Tommaso Gagliardoni

Cryptography, privacy, quantum security, infosec, retro vibes.

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-24

Related to infosec.exchange/@tomgag/11450 (GitHub now requiring users to login in order to browse public repositories), this sucks particularly with Obtainium, when reinstalling apps from scratch on a new phone or doing mass updates.

#github #android #obtainium #enshittification #ai #ml #llm #microsoft #foss #floss #opensource

Tommaso Gagliardoni boosted:
Nathan Hamiel :2001:nhamiel@infosec.exchange
2025-05-23

Join Nils Amiet and me at Black Hat USA this year for Hack to the Future. This isn't a prompt injection talk. This is about the hidden dangers of deploying these tools in your environments and the potentially devastating vulnerabilities that can result. blackhat.com/us-25/briefings/s

Hack to the Future promo
Tommaso Gagliardonitomgag@infosec.exchange
2025-05-21

@nobody Good point, did not know that! I digged a bit into Simplex and there are indeed a few things I don't really like about it. I will have to update the blog post with a 2.0 at some point, I also have some other IMs on my evaluation list.

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-21

@nobody

Well that doesn't it feel sort of disingenuous to make out universal traceability and compliance to be a normal state of affairs, rather than the modern aberration that we haven't learned to live with?..

I think you misinterpreted my blog post. I did not imply that the 2010s status quo was OK, and I did not write that "history of currency" = "2010s status quo". I simply wrote that this was the situation, and that it remained pretty stable for a relatively long time (1980-ish - 2010-ish, which is insanely long in the context of the current pace of things). This has nothing to do with the definition of "modern world", which I picked as "history of currency" in a totally arbitrary way to serve the storyline of the blog post.

What I further wrote is that whether this status quo was better or worse than the current financial crypto anarchy is a matter of perspective. I, for one, if had absolutely to pick one, would prefer the old way. But I wish we could do better, and my blog post was meant to give some proposals for going in that direction.

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-20
A humoristic (fake) screenshot of a CAPTCHA request to prove you are not a Zoomer (GenZ). It asks the user to match two related objects among possible five: a Croc slipper, an audiocassette, an iPhone, a kitten, and a pencil.
Tommaso Gagliardoni boosted:
Nathan Hamiel :2001:nhamiel@infosec.exchange
2025-05-19

The next battleground is in sight, and things are going to move fast. Half-baked tech pitched as transformational will be quickly adopted and thrown in front of children without any validation, but the demos will be amazing!

Schools just for childcare
Tommaso Gagliardonitomgag@infosec.exchange
2025-05-19

@nobody

That's literally a fraction of 1% of the history of currency?

Uh, yes?

The [dictator] whose regime literally could not exist without AML and KYC

Put your favourite [dictator] in the brackets 😉

Tommaso Gagliardoni boosted:
2025-05-17
Screenshot of an article entitled “How the Web Became Unreadable” with the lede obscured by a Medium login modal
Tommaso Gagliardoni boosted:
2025-05-15

I think we should tell Gen Z that Head Cleaner's "Play Both Sides" was the 🔥 album of 1986

Cassette tape Head Cleaner Play Both Sides
Tommaso Gagliardoni boosted:
2025-05-15

Coinbase filed an 8K with the SEC for a breach. They believe multiple insiders have sold customer information to a threat actor who is now extorting them.

It looks like a very significant breach as it includes customers passport scans.

sec.gov/ix?doc=/Archives/edgar

#threatintel

Tommaso Gagliardoni boosted:
2025-05-15

If you’re in the EU and you opted out of Meta training generative AI on your Facebook, Threads and Instagram posts and pictures, Meta are requiring you to opt out *again* or they will continue training on your data.

Users have until May 27 2025 to opt out again or forever lose the right. arstechnica.com/tech-policy/20

This is the random ass opt out URL, which isn’t advertised in their apps: facebook.com/help/contact/6359

Instagram opt out: help.instagram.com/contact/233

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@zstg @Foxboron it's definitely a calculated one instead: github.blog/changelog/2025-05-

Now, either they have lowered the trigger rate, so to increase the limits, or they reverted the decision after #slashdot and #hn backlash (but haven't updated the blog post yet)

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@ripienaar @whack it looks like it doesn't always happens so fast (now I'm not blocked after 10-15 attempts for example). Maybe they reverted it?

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@Foxboron doesn't work anymore for me either. Did they revert?

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@michael @maxd @slotos I see what you did there

A "benevolent dictator"
Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@tyil @giacomo yes, you're right, I simplified a bit too much, of course the reasons behind Big Tech can never be nefarious enough 😅

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@0xDEADBEEF @famubu it's about community and bug tracker. Git is already decentralized, you can easily move your repository (the *storage*) and its history to another forge. But you lose all issues, comments, contributors, etc. In theory you *can* migrate a project away from, e.g., GitHub, but in practice starting from scratch is a pain.

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@famubu Yes, I know of #radicle but there are some other good pointers in the comments in this very thread #forgefed #meissa #forgejo

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@kevin Not sure about that, but I would be very surprised if that were not the case. Can you try and report maybe?

Tommaso Gagliardonitomgag@infosec.exchange
2025-05-14

@0xDEADBEEF @Codeberg Indeed! That is why, for example, the #Shufflecake Project is, and has always been, not on GitHub 😉

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst