Cryptography, privacy, quantum security, infosec, retro vibes. I am a mathematician and cryptographer, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner. I co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution. I am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism. Fascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote "fascinated", not "knowledgeable". Here you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!
Public Key
npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Profile Code
nprofile1qqswf63vq5twdpdvywsxa0t7us2ajdn729uusxh2p6mw76vjvnnrkvgpz4mhxue69uhhyetvv9ujuerfw36x7tnsw43q5ds96f
Show more details
Published at
2026-08-20T08:06:08Z Event JSON
{
"id": "e5fd2511a343f5df42c4fce0b794e880c66c37f187c3d77c01f90bc4e8d3f2d8" ,
"pubkey": "e4ea2c0516e685ac23a06ebd7ee415d9367e5179c81aea0eb6ef699264e63b31" ,
"created_at": 1787213168 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://infosec.exchange/users/tomgag",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"Tommaso Gagliardoni\",\"about\":\"Cryptography, privacy, quantum security, infosec, retro vibes.\\n\\nI am a mathematician and cryptographer, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner.\\n\\nI co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution.\\n\\nI am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism.\\n\\nFascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote \\\"fascinated\\\", not \\\"knowledgeable\\\".\\n\\nHere you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!\",\"picture\":\"https://media.infosec.exchange/infosec.exchange/accounts/avatars/110/680/679/712/333/612/original/9ff79cc367140f23.jpg\",\"banner\":\"https://media.infosec.exchange/infosec.exchange/accounts/headers/110/680/679/712/333/612/original/91487e2c36283f3d.jpeg\",\"nip05\":\"[email protected] \",\"fields\":[[\"Homepage\",\"https://gagliardoni.net/\"],[\"Linkedin\",\"https://www.linkedin.com/in/tommasogagliardoni/\"],[\"Shufflecake\",\"https://shufflecake.net/\"],[\"My own company\",\"https://www.lucumo.net/\"]]}" ,
"sig": "d962e8443c0a63f0d0c67a9dcdfdf8b1a76617219c6348906b5e54dd23305ff2d711e445f802b50a4c6be58b8a815e5244188a7c8295b89cf557eca7a699ed73"
}
Last Notes npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…tkpx ROTFL all things as usual I see 😉 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni BREAKING! Meshcore team splits over dispute over AI-generated code disclosure, and hostile trademark takeover. Meshcore is an off-grid, decentralised mesh radio platform powered by low-cost and public access LoRa radio technology for reliable, long-range emergency text and embedded sensors communication. It can communicate across kilometres — no towers, no subscriptions, no single point of failure. https://blog.meshcore.io/2026/04/23/the-split #meshcore #meshtastic #lora #radio #opensource #foss #drama #privacy #security #selfsovereignty #ai #copyright #takeover npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Dear LinkedIn, It is great that you respect my privacy. But I'm confused: I thought I had previously already denied AT LEAST 89 OTHER TIMES my consent for you to profile me, track me with 3rd party cookies, anally probing me, and generally making my life a bit more miserable. To you and all the other countless buffoons out there: could you please kindly f**k off? #linkedin #privacy #ad #gdpr #enshittification #consent https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/288/918/051/802/631/original/5535bb1b8527996a.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Hard LOL https://www.bye-dubai.com/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…5kt4 better than nothing, no? I mean, what's the alternative? 1) keep using Pixels only 2) use a still immature Linux mobile OS 3) embrace enshittification. It's not that I don't agree, mind you, but at this point any good news is good news IMHO. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…udtr good point! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…nqv0 @nprofile…px8j I agree, but I think this announcement points exactly at the fact that Motorola agrees to produce phones that meet GOS' stringent security features, even if no model has been released yet that's good news. In other words, this should mark the beginning of exactly what you said: avoiding reliance on Pixel phones only. Thread on the GOS forum from a few min ago: https://discuss.grapheneos.org/d/32656-motorola-partnership-announcement npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…px8j your choice I guess, but just FYI, I've been on GOS on Pixels for years and they work flawlessly. Only two things don't work: contactless payments (blame Google and politics, not GOS) and CERTAIN banking apps. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…px8j good news for you then: once you install GOS on it, bloatware will become a thing of the past :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…5kt4 Yes, I think that's the best part: Motorola phones are great hardware-wise but have terrible updates cycle. Graphene OS fits perfectly there, because they are only subject to the much faster AOSP release cycle! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni This made me chuckle, but also made me angry, because it's SO TRUE. The Norwegian Consumer Council, a government funded organization advocating for consumer's rights, released a report on the trend of "enshittification", and a funny four-minute video: A Day in the Life of an Ensh*ttificator https://www.youtube.com/watch?v=T4Upf_B9RLQ #enshittification #capitalism #norway #eu #politics #funny npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Motorola announces partnership with Graphene OS to bring us secure phones! https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/ So the mysterious manufacturer GOS was working with was Motorola, not OnePlus as early speculations suggested. This is good news, Motorola is owned by Lenovo and makes cool phones! Reminder that Graphene OS is still based on AOSP and therefore, IMHO, eventually doomed to succumb to Google's shenanigans. However, for now and for the foreseeable future, that's the best we can have. #grapheneos #motorola #android #aosp #linux #pixel #google #enshittification #security #privacy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni First impressions of Mistral Small 3.2: seems pretty solid, it answers "uncomfortable" political question quite neutrally. I don't understand why #confer and #euria by #infomaniak are not based on this. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Heretic quantized versions of Qwen 3.5 have just been released but even the base Qwen 3.5 model seems to have issue with ollama currently, and I don't have bandwidth to do a manual patch now. Trying Mistral 3.2. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Going into the rabbithole of testing local LLMs right now. I don't have a dedicated GPU, but 32 GiB of RAM should be enough for anyone. #ai #huggingface #selfhost #localai #ollama #heretic #qwen #mistral npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I don't know if the news about the Palantir hack are true, but it is surely going to be popcorn time! #palantir #privacy #surveillance #hacking #usa #russia #china #conspiracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Conspiracy theory: I think LinkedIn's recommendation algorithm "deprioritizes" topics like this. I reposted the same content on my LinkedIn feed, and after two days it's not even 500 impressions. I'm not a big guy on social, but I regularly exceed 10'000 impressions on LinkedIn, with very few posts below 1'000. I think this is the lowest I've ever reached, and it's quite strange considering that it is a quite hot political + tech topic in the news. #linkedin #censorship #tiktok #epstein #politics #bigtech #conspiracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Wat. #surveillance #1984 #censorship #politics #bigtech #nottheonion #epstein #tiktok https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/966/391/562/500/468/original/448dd109cc92387d.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects’ laptops https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports/ Because, of course, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud, and it looks like you need to pay for the privilege of having the Pro edition if you want to have the option of opting out. Reject this BS. Use proper disk encryption! Or, even better, if you care about plausible deniability, use Shufflecake! https://shufflecake.net/ #shufflecake #truecrypt #veracrypt #microsoft #bitlocker #luks #security #privacy #fbi #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…ynf4 a bit of shameless self-promotion: it looks like we'll be able to launch a prototype for a fully hidden OS using #Shufflecake somewhere this year. And, no, we don't have an option for uploading encryption keys to "the Cloud" 😂 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni OMG this is killing me 🤣 The thread at https://x.com/beneater/status/2012988790709928305 is super hilarious (alt link: https://xcancel.com/beneater/status/2012988790709928305 ) #ai #ml #vibe #vibecoding #hallucination #circuits https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/922/730/623/082/787/original/e1de6c5aa58a4eb6.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni It looks like I am one of the few lucky folks randomly selected to take part in the Swiss Federal Survey for Mobility and Traffic. https://www.bfs.admin.ch/bfs/de/home/statistiken/mobilitaet-verkehr/erhebungen/mzmv.html The request is easy: 1) download and install a proprietary app from the App Store or the Play Store. 2) The app makes use of GPS tracking and other sensors to track in real time your location. 3) Never turn off your phone or put it in flight mode during the survey period assigned to you (usually one day per week). They are quite insisting too, I have already received the second solicitation begging me for my "invaluable help"! I mean... I am flattered but... I find it super hilarious that I was picked as a participant 😂 Of course I trashed the letter. #switzerland #privacy #android #apple #security #swiss #suisse npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…xhd4 @nprofile…7v08 it seems that it works if I use a YubiKey (Firefox on Linux). Quite inconvenient I must say, I understand security is important but shouldn't it be opt-in? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…khyj Now, that's an interesting interdisciplinary mix. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Signal creator Moxie Marlinspike wants to do for AI what he did for messaging. https://arstechnica.com/security/2026/01/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what-he-did-for-messaging/ The idea might sound nice, but there are caveats. First of all, PassKeys? This screenshot is what I see on my Firefox 146.0.1 on Linux. Hopefully I can use a FIDO2 token like a YubiKey instead? I will test it later. Second, the whole security seems to rely on TEEs, which are notorious for... well... https://en.wikipedia.org/wiki/Software_Guard_Extensions#List_of_SGX_vulnerabilities I'll be honest, I'm not sure AI assistants can ever be made really private, save for self-hosting open source models. But still, much much better than the current Gemini, ChatGPT, etc. Like Signal was not the perfect solution for IM but moved the world toward a better state overall, I wish @nprofile…7v08 all the best with Confer.to because it would be good for all of us. #ai #llm #signal #confer #yubikey #passkeys #linux #privacy #security https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/888/595/767/145/688/original/4e59fd2de2b2d61b.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I hope it's only a temporary glitch, but suddenly the UBS home banking login page does not seem to work on Firefox anymore (it works with Chrome). This also happens with a fresh Firefox install (no addons, mods, anything). If this is true, then this means that from now on, the largest Swiss bank only allows customers to use their home banking with either their proprietary app (which of course requires Google Play Protection and does not work on Graphene OS), or with a hardware token plus a US-megacorp controlled browser (Chrome, Edge, Safari). #ubs #switzerland #banking #enshittification #foss #floss #firefox #chrome #safari #edge #google #microsoft #apple #privacy #security #opensource #android #ios #grapheneos #lineageos https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/866/492/443/657/717/original/db26b66f997211a9.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni The Vietnam government has banned rooted phones from using any banking app https://xdaforums.com/t/discussion-the-root-and-mod-hiding-fingerprint-spoofing-keybox-stealing-cat-and-mouse-game.4425939/page-118#post-90441375 #vietnam #root #android #ios #lineageos #grapheneos #google #apple #enshittification #privacy #security #banking npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni European Commission issues call for evidence on open source: https://lwn.net/Articles/1053107/ The European Commission has opened a "call for evidence" to help shape its European Open Digital Ecosystem Strategy. The commission is looking to reduce its dependence on software from non-EU countries. #foss #floss #eu #politics #bigtech #digitalsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…u6wm I was with Commerzbank like 15 years ago, when it still didn't suck too much, but now I've been out of Germany for some time, so I really don't know what's there. But I recently saw a curated list on the GrapheneOS website of compatible banking apps, maybe you can start from there? Or even better, choose a bank that offers a hardware token as 2fa. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Commerzbank (one of the largest German banks) just banned GrapheneOS: https://discuss.grapheneos.org/d/28440-commerzbank-one-of-the-largest-german-banks-bans-grapheneos There is literally zero reason why banking apps shouldn't work on GrapheneOS, and yet so many European financial institutions prefer to rely on the security assurances of megacorporations controlled by a foreign country. At least I hope that the current geopolitical madness will contribute to stopping this plague. #google #android #aosp #grapheneos #lineageos #bigtech #enshittification #security #privacy #digitalsovereignty #usa #eu #europe #politics #germany #commerzbank npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Google will now only release Android source code only twice a year: https://www.androidauthority.com/aosp-source-code-schedule-3630018/ https://source.android.com/docs/whatsnew/site-updates?year=2025 Effective in 2026, to align with our trunk stable development model and ensure platform stability for the ecosystem, we will publish source code to AOSP in Q2 and Q4 Unclear how this will impact 3rd party ROMs like Lineage OS and Graphene OS... Just kidding! It's pretty clear how this will impact them in the long run. That's the whole goal of it. The only good news: Google [...] will keep publishing security patches each month on a dedicated security-only branch for relevant OS releases just as it does today. It's really time to move away from megacorp-controlled OSes and embrace really open source alternatives, both for personal and institutional use. It's not just a matter of privacy and security, but, most importantly, national security and self-sovereignty, especially with the current geopolitical turmoil going on. The ship is sinking. #google #android #aosp #grapheneos #lineageos #bigtech #enshittification #security #privacy #digitalsovereignty #usa #eu #europe #politics https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/852/872/051/252/517/original/a8d37c3646775d54.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni "Unfortunately We Are Unable To Provide Feedback" No, you're not "unable", you are unwilling. And this is not OK. https://gagliardoni.net/#20251227_nofeedback Many cybersecurity and Web3 conferences refuse to provide an explanation of why a submission was rejected. The argument is that it would be too much time consuming due to the large volume of applications, but in this blog post (which is both a rant and an open letter) I make the point that this is just an excuse, and it's due time to change this behavior. It's not only a lack of respect for the community, but also a red flag about the transparency of the review process. Please be better than this. #cybersecurity #security #infosec #web3 #rant #academia npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…pqg8 @nprofile…7m8a I'm not sure whether moving to Vivaldi makes sense or not, but this is a very wise sentence: uBlock Origin [...] is the most important extension for being able to browse the web nowadays. Seriously, recently I happened to browse random stuff from a "normie Chrome" and, fuck my life, how do people manage to live with that? No wonder everybody seems to be getting crazier by the day. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…hlh9 I visited https://bastyon.com just out of curiosity and Думаю, это привело к развитию у меня деменции головного мозга. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…pjjl I know, right??? And for some reasons a lot of people call me "Matteo"! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Imagine your name were "Jon" and everybody kept misspelling your name as "John". This is how I scream internally whenever people call me "Tomasso". npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…n926 I shouldn't post in a flamebait thread, but here are my few data points: 1) I am Italian, born and raised in a small city in Central Italy. My grandfathers were farmers, my grand-grandmother passed away when I was 13 years old. 2) I can guarantee 100% that, in my family, recipes do get passed generations by generations, from granma to grandchildren. 3) I have personally met people who still make this as a family recipe: https://en.wikipedia.org/wiki/Testaroli 4) Most Italians I know cringe when they see how "immigrant Italian cuisine" looks like. Let me rephrase: What a foreigner calls "Italian cuisine" is not what I call "Italian cuisine". 5) The reason for 4) is undoubtedly the "marketing" component, and I agree that many of the "iconic" dishes that are considered "Italian cuisine" in folklore come from the 50-60's. 6) That said, Alberto Grandi is a notorious troll who literally made a career out of overinflating sensationalistic claims with the precise goal of feeding the flames. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…l8gu extremely cool, thanks! Just one question: I see you mention Ed25519 specifically. Any chance of considering some form of crypto agility for signatures? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Hey #mastodon this is something to look at! @nprofile…l8gu just announced v0.1.0 of their key transparency specification for the Fediverse! https://soatok.blog/2025/12/15/announcing-key-transparency-fediverse/ This is an incredibly useful project, something really missing in a robust decentralized architecture. #fedi #fediverse #crypto #cryptography #authentication #security #federation #digitalsovereignty #digitalselfsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I just found this cool video explaining the DIffie-Hellman cryptographic key exchange with the analogy of mixing colors! I was not aware of this neat explanation! Cute! https://youtu.be/YEBfamv-_do?t=160 #crypto #cryptography #security #privacy #education #video npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I just received a letter from the Swiss Confederation about a "Mikrozensus Mobilität und Verkeher". Basically they ask me to participate in a survey by installing a tracking app on my phone to report my location as I drive my car around. GIGALOL #switzerland #privacy #madness npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Dear #Mastodon can someone explain me why sometimes a thread gets "broken" and I cannot access part of it anymore? Example: I toot "A", other users reply to the toot as "B" and "C", and I reply to both with "BA" and "BC", respectively. After some time I see that my original thread only shows one "branch": it has become A->B->BA. The other branch still exists, I can see it from my "posts and replies" feed, but it appears as detached from the main "A" thread. What's going on? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Mastodon users: please, please remember to tag your toots with the correct language. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…g38k @nprofile…9dq6 @nprofile…rjdn Yes, I saw the announcement via Hacker News, this is great, I'm keeping my eyes on that! Totally agree that the way forward is beyond Android. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…d3h0 @nprofile…dwhh thanks for the clarification, will keep this in mind. What features does it have that improve on Signal? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…7yjy @nprofile…dwhh no contradiction here: as I wrote in my blog post, "I admire Soatok and I think he's right on many things. I also think he's wrong on many other things". Among the things I disagree with, is that one should only focus on the "protocol security" of an IM (where Signal clearly wins). npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…92wj yes, I need to do a part 2 of that blog post, and Delta Chat is something I will cover for sure. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…dwhh well, it's a bit like Signal (centralized) but paid, and with worse security: https://soatok.blog/2021/11/05/threema-three-strikes-youre-out/ See also this discussion: https://discuss.privacyguides.net/t/threema-instant-messenger/1679 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Oh, this is so f***ing gold. This post is a juice concentrate of the many reasons why Matrix sucks: https://yaky.dev/2025-11-30-self-hosting-matrix/ Among others: Users cannot be deleted This is simply not an option in the API. Server admin can perform a "deactivate" (disable login) and "erase" (remove related data, which claims to be GDPR-compliant) on user accounts, but the accounts themselves stay on the server forever. LOL. Here is my take on why you should trash Matrix and use XMPP, or ta least Signal instead: https://gagliardoni.net/#im_battle_2025 #im #matrix #jabber #xmpp #signal #privacy #security #enshittification #cypherpunk npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…x0rg yeah OK, maybe "cloud services" is a bit oversimplifying, but it's correct enough in spirit I think. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni In a rare show of sanity, the Swiss Data Protection Officer has severely restricted the use of international cloud services – particularly hyperscalers like AWS, Google, or Microsoft – for Swiss federal authorities! https://www.heise.de/en/news/Switzerland-Data-Protection-Officers-Impose-Broad-Cloud-Ban-for-Authorities-11093477.html #security #privacy #cloud #politics #digitalsovereignty #bigtech #google #aws #microsoft #azure #amazon #switzerland npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…mkrw Sorry, I don't want to share my opinion on the matter, just posting to be on this thread which has the potential to achieve legendary divisiveness status 😂 Kidding apart, one argument I didn't see discussed which is potentially against hybrids, at least for encryption, is the possibility of better kleptographic attacks: https://eprint.iacr.org/2022/1681.pdf The idea is that you can design a circuit that uses e.g. ECDH to embed kleptographic data on ML-KEM public keys. In a pure ML-KEM hardware implementation, this would be easy to spot, because of the conspicuous amount of EC-related circuitry that shouldn't be there. But with a hybrid, that's much more difficult to spot. DISCLAIMER: I AM NOT ARGUING FOR HYBRID VS NON-HYBRID, JUST REPORTING THE FACT, FOR THE LOVE OF GOD PLEASE DO NOT JUMP AT MY THROAT. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Sorry, I don't want to share my opinion on the matter, just posting to be on this thread which has the potential to achieve legendary divisiveness status 😂 Kidding apart, one argument I didn't see discussed which is potentially against hybrids, at least for encryption, is the possibility of better kleptographic attacks: https://eprint.iacr.org/2022/1681.pdf The idea is that you can design a circuit that uses e.g. ECDH to embed kleptographic data on ML-KEM public keys. In a pure ML-KEM hardware implementation, this would be easy to spot, because of the conspicuous amount of EC-related circuitry that shouldn't be there. But with a hybrid, that's much more difficult to spot. DISCLAIMER: I AM NOT ARGUING FOR HYBRID VS NON-HYBRID, JUST REPORTING THE FACT, FOR THE LOVE OF GOD PLEASE DO NOT JUMP AT MY THROAT. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…e72p Elia and I have bee quite under the water recently, but we've been quietly working to this new release - mostly Elia, TBH :) In addition to the long due test units and dev guide, we worked a lot on FLUSH and FUA requests for block device I/O. We got SCARY performances, very close and at times beyond dm-crypt in fio tests! I think it is safe to say that performances won't be our priority from now on (at least for the Lite scheme), and we can keep focusing on new features and the roadmap to our Holy Grail: a fully hidden Linux OS! #shufflecake #crypto #cryptography #privacy #veracrypt #plausibledeniability #linux #cypherpunk npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni The results of the 2025 elections for the president and board members at the International Association for Cryptologic Research (IACR) have been botched because the results of the super-secure cryptographic e-voting system cannot be retrived due to the "accidental loss" of a decryption key. https://iacr.org/news/item/27138 While human mistakes happen, this accident comes under very troubling circumstances. Why an e-voting system of an association like IACR does not support t-out-of-n threshold decryption? Why is a system where a single party can collude to invalidate the vote considered acceptable? Wouldn't be wiser to freeze to the date of November 20th the eligibility status for voting instead of "calling to arms" IACR members who had previously decided to opt out from Helios emails? Does the identity of some of the candidates to Director represent a problem for IACR? #iacr #crypto #cryptography #politics #evoting npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni WTF IACR? Conspiracy intensifies... #iacr #helios #crypto #cryptography #politics #conspiracy https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/592/491/313/950/743/original/55b777ee4331eb01.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni BTW, it's funny, sometimes I duplicate also on LinkedIn the same posts that I write on Mastodon and that link to my website (so-called POSSE philosophy), and every time I rant about bad AI or Big Tech I get much more reactions and engagement on Mastodon than on LinkedIn. I understand the audience is very different but it feels almost... if... LinkedIn's algorithms do not want to show around some topics too much? Conspiracy intensifies. #conspiracy #linkedin #mastodon #bigtech #ai npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…4e5a what tshirt is that? Curious :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting take from Christopher Butler on " What AI is Really For". https://www.chrbutler.com/what-ai-is-really-for The best case scenario is that AI is just not as valuable [...] The worst case scenario is that the people with the most money at stake in AI know it’s not what they say it is. The observation is that, while the AI bubble might burst, the multibillion deals for building datacenters will hand over ownership of energy infrastructure, land and water to a few individuals. Forever. The value of AI can drop to nothing, but owning the land and the flow of water through it won’t. #ai #ml #capitalism #politics #dystopia #technocracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…nlrw @nprofile…87np @nprofile…nguw @nprofile…z26c @nprofile…s38p @nprofile…x90w @nprofile…h5vr I feel your pain. It's really hard to spend time and energy over and over again to fight this BS. I think we're on the right track by spreading the voice and joining initiatives such as the ones against ChatControl, I also did my part by sending letters to Italian politicians and I might do the same about #omnirape if the proposal gets presented. For now this is a call to arms and signaling to everyone reading this that, no, we're not OK with this, and we'll do everything we can to fight back. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Look, I even felt creative today! https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/530/480/244/257/158/original/fc08ae0f3677fd4a.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Here's another thing I didn't need today: "Digital Omnibus". EU antitrust chief Henna Virkkunen will present to the EU Commission on November 19th a series of amendments to European data protection guardrails, which would substantially weaken GDPR and other privacy protections, and explicitly allow large AI companies unlimited access to the data of EU citizens and even to their digital devices. This is done in order to "placate US industry" (yes, seriously), and proposed through a stealthy "fast-track procedure", which we know of only because some media outlets obtained a leaked draft of the proposal. https://gagliardoni.net/#20251111_digital_omnirape "Digital Omnibus" is not a catchy term, we need something better. I propose "Digital Omnirape". Here are some scary quotes: According to the plans, Google, Meta Platforms, OpenAI and other tech companies may be allowed to use Europeans' personal data to train their AI models based on legitimate interest. In addition, companies may be exempted from the ban on processing special categories of personal data [religious or political beliefs, ethnicity, sexual preferences, or health data]. Companies can now remotely access personal data on your device for [...] "legitimate interest". Consequently, it would be a possible reading of the law that companies such as Google can use data from any Android apps to train it's [sic] Gemini AI. One massive change (on German demand) is to limit the use of data subject rights (like access to data, rectification or deletion) to "data protection purposes" only. Conversely, this means that if an employee uses an access request in a labor dispute over unpaid hours – for example, to obtain a record of the hours they have worked – the employer could reject it as "abusive". The same would be true for journalists or researchers. #digitalomnibus #digitalomnirape #omnirape #eu #politics #gdpr #privacy #ai #google #meta #facebook #openai #ml #lobbying npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni You will be SHOCKED to know that a NONZERO number of Italian politicians replied to the letters I sent by post last month last month to speak up against ChatControl! https://gagliardoni.net/#20251106_chatcontrol_butti #chatcontrol #privacy #eu #italy #politics npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Great article by F-Droid on "What We Talk About When We Talk About