem with @whot@floss.social adding a rustc dep to #fwupd now is the time to squeak.

mastodon.social
5
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 1mo ago
Replying to
@whitequark@social.treehouse.systems what's your point? I don't understand the hate.
1
7
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 1mo ago
Replying to
@whitequark@social.treehouse.systems so why write the post? Real people write code and maintain projects. I know Matthias isn't paid to write appstream -- a project that thousands of projects use.
1
5
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
We did it everyone! The impersonated account is gone. Thank you all for your help, it's much appreciated.
21
3
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

I've just tagged #fwupd 2.1.2, with lots of fixes, new hardware support and a few cool new features. See https://github.com/fwupd/fwupd/releases/tag/2.1.2 for the list. Enjoy!

mastodon.social
15
2
2
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@frameworkcomputer@fosstodon.org my heart jumped when I heard #LVFS spoken aloud in the official announcement. I'm both proud and grateful for what we can do working together. Keep up the great work. ♥️
13
1
2
0
Open post
Richard Hughes @hughsie@mastodon.social
· 7mo ago

Announcing #fwupd 2.1.1 -- a very big release with the usual bugfixes, new features and lots and lots of new hardware support: https://github.com/fwupd/fwupd/releases/tag/2.1.1

mastodon.social
18
0
6
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

In less-awesome news somebody is now impersonating me on GitHub. If you see anything from "Richard Hughes jr" with an AI version of me as a profile photo -- it's obviously not me.

I'm certainly not promoting any kind of cryptocurrency and I'm certainly not a believer in NWO or the Illuminati of all things. I wish I was making all this up... and what a weird timeline we live in.

12
0
3
0
Open post
Richard Hughes @hughsie@mastodon.social
· 2mo ago
Replying to
If anyone wants to help, we're a bit light on translations at the moment: https://hosted.weblate.org/projects/passim/passim/
hosted.weblate.org
2
0
5
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@bagder@mastodon.social I get this with fwupd too. Everything that's AI found is reported as a CVSS 10.0 CRITICAL vulnerability, and then you find out it's assuming the attacker has write access on /etc or something dumb like that. At that point it's just a regular old typo bugfix like all the other thousands of unimportant commits.
9
0
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@purpleidea I'm literally at #PremDay talking to server vendors this week. Nothing amazing to announce yet, but the vendors are starting to see the writing on the wall. Lot's of promises, but I've heard most of them before.
6
1
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
Part 1 of 3 complete...
7
5
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

I've been (ab?)using Claude to find bugs in my software, and although it's found quite a few false positives, it's also found a lot of actual real bugs. Nothing CVE-worthy, but still important to fix. Releases include:

* passim: https://github.com/hughsie/passim/releases/tag/0.1.11
* libxmlb: https://github.com/hughsie/libxmlb/releases/tag/0.3.26
* libjcat: https://github.com/hughsie/libjcat/releases/tag/0.2.6

#fwupd will follow, when all ^^^ has hit the various build-roots. If anyone wants to polish the translations in the meantime, it's the normal place: https://hosted.weblate.org/projects/fwupd/fwupd/

github.com
7
2
5
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

I'm super impressed with the reviews from @coderabbitai@mastodon.social -- they're an order of magnitude better than Claude (and two orders of magnitude better than copilot) even with the latest models. And free for open source projects!

@coderabbitai@mastodon.social how do I refer to you in a commit? e.g. "Co-Authored-By: coderabbitai" perhaps? Claude uses "Co-Authored-By: Claude Sonnet 4.5 " if that helps.

5
19
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 7mo ago
Replying to
@GossiTheDog I guess the AI security scanners will clean this up with their automated scan and CVE requests.
8
1
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@itsfoss@mastodon.social I think it worked. More info really soon.
4
1
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 7mo ago
Boosted by @ferrix@mastodon.online
If the LVFS stopped signing with GPG+PKCS#7 and only relied on PKCS#7 going forward would anyone care? Thanks to using libjcat we can add and remove signature formats as we need to in a forwards and backwards compatible way. We added PQC-compatible certs a few months ago and nobody noticed.
7
2
4
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@patric2k@infosec.exchange thanks; that's probably a great idea -- if anyone else wants to report https://github.com/kjedrdev as impersonating me that would be great.
github.com
4
6
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 3mo ago

What would you rather see in the output of fwupdmgr security?

