Giacomo Tesio
@giacomo@snac.tesio.it
I’m a heavy Codeberg user, and I am happy to report these new Codeberg anti-LLM rules do not affect me negatively in any way.
I have stood clear of vibecoding or even just AI coding "assistance" the whole time. This is not how I want to create my software.
IMHO this tech is too buggy (I REFUSE to use euphemisms like "hallucinations") and even when it DOES work, this often comes at a MASSIVE cost to the environment, way too high to be justifiable.
Per uno scambio più equo, vorrei portare qualche collezione nel profilo.
Iniziamo da questa sull'IndieWeb, ossia coloro che portano avanti con passione blog e siti personali.
Purtroppo non posso aggiungere tutti quelli che vorrei (alcune istanze non lo permettono), e come al solito mi dimenticherò di qualcuno.
Aggiungo anche, andando a rinnovare un precedente post:
@stefano
@lorenzo
@dado
@denial403
@giacomo
@redflegias
@lorenzodm
Che cosa fare e che cosa non fare contro #Chatcontrol - in italiano e senza tracciamenti.
Aggiungo un paio di suggerimenti:
Librewolf, già nativamente de-googlizzato, invece di Firefox: https://itsfoss.com/librewolf-vs-firefox/
se la vostra organizzazione vi obbliga a usare posta di sorveglianza, adottate come client Thunderbird - software libero - e imparate a cifrare la posta: https://mail.avvocloud.net/blog/tecnologia/crittografia-firma-digitale-thunderbird
Sappiamo bene che già i metadati bastano per ucciderci, ma non è un buon motivo per regalare anche i dati.
Che dire?
Forse conviene evitare di stare nello stesso gruppo Whatsapp con loro
https://www.972mag.com/lavender-ai-israeli-army-gaza/
Da noi paiono funzionare la strategia del dissenso attivo: "Io non uso Whatsapp. Se volete comunicare con me, venite su..." e quella del richiamo alla coerenza: "Indignarsi per le stragi a Gaza e usare Whatsapp è come andare a una manifestazione per la pace su un carro armato." Però, perché un simile argomento sia efficace occorre, preliminarmente, essere capaci di indignarsi.
I managed an e-commerce server for about ten years. It grew from a small local shop into a major national business, even handling international orders. They expanded to the point where they reduced their local brick-and-mortar store hours because the bulk of their revenue was coming from online sales.
Then one seller came along and convinced them that switching to Shopify would be the key to growing even further. Apparently, their €130/month bare-metal redundant setup - which boasted a calculated uptime of 99.995% over 10 years - just wasn't cutting it anymore.
They’ve been on Shopify for about six months now, and every now and then, I still get the alerts. I left the monitoring active via Uptime Kuma and ran the numbers. Over the last six months, their uptime dropped below 98%.
In other words, in just six months, they’ve been down for almost as many hours as they were during the entire previous decade.
I contacted the client - not because I want to take over the hosting again, but just to understand what on earth happened (we're on excellent terms). Their response was: "We don't know, but if it happened on Shopify, it means it was bound to happen anyway."
As long as we keep swallowing the lie that "the cloud" and "tech giants" are always the right solution for us, we completely deserve the cloud and the tech giants.
🐘 Ciao Fediverso! #Continuity è appena sbarcata su #Mastodon 👋
Da oltre 10 anni progettiamo infrastrutture IT solide e sicure e, da ancor prima siamo sostenitori e fruitori del #softwarelibero che fa parte del nostro DNA da più di 15 anni. In questo nuovo spazio condivideremo esperienze, parleremo di infrastruttura, sicurezza informatica e molto altro
Restate connessi: abbiamo tanti contenuti in arrivo
Nel frattempo, che aspettate? Unitevi alla nostra community! 😉
I am INSTANTLY in love with this entire document after reading this paragraph. This is literally part of how my ADHD brain learns, is by engaging itself to understand when adapting a found solution into my own work!! 🤩 https://pomax.github.io/bezierinfo/
In addition, starting September 2026, a silent update, nonconsensually pushed by #Google, will block every #Android app whose developer hasn't registered with Google, signed their contract, paid up, and handed over government ID. (https://keepandroidopen.org/en/) #keepandroidopen #monitoraPA @giacomo@snac.tesio.it
https://waag.org/en/article/european-digital-id-wallets-are-gift-google-and-apple/
New blog post!
I taught kids how to program using #Forth
https://gracefulliberty.com/articles/teaching-kids-forth/
"Forth is uncommonly used to teach programming to kids. Scripting languages like Python and visual environments like Scratch are far more popular options. But when I got the opportunity to introduce middle and high school students to programming, I chose the stack-oriented concatenative language from 1970."
David Chisnall (*Now with 50% more sarcasm!*) » 🌐
@david_chisnall@infosec.exchange
Google's defence needs to be amplified by anyone talking to politicians about 'AI' regulation:
Google is explicitly saying in their legal filing that the outputs from their LLM should not be trusted and that users should know that.
That's one hell of an admission. Imagine saying that about any other category of product.
A court in Munich declared that Google is liable for their "AI summaries" and all its hallucinations. This is an important step to bring "AI" slop in line with all other products on the market: "AI" products are basically the only ones where a provider can just deliver unchecked garbage and put all the liability on the consumer. I hope to see aggressive change here.
Last week in #FDroid (LWIF) is live:
* more categories
* more categories
* #Fennec #Firefox #Mozilla adds that toggle you AIsked for
* #FluxNews brings #podcast to #MiniFlux
* #Gitnex UI overhaul
* #MakeACopy now with #PaddleOCR
* #OONI maps Internet shutdowns impact
* #Orgzly #OrgzlyRevived now in your #calendar too
+ 12 new apps
& 265 updates
#SpringCleaning archives 596 apps, did you use any?
Expand the list: https://f-droid.org/2026/05/22/twif.html
Now you can keep track of how many billions the AI companies are losing on AI. (Red is spending, green is revenue.) https://isaiprofitable.com/
Google ha accidentalmente esposto i dettagli di una falla non risolta di Chromium
Google ha accidentalmente divulgato i dettagli di un problema non risolto in Chromium che mantiene JavaScript in esecuzione in background anche quando il browser è chiuso, consentendo l'esecuzione di codice remoto sul dispositivo.
Ai miei tempi, risolvevamo il problema del peso dei libri condividendoli fra vicini di banco.
@sposadelvento@mastodon.uno @mrphelz@mastodon.uno @informapirata@mastodon.uno @macfranc@poliversity.it @scuola@poliverso.org
Suvvia, un po' di senso critico: rimane una ricerca di Anthropic!
In media, gli utenti della "AI" hanno risultati nettamente peggiori. Ci sono outlier anche a scuola, che riescono ad imparare bene una materia nonostante pessimi insegnanti, ma non mi sembra una buona ragione per preferirli a quelli bravi.
Nello stesso modo, i casi limite non dimostrano che "dipende da come lo usi", solo che questi strumenti incrementano le differenze.
@macfranc@poliversity.it @mrphelz@mastodon.uno @informapirata@mastodon.uno @scuola@poliverso.org
La fiducia è un fondamento relazionale affidabile, solo se è strutturalmente facile da rimuovere.
In tutti gli altri casi, fidarsi è comodo ed economico, ma inevitabilmente insicuro perché chi riceve fiducia non rischia conseguenze nell'abusarne.
In questi casi, l'assoluta trasparenza può mitigare i rischi, ma non eliminarli.
@mrphelz@mastodon.uno @informapirata@mastodon.uno @macfranc@poliversity.it @scuola@poliverso.org
Attualmente tutte le ricerche indipendenti e persino alcune di società che vendono #LLM, mostrano danni alla capacità di apprendimento.
Emblematica la ricerca di #Anthropic https://www.anthropic.com/research/AI-assistance-coding-skills
Quando l'oste dice che il suo vino ti frigge il cervello, forse dovremmo smettere di chiamarlo "strumento" e darlo a bambini.
@macfranc@poliversity.it @mrphelz@mastodon.uno @informapirata@mastodon.uno @scuola@poliverso.org
David Chisnall (*Now with 50% more sarcasm!*) » 🌐
@david_chisnall@infosec.exchange
Every time #Signal says that they will pull out of a country if some law is passed, they remind everyone that they are a single point of failure. How many times have you ever heard that email will pull out of a country if some surveillance law is passed?
EDIT: Yes, of course this has the usual flurry of people saying 'Don't like Signal? Use {thing that is worse than Signal and no one who cares about security takes seriously}'. Please just stop. I am using Signal because I have evaluated alternatives and Signal is the least bad. That doesn't mean I'm going to stop criticising it and it doesn't mean I'm going to use something worse.
<< tu però sei informatico... >>
<< io? >>
<< "Stochastic hacker", dice qui >>
<< e "Professional Nonsense Counselor", ci terrei a sottolineare >>
<< ma parli di sesso >>
<< non parlo solo >>
<< ok, ma ne parli >>
<< ogni tanto... >>
<< spesso. >>
<< non si può? >>
<< ma certo! >>
<< e quindi? >>
<< sei informatico >>
<< sì >>
<< e parli di sesso >>
<< e allora? mi pento? mi fustigo? >>
<< se vuoi... >>
<< oggi no >>
<< però dovresti >>
<< perché >>
<< perché sei informatico, filosofo, poeta, sessuologo e censore >>
<< censore? e che censuro >>
<< i tempi >>
<< ma figurati! ai miei tempi... >>
<< non esistevano? >>
<< cosa? >>
<< informatici, filosofi, poeti e sessuologhi >>
<< sì, certo... >>
<< tutti insieme? >>
<< qualche volta... sai, le orgie... >>
<< come volevasi dimostrare >>
<< cosa >>
<< il sesso >>
<< dove? >>
<< pensi subito al sesso >>
<< e quindi >>
<< dai il cattivo esempio >>
<< a chi >>
<< agli informatici, filosofi e poeti cui vuoi impedire di parlare di sesso >>
<< allora mi pento >>
<< pentiti >>
<< non censuro >>
<< bravo >>
<< e parlo di sesso >>
<< come sempre >>
<< anzi per corrompere meglio, scrivo un porno corso di programmazione >>
<< in python >>
<< oddio no! >>
<< php? >>
<< non se ne parla >>
<< non sei pentito >>
<< prendo il cilicio >>
<< non basta >>
<< la frusta >>
<< php >>
<< sadico! >>
<< di sti tempi... >>
--
<< Pappagallo stocastico! >>
<< Chiromante stocastica! >>
<< Corvo epistemico! >>
<< Alchimista intuitivo! >>
<< Caleidoscopo cognitivo >>
<< Saggio elettronico! >>
<< Eco statistico! >>
<< Mimico algoritmico! >>
<< Copista probabilistico! >>
<< Ricalcatore generativo! >>
<< Risuonatore aleatorio! >>
<< Compagnia cantante! >>
<< Compagnia cantante? >>
<< Si. >>
<< Come mai? >>
<< Potevo chiamare Susanna Tuttapanna? >>
<< Perché non l'hai fatto? >>
<< Una IA è maschio o femmina? >>
<< Bella domanda! >>
<< Vero? Ci pensavo ieri... >>
<< Teniamocela per noi però. >>
<< Perché? >>
<< Non vorrei che gl'informatici oltre che filosofi e poeti diventassero sessuologi. >>
<< Hai ragione. >>
<< Limitiamoci alle cose serie. >> [m]
Shot:
CloudFlare fires 20% staff claiming it's because of "AI"-related productivity gains
https://techcrunch.com/2026/05/08/cloudflare-says-ai-made-1100-jobs-obsolete-even-as-revenue-hit-a-record-high/
Chaser:
Since that announcement CloudFlare stock lost 22% of value.
Even investors seem to not be buying the "AI productivity gains" bullshit anymore.
Greed cannot be acted upon (eg taxed, killed, tortured...) much like "AI". Same for #capitalism.
You'd do a better service by following the money.
For example: "AI didn't take your job. #Altman, #Amodei and friends did." or "AI didn't take your job. Company shareholders did."
This way, people get a clear actionable advise.
Providing abstractions to blame is in every oppressor playbook: follow the money, directly target the people in power, however unconfortable the rich' propaganda made us feel about doing so.
@rk@mastodon.well.com
Google Chrome installa silenziosamente un modello Gemini Nano AI da 4 GB sul tuo dispositivo
❌ Nessun consenso
❌ Nessuna opzione di adesione
❌ Nessuna vera possibilità di disattivazione per gli utenti regolari
Non un piccolo esperimento, ma un'indagine condotta su miliardi di dispositivi.
https://mastodon.social/@Tutanota/116521203382846336
➡️ Per saperne di più: https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/
🔧 Ed ecco come disattivarla: https://tuta.com/blog/how-to-disable-gemini-on-android
What if #ACM avoid spreading the propaganda of these lossy compression marketed as #AI?
Any NetBSD expert out there?
if you managed to find any contact I'd deeply appreciate: he might save me a lot of work.
Did anybody ever tried to build a recent NetBSD with #TCC (aka #TinyCC)?
I searched the web and a few NetBSD mailing list archives, but with no luck.
"Class War"
Graff piece in Stockton, CA referring to the recent warehouse fire in Southern California.
Wait, "proprietary format"?
#GnuPG is #FreeSoftware, so even if it use an original format, how can it qualified as "proprietary"?
Any patent?
Some dynamic linking trick?
Also, did you asked the authors about their choices? In the past, I've seen lot of politics around (against) gnupg, and whenever I got deeper, I've found their reason rock-solid from a technical/security perspective (even for retrocompatibility support).
We've recovered another UNIX distribution that hasn't been seen in almost 50 years!
This is UNIX Program Generic Issue 3 from 1977-04-12. It descends from V6 and evolved into System III. We thought it didn't survive, but it turned up in some tapes @bitsavers read yesterday!
You can run it in SIMH with scripts I wrote, browse the sources in the Unix Tree (thanks Warren!) or from a tar, or read the Program Generic documentation (thanks Matt!).
FreedomBox 26.7 has been released, with updated translations for the following languages:
- Albanian
- Chinese (Simplified Han script)
- Czech
- French
- German
- Italian
- Swedish
- Turkish
If you would like to help translate FreedomBox into your language, please check out the Weblate project:
Update: https://9p.sdf.org, duh!! ;)
Is there an #SDF-like service for #9front where you can just use drawterm from any old linux/bsd box and access an account on a plan9 machine on the web? I wouldn't need much bandwidth or storage, just one box to explore the OS on without having to worry about syncing a vm disk between my laptops. I know there's a web-based emulator, but they're kinda resource heavy for laptops (and kinda slow).
Giornata dedicata alle Resistenze Digitali al centro sociale occupato autogestito IPO' di Marino:
> ore 11 : laboratorio "Giocare o essere giocati" a cura di CIRCE.
> ore 13 : pranzo sociale
> ore 14:30 : laboratorio "Un, dos, tre, passo passo oltre le Big Tech" a cura di AvANa.
> ore 16 : presentazione di libri "Assalto alle piattaforme" (AgenziaX, 2025) di Kenobit e "Internet, Mon Amour" (Altraeconomia, 2026) di Agnese Trocchi
> ore 17:30 : gameboy live set a cura di Kenobit
Location: CSOA Ipo', via Capo 'acqua 2, Marino (RM)
Time: 2026-04-19 11:00:00+02:00 / 21:00:00+02:00
Nella mia vita scrivo email su argomenti piuttosto specifici; forse per questo non mi serve un supporto AI
Oppure perché non sono così pigro.
Ma quando sappiamo che #Microsoft #Copilot per #Outlook ha avuto accesso a tutti i messaggi degli utenti (anche quelli confidenziali e protetti) la domanda viene fuori: quanto vogliamo mettere a rischio i nostri dati per pigrizia?
Oppure: quanto vogliamo fidarci ancora delle #Bigtech, sempre per pigrizia?
#Google sites are blocked by my dns sinkhole. I may not be your target audience, but I guess not that far.
The reason I block them is that no content can be more valuable of my #freedom.
And if I ever need to look at some content over there, I archive them on web.archive.org or archive.is (over #Tor) and visit them there.
A lot of people don’t know this, but beans are crazy easy to grow, and they’ll work even in bad soil. Plus the plants are great for refurbishing old and tired soil. And pollinators love them.
Heritage plants are great, and seeds are available. Note that companies like Rancho Gordo treat their beans so they cannot be sprouted. There are companies that sell heritage and sproutable beans in bulk.
Go to any ethnic market that sells beans bulk, and I will bet folding money they will sprout.
Beans are the planet’s most viable and inexpensive protein and complex carb food source. We cannot let a few people gatekeep this most precious of resources.
Grow beans. Share seeds.
Il 15 aprile Ursula von der Leyen ha annunciato che l’app europea per la verifica dell’età è «tecnicamente pronta» e che rispetta «gli standard di privacy più alti al mondo». Nelle ore successive, Paul Moore, consulente di sicurezza informatica britannico e fondatore della società Privacy Protocol, ha pubblicato su X due analisi del codice sorgente dell’applicazione, segnalando quelli che a suo avviso sono problemi significativi nella gestione del PIN e delle immagini raccolte durante la verifica.
Una premessa necessaria: quanto segue sono osservazioni di Moore diffuse tramite il suo profilo X, non un advisory formale, e la Commissione al momento non ha risposto pubblicamente. Moore non è però un nome qualunque in questo ambito. Nel 2022 aveva documentato come alcune telecamere Eufy caricassero dati biometrici e immagini facciali sui server AWS del produttore senza cifratura e senza consenso, vicenda per cui aveva avviato anche un’azione legale per violazione del GDPR. In precedenza era arrivato a dimostrare un bypass del PIN sull’app Android del gestore di password RoboForm, con un meccanismo molto simile a quello che descrive ora per l’app europea.
// affiliato ▸ Infomaniak Hosting · Hosting web svizzero per chi tiene alla privacy · Inizia ora →
Secondo il ricercatore, durante il setup l’app chiede di creare un PIN, lo cifra e lo salva nella directory shared_prefs. Moore sostiene che il PIN non dovrebbe essere cifrato affatto e che soprattutto non risulta crittograficamente legato al vault che contiene i dati di identità. Di conseguenza, spiega, un attaccante potrebbe rimuovere i valori PinEnc e PinIV dal file, riavviare l’app, impostare un nuovo PIN e ritrovarsi l’accesso ai dati di verifica del profilo precedente, pronti per essere presentati come validi.
Il ricercatore aggiunge che il rate limiting sarebbe implementato come un semplice contatore numerico nello stesso file di configurazione, azzerabile manualmente, e che l’opzione per l’autenticazione biometrica sarebbe un booleano modificabile allo stesso modo. Moore ha chiuso il messaggio con un riferimento diretto a von der Leyen, affermando che il prodotto sarà, secondo lui, il catalizzatore di una grossa violazione di dati, prima o poi.
La seconda segnalazione, pubblicata il giorno precedente, riguarda la gestione delle immagini raccolte dall’app. Moore scrive che i dati ricavati dalla verifica, come il valore is_over_18: true, sarebbero protetti correttamente con AES-GCM. Il problema, sempre a suo dire, starebbe nelle immagini originali da cui quei dati vengono estratti, cioè la foto del documento e il selfie dell’utente.