Sideloading". https://f-droid.org/2025/10/28/sideloading.html A few excerpts: It bears reminding that “sideload” is a made-up term. Putting software on your computer is simply called “installing” [...] the term “sideload” was coined to insinuate that there is something dark and sinister about the proces You, the consumer, purchased your Android device believing in Google’s promise that it was an open computing platform and that you could run whatever software you choose on it. Instead, starting next year, they will be non-consensually pushing an update to your operating system that irrevocably blocks this right and leaves you at the mercy of their judgement over what software you are permitted to trust. You, the state, are ceding the rights of your citizens and your own digital sovereignty to a company with a track record of complying with the extrajudicial demands of authoritarian regimes #google #android #aosp #security #privacy #enshittification #bigtech #opensource #politics #fdroid npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Great article by F-Droid on "What We Talk About When We Talk About Sideloading". https://f-droid.org/2025/10/28/sideloading.html npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…745p yes, I know, I avoided the hassle so far because the old modem they gave me was pretty good, but now I guess I'll have to do that. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Ah, the joys of calling my ISP's support number to complain that the new fiber modem they sent me is as configurable as a tamagotchi, and spending 15 minutes at the phone with the operator trying to let her understand that, yes, I have already tried clicking on the top white bar of my browser, digited 192.168.1.1 and pressed ENTER. #sunrise #switzerland #isp #annoying #tech #tamagotchi npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…us0z yes, I did not mean to bash AWS in particular, it could have been anyone else. My point is that decentralized systems are way less suceptible to this kind of issues. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…wqsx just to be clear, I think OMEMO encryption is basically fine enough, but not everyone is of the same opinion: https://soatok.blog/2024/08/04/against-xmppomemo/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…cr4r I and most of my contacts were. I guess it depends on your geographic area. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Today's AWS debacle is the perfect example of the reason why in the last few years I started to be less enthusiastic about Signal, and more oriented to federated or even P2P solutions like XMPP and Jami. I wrote about it already: https://gagliardoni.net/#im_battle_2025 Signal was down for few hours today, after an aoutage that affected AWS: https://mastodon.world/@Mer__edith/115405436746725236 Let's ignore for a second the blind reliance on AWS or any other cloud provider. In a decentralized system, this would not have happened, or at least it would have not impacted so many users. Yes, I am a cryptographer myself, I know that Signal's encryption is the best. But encryption is not everything. Availability issues, geopolitical troubles, risk of enshittification, limitations on users' freedom to use and control the software lead to a lack of trust, even in a supersecure solution. And I say that with honest admiration for the folks at Signal, who are doing a great job. May they prove me wrong over and over again. #signal #im #aws #amazon #privacy #security #digitalsovereignty #selfhosting #fediverse #federation #p2p #enshittification #xmpp #jami #politics #opensource #freesoftware #libre npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Ah, the joys of half of the internet relying on AWS because "Cloud". Among too many other things, also Signal is down. https://mastodon.world/@Mer__edith/115405436746725236 #aws #amazon #outage #cloud #down #signal npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Here is my morning trying to convince Gemini that, no, the --discard option in Debian's losetup is pure hallucination. #ai #ml #hallucination #linux #debian #opensource #google #gemini https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/405/629/866/660/009/original/6db4fe45e746b730.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…0kmn it's many different obstacles, to name three: the fact that most apps people use are deeply integrated in the Play Store, the fact that AOSP security patches are released by a Google team, and too many binary blobs. But, in general, it's really the Android model that sucks. The whole idea that, in order to be considered "secure", users should not be allowed to unlock their bootloader and install whatever apps they want, is bollocks. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Some big news regarding mobile OSes: First, Graphene OS has confirmed a partnership with a large OEM to bring support to non-Pixel devices (Snapdragon SoC): https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-exclusivity-new-oem/ This is good news, but IMHO it only delays the unavoidable demise of free AOSP-based projects since Google is now finally pulling the rug. Second, the FSF announced Librephone, an initiative to bring real freedom to mobile devices: https://www.fsf.org/news/librephone-project This is also good, but it must be taken in the right perspective: Librephone, as far as I understand it, is not a new mobile OS, but rather an initiative to open-source existing proprietary firmware blobs. AOSP-based open source OSes like Lineage, Graphene, and even /e/OS, will hopefully benefit from this initiative, by being able to replace binary blobs with open-source firmware. But they still remain AOSP-based solutions, and therefore bound to the Google ecosystem. There are two problems here that really need to be addressed. The first one is political. Legislators and citizens must come to acknowledge that a democratic society where the full mobile ecosystem is in the hands of a corporate duopoly is not acceptable. The second one is technological: AOSP is not a fully free OS, it's a trojan horse, a trap set by Google years ago that is springing right now. We need to move away from Android and embrace full GNU/Linux solutions, or even something completely new, at this point I don't even care. I've heard good opinions of Postmarket OS. Any feedbacks here? Say what you want about Richard Stallman, but he saw this coming. #android #aosp #google #lineageos #grapheneos #eos #postmarketos #libre #foss #floss #opensource #privacy #security #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Stop calling it "sideloading". Call it "installing" instead, as it should be. If you're "installing" from the Play Store, call it "Googleloading" instead. Word choice is important. Make the legislators understand what's going on here. #google #android #aosp #politics #enshittification #surveillance #sideloading #control #antitrust #monopoly #privacy #digitalsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…j5lu "i need to access my email every time" is that such a horrible thing? For me, yes, for the reasons I wrote above. Even if one doesn't care about security, at least should care about waiting those extra 2-10 seconds to receive email, open it, read code, input code. or of course people just never logout, and never have to face this email/login dance very often at all? Well, beyond being bad security practice (and of course we can argue whether a booking.com login is sensitive enough or not, I'd rather not risk my kids accidentally booking a stay at the Hilton that split second that I get distracted away from the keyboard), this wouldn't work for people, like me, who mostly browse on Incognito. Part of me thinks that this might be the real reason for website adopting this monstrousity: adding extra friction for privacy conscious users. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…j5lu in not particular order: slower more annoying unencrypted I need access to my email every time The last point is particularly painful in certain setups. For example, if I travel to some problematic countries I would rather bring a burner phone with minimal personal accounts on it. But then, if I want to use, say, Booking.com, now I have three options: 1) use their fantastic mobile app 2) also keep on my burner phone the credentials for my main email 3) register my Booking,com account with ANOTHER, lower security tier email. Option 3) might sound wise, but then remember that you have to do this for EVERY website that uses this cursed method of authentication. Which, don't get fooled, it's only done BECAUSE it's 2025 and websites (and their users) can't get a grasp of 2FA, websites need to enable it for compliance, but users don't want it. So the genius solution is to say "we don't need to enable 2FA authentication for our users, because their 2FA is their email". npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…tm69 this login method is so wrong for so many reasons I don't even know where to start cursing. I will probably write a blog post about it. TL;DR it's just for compliance: they can say they don't have the burden of authenticating the user, because that burden is now unloaded on the email provider. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni May whoever invented the "We sent a one-time login code to your registered email address" login method find a little dog turd in their sandwich. #security #hacking #curse #rage #compliance #humor #annoying #email #authentication npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Finally some good news! I feel I really needed them! We are finally able to write with good news! The Member States could not find a consensus in their meeting today, and the planned vote to approve a chat control regulation has been removed from next week's agenda of the ministers of home affairs. In other words: no version of chat control will be accepted for now. (from the academic open letter initiative at https://csa-scientist-open-letter.org/Sep2025 ) #chatcontrol #privacy #eu #politics #civilrights #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…6w56 They finally fixed it tonight on Beta. Beyond a serious bug like this slipping unnoticed from nightly to beta, it took 5 days to fix. For Mozilla. It makes me feel more confident of how we treat these thing on Shufflecake 😅 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…r0kn 100% this, I moved all my domains away from Gandi since it went south. Not to Porkbun though, but to EU-based registrars instead 😛 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…skc4 check this: https://gagliardoni.net/#im_battle_2025 Summing up, in my personal opinion: XMPP > Signal > Matrix > Anything else. The situation is not optimal I haven't included Delta Chat, Simplex, and Jami in the comparison. This is WIP but what I wrote might already be a good start for you. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…ddc2 @nprofile…rsu8 what? Seriously? I was not aware of that, I only used Accrescent as a user on my Graphene OS. This surely is troubling if true. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Anyone involved in the program committee or community of the International Journalism Festival? I would like to propose something but I have a few questions. #IJF #ijf26 #ijf2026 #ijf26speaker #journalism #internationaljournalismfestival #festivalinternazionaledelgiornalismo npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…ve0p Yes it's 144b9 for me as well, the bugzilla tracker is inundated of reports, so it's definitely not just me 😅 waiting for 145 to be pushed on Beta. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…hn22 ah, yes, the Lizard People npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni It looks like it started 3 days ago on Nightly even: https://www.reddit.com/r/firefox/comments/1nxmrec/firefox_nightly_for_android_keeps_asking_to_open/ @nprofile…muyw npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni What's going on with Firefox Beta on Android? Tonight my Fenix installed through Obtainium on my de-googled Graphene OS did an update, and since then I cannot open it anymore. The crash log contains an ominous: Caused by: com.google.android.play.core.review.ReviewException: -1: Review Error(-1): The Play Store app is either not installed or not the official version. (https://developer.android.com/reference/com/google/android/play/core/review/model/ReviewErrorCode.html#PLAY_STORE_NOT_FOUND) It seems caused by the PlayStoreReviewPromptController which occasionally asks you to rate