1
0
2
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

I'm pondering some interesting talks I could suggest for #OSFC this year. Does anyone want me to talk about anything specific for firmware, #fwupd or LVFS topics?

I'm thinking doing a pretty aggressive FU aiming at some of the major hardware vendors, but I'm not sure my boss would approve. Other ideas welcome.

mastodon.social

Mastodon

3
3
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@swick@hachyderm.io @coderabbitai@mastodon.social yes, Assisted-by seems more correct than Co-Authored-By -- I'll try to get Claude to do that in the future.
2
1
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@smrqdt@chaos.social @CyReVolt@mastodon.social yup, it3's certainly either an OpenClaw agent gone rogue or somebody that probably needs medication. Either way, I don't want any part of it.
2
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
Part 2 of 3 complete:
2
2
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 8mo ago

Hello again internet friends. What's the 2026 state of the art for syncing two folders on two different machines. e.g. like Dropbox used to be. It doesn't have to sync offline, but bonus points if it syncs to my Proton Drive too.

I want to be able to change and add content to folders on either machine. There's no need to recover previous versions as I already back up in a different way.

I used to use Unison for this a decade ago, but I wanted something that just works with GNOME. Ideas?

4
10
4
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago

Is everyone getting horseshit responses from #claude today? Queries that worked fine on Friday generate nonsense today.

mastodon.social

Mastodon

2
4
1
0
Open post
Richard Hughes @hughsie@mastodon.social
· 6mo ago

How is there no standard MiB constant of 1024*1024 in the C standard? What do other codebases do?

2
12
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 10mo ago
Replying to
@froztbyte no comment on all the other stuff, but with regards to timing we've been working on this behind the scenes for ages. The slowest part was actually getting the agreements written and setting up the ability for the Linux Foundation to take a donation specifically for just one project. Framework were ready before we were!
5
2
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@Logical_Error then you need a third to know which one is right.
1
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 10mo ago
Replying to
@ross IIUC, Framework also joined the LF.
1
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@ebassi@mastodon.social doesn't that seem a bit disingenuous? I didn't write the patch -- I just asked the agent to do something on my behalf. I'm not even sure if I'm the *author* :/
0
2
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@zeenix@toot.cat @patric2k@infosec.exchange I just used the "report" button on https://github.com/kjedrdev -- many thanks.
github.com
0
1
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@CyReVolt@mastodon.social yup, it's actually more insidious than this; someone has been emailing people I know warning them that I'm actually a "German hacking group" and that fwupdt (sic) is compromised with "git blobs with XOR puzzles".
0
1
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@asw@mastodon.social absolutely! Get them to send me their postal address to richard_at_hughsie_dot_com -- it's the least I can do.
0
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@johannbg@mastodon.social @ebassi@mastodon.social ohh I'm very much using AI as a tool; i don't enjoy using it, but it's certainly found a lot of valid issues I wouldn't have spotted in a very long time. It's also "found" a lot of nonsense too, but I'm just ignoring that.
0
1
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 10mo ago
Replying to
@paninid@mastodon.world paying for #kagi every month is a luxury, but I can't imagine going back to Google search now. Using Kagi is like Google search 10 years ago; the page you want in the first 5 results and no deceptive ads anywhere.
0
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@zygoon dude, of course! Yell if you spot any bugs.
0
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 5mo ago
Replying to
@ebassi@mastodon.social I most certainly reviewed it, and more than probably tweaked the code style and changed the commit message to make more sense.
0
4
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 6mo ago
Replying to
@23n27 I don't know if that's madness or brilliance.
0
0
0
0
Open post
Richard Hughes @hughsie@mastodon.social
· 3mo ago
Replying to
@wall_e@ioc.exchange @wall_e@ioc.exchange usually the LLM has a lot more internal context at the point of filing the issue than what's formatted in the report -- at least from my limited experience it usually does a half-decent job at fixing the bug and adding tests -- even if a human has to refactor and move things around for maintainability.
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:35:56 UTC