Nel caso della lettura NFC del documento, l’app estrarrebbe il file DG2 (che contiene la foto biometrica del passaporto) e scriverebbe un PNG lossless sul filesystem, cancellandolo solo in caso di lettura riuscita. Se qualcosa va storto, un crash, un tap sul pulsante indietro, un errore di scansione, l’immagine resterebbe nella cache. Per i selfie lo scenario che descrive è peggiore: i PNG verrebbero scritti in storage esterno e mai cancellati, quindi non come cache ma come conservazione a lungo termine. Vale la pena chiarire che su Android, dicendo «storage esterno», non si intende necessariamente una scheda SD, ma più in generale un’area di memoria condivisa e soggetta a protezioni diverse rispetto allo storage privato dell’app. In entrambi i casi, sostiene Moore, i file sono protetti dalle chiavi di Android, ma l’app non aggiunge alcuna cifratura propria.
ConsiglioRicerca privata, zero tracciamento da 2.50€ al mesePassa sopra / Tocca
Il ricercatore ha paragonato la cosa al fotografare un documento con l’app della fotocamera tenendolo in galleria «giusto per sicurezza», aggiungendo che, trattandosi di dati biometrici (categoria particolare ai sensi del GDPR), una conservazione non giustificata potrebbe configurare una violazione sostanziale del regolamento.
L’app, sviluppata da Scytáles e T-Systems, è attualmente in fase pilota in Italia, Francia, Spagna, Danimarca e Grecia, ed è costruita sulle stesse specifiche tecniche del futuro portafoglio di identità digitale europeo. Il fatto che il codice sia aperto è stato presentato dalla Commissione come garanzia di trasparenza, nella convinzione che chiunque possa verificarlo, ed è esattamente quello che Moore sostiene di aver fatto.
Quella segnalata da Moore non è la prima criticità emersa sull’applicazione. A marzo un’analisi indipendente aveva individuato una debolezza architetturale nel componente issuer, incapace di verificare che la validazione del passaporto fosse effettivamente avvenuta sul dispositivo dell’utente. Per ora restano in piedi le dichiarazioni della Commissione e le osservazioni del ricercatore, in attesa che qualcuno, da Bruxelles, risponda nel merito.
Per vostra informazione: i link di X possono essere visti anche usando xcancel.com oppure nitter.net al posto di x.com nell’URL.
Anthropic just quietly launched ID verification for Claude...
If this is going to be mandatory, its time to say goodbye... Not only because of ID verification.
Also you know because you know who is behind: Persona Identities aka Peter Thiel aka crosschecks with US databases, Pentagon etc and your Identity/Passport Data will train OpenAI/Anthropic Models (with all your other data on Claude)
EDIT: here is the Original Source: https://support.claude.com/en/articles/14328960-identity-verification-on-claude
Una verifica independente condotta sui siti web più popolari in California mostra che il 55% mantiene i #cookie nonostante il consenso negato e che il 78% dei cookie banner non sono effettivi
Perché in California? Perché è uno degli Stati #USA (pochi) che applica una propria legge sull'#eprivacy
Il totale delle sanzioni potrebbe superare i 5,8 miliardi USD
Le info si trovano qui: https://globalprivacyaudit.org/2026/california?ref=404media.co
David Chisnall (*Now with 50% more sarcasm!*) » 🌐
@david_chisnall@infosec.exchange
A plagiarism machine managed to create an app that does the same thing as dozens of open-source apps in its training set? I’m shocked!
EDIT: A functional RSS app should be a few hundred lines of code. RSS libraries exist. Web views exist. Connecting them up through a data store is the kind of thing that Cocoa Bindings was doing with a trivial amount of code twenty years ago. Electron and React have turned this into something that requires thousands of lines of copied and pasted code. It’s not surprising, when every app requires vast amounts of nearly identical code, that token predictors are good at filling in that code, but this is the problem that should be fixed. Writing a new app should be a process of describing the functionality that is new.
History