Firefox Beta on the Google Play Store. Is it just me? I filed a bug report. #mozilla #firefox #google #degoogle #obtainium #neostore #fdroid #grapheneos #android #aosp #playstore #bug #ads #enshittification npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I just received this update on ChatControl from @carmelatroncoso @nprofile…x59z @nprofile…yfc9 and Anja Lehmann: Here is a new update. As you might know, there is no consensus still on the Chat Control regulation. The next two weeks are crucial. On October 8th there will be a non-public meeting where states will reveal their vote intention, with an actual vote on October 14th. [...] As of today, we have no guarantee that the regulation will be rejected. In fact, we have never been closer to acceptance, as several countries with major impact on the vote are reverting their previous position to reject or abstain. [...] What would help right now is to either raise more public awareness, for example through the press, to put public pressure on governments; or directly contact your representatives, opposition parties, or relevant ministers, to bring awareness to the issues. [...] And we have created an FAQ to make it more accessible to press and politicians: https://csa-scientist-open-letter.org/FAQ [...] If you can spare time to take any of the above actions, please do. Every little push counts. [...] Countries that are opposing the Danish chat control text: Austria - strongly opposing Poland - strongly opposing Luxembourg - strongly opposing Estonia - but needs support to stay opposing Czechia - but needs support to stay opposing Countries that are undecided, abstaining or ambivalent - need to be pressured: Italy – undecided, we think there is a chance for an abstention Finland – undecided / rumoured to be opposing, we think there is a decent chance for opposition Germany - undecided / rumoured to be close to acceptance Netherlands – they are confirmed abstention, this cannot change in time for the vote Latvia – rumoured to be opposing, but the last official notes showed them supporting Greece – silent, but have supported in the past Slovenia – silent, but have opposed in the past Countries that have only recently started supporting the Danish text, or that support it but have had concerns, so could maybe be convinced to change position, or at least abstain: Belgium - recent support France - recent support Lithuania Croatia Malta Portugal It doesn't look good. Not at all. Please do anything you can, this situation is so ridiculous that I find it difficult even to explain it to Average Joe. #chatcontrol #eu #politics #privacy #security #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni We have to stop the Google/Apple mobile duopoly. And we have to stop the marching enshittification of society. More concretely, we have to fight back against Google's attempt to lock-down the whole Android ecosystem. https://f-droid.org/2025/09/29/google-developer-registration-decree.html This is something that any sane regulatory body should forbid. #google #apple #android #aosp #fdroid #privacy #security #enshittification #surveillance #mobile #politics npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni This is getting ridiculous: https://mastodon.social/@chatcontrol/115204439983078498 Danish Minister of Justice and chief architect of the current Chat Control proposal, Peter Hummelgaard: "We must break with the totally erroneous perception that it is everyone's civil liberty to communicate on encrypted messaging services." #chatcontrol #eu #politics #privacy #civilrights #security #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Did I just send 25 letters by recorded post to representatives of the Italian government, parliament, and EU institutions, speaking out against ChatControl? https://gagliardoni.net/#20250913_chatcontrol_letters Yes, it looks like I did. #chatcontrol #eu #privacy #surveillance #security #politics #cryptography https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/198/030/777/617/278/original/fcfc9f158e4c498b.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Oh, I like this: https://swiss.social/@swaldorff/115186445638788782 Interesting: a Danish supermarket chain is setting up "Emergency Stores" that can keep open for up to three days without power or telecom and store an expanded stock of non-perishable food and essentials. The idea is that no one should be more than 50 km from such a store and it should prevent hoarding/panic buying as people will know basic food will be available in an emergency. #prepping #selfsufficiency #war #security #resilience #denmark #eu npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Today I discovered the word "dingleberry". Fun fact, there is a perfect 1:1 translation of the word in Italian: it's called "tarzanello" (little Tarzan, for obvious reasons). #ud_dingleberry #tarzanello #humour #disgusting #nsfw npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Following the success (sarcasm!) of my previous post "Battle of IMs", I decided it's time to write another post where I try to articulate in a technical but snarky way my view on the wonderful world of social media, and which one is best among the mainstream and non-mainstream ones. This is a long post, reviewing 14 different "socials". https://gagliardoni.net/#20250818_battle_of_socials #socialmedia #social #privacy #selfsovereignty #security #digitalsovereignty #mastodon #nostr #bluesky #ssb #securescuttlebutt #facebook #meta #tiktok #threads #x #twitter #diaspora #friendica #linkedin #xing #instagram npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I just noticed that ioc.exchange warrant canary has been dead since March. https://ioc.exchange/about I wonder how meaningful canaries are, especially in the context of platforms like Mastodon. I mean, the bar to keep them alive is pretty high: "never provided any law enforcement organization logs/feed of our customers' content". I would expect these things to be the norm for a social media instance. #mastodon #canary #security #privacy #iocexchange #lawenforcement npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…npq2 it's an amusing read, but very flawed. https://gagliardoni.net/#20250714_ludd_grandpas npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…m5w3 🤦♂️