Cryptography, privacy, quantum security, infosec, retro vibes. I am a mathematician and computer security scientist, with a strong interest in cryptography and anonymity, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner. I co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution. I am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism. Fascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote "fascinated", not "knowledgeable". Here you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!
Public Key
npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Profile Code
nprofile1qqswf63vq5twdpdvywsxa0t7us2ajdn729uusxh2p6mw76vjvnnrkvgpz4mhxue69uhhyetvv9ujumt0wd68ytnsw43qz9thwden5te0wfjkccte9ejxjar5duh8qatzn0dtd8
Show more details
Published at
2026-07-24T08:19:50Z Event JSON
{
"id": "b69eb123cf3bbcd2cebc43081d42ac253b4924262fbe8f973eb2294676fb87e9" ,
"pubkey": "e4ea2c0516e685ac23a06ebd7ee415d9367e5179c81aea0eb6ef699264e63b31" ,
"created_at": 1784881190 ,
"kind": 0 ,
"tags": [
[
"proxy",
"https://infosec.exchange/users/tomgag",
"activitypub"
],
[
"client",
"Mostr",
"31990:6be38f8c63df7dbf84db7ec4a6e6fbbd8d19dca3b980efad18585c46f04b26f9:mostr",
"wss://relay.ditto.pub"
]
],
"content": "{\"name\":\"Tommaso Gagliardoni\",\"about\":\"Cryptography, privacy, quantum security, infosec, retro vibes.\\n\\nI am a mathematician and computer security scientist, with a strong interest in cryptography and anonymity, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner.\\n\\nI co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution.\\n\\nI am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism.\\n\\nFascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote \\\"fascinated\\\", not \\\"knowledgeable\\\".\\n\\nHere you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!\",\"picture\":\"https://media.infosec.exchange/infosec.exchange/accounts/avatars/110/680/679/712/333/612/original/9ff79cc367140f23.jpg\",\"banner\":\"https://media.infosec.exchange/infosec.exchange/accounts/headers/110/680/679/712/333/612/original/91487e2c36283f3d.jpeg\",\"nip05\":\"[email protected] \",\"fields\":[[\"Homepage\",\"https://gagliardoni.net/\"],[\"Linkedin\",\"https://www.linkedin.com/in/tommasogagliardoni/\"],[\"Shufflecake\",\"https://shufflecake.net/\"],[\"My own company\",\"https://www.lucumo.net/\"]]}" ,
"sig": "6b4af0ddc34cb951810e24d4c78ec1f2dc7fd92461cceb2befc7fbde1a29f8dae776f53e75626b5ad2ba79828b782178eb1e67fd6c354702469d273ee5c8ebe5"
}
Last Notes npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni It begins: https://マリウス.com/i-regret-migrating-to-codeberg/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni The day quantum computers break the first cryptographic key I'm gonna go full rampage and publicly name and shame all the snarky folks who identify themselves with the "QC/is/bullshit" gender. I am taking notes on my list, mind you. Your name is there as well. Revenge is best served at 0.02 Kelvin. #crypto #cryptography #infosec #quantum #quantumcomputing #qc #drama #humor npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni VeraCrypt to stop developing Windows application due to Microsoft revoking their driver signing certificate: https://sourceforge.net/p/veracrypt/discussion/general/thread/9620d7a4b3/ Sorry to hear about this turn of events, but it was pretty much to be expected given the way the world is turning, and Microsoft being Microsoft. Switch to Linux if you can, and come give Shufflecake a try ;) #veracrypt #truecrypt #privacy #cryptography #plausibledeniability #shufflecake #microsof #windows #enshittification #surveillance #cypherpunk npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Legal disclaimer: this was, obviously, an April Fool's. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I am happy to share that, as of today, I am starting a new position as Head of Cryptography at Palantir! I will join a team of great researchers with unmatched talent and pragmatically flexible ethics. Our mission is to drive innovation and make sure that security and privacy are available to everyone without needlessly hindering the legitimate collection of data to improve user experience and safeguard national security! #aprilsfools #april #1april #palantir #privacy #cryptography #crypto #surveillance #socialmedia npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…uvmw from a quick look, this seems a bit... audacious? under plausible assumptions, the runtime for discrete logarithms on the P-256 elliptic curve could be just a few days for a system with 26,000 physical qubits npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni New breakthrough results for quantum attack resource estimates against 256-bit elliptic curves: most ECC-based applications including ECDSA and Bitcoin could be at risk way sooner than expected: https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/ "We estimate that these circuits can be executed on a superconducting qubit CRQC with fewer than 500,000 physical qubits in a few minutes [...] This is an approximately 20-fold reduction in the number of physical qubits required to solve ECDLP-256" I have been saying this since the 2010s: quantum cryptanalysis is one of those non-linear technology progresses that will take everyone by surprise when it arrives. Qubits quality and numbers go up, error-correction and attacks improve, investments scale up accordingly. It's a perfect storm of compound factors. Folks didn't listen, now time is ticking. #quantum #quantumcomputing #cryptography #security #cybersecurity #infosec #google #bitcoin #blockchain #ethereum npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Another Friday afternoon. #politics #usa #iran #war #trump https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/302/030/489/733/803/original/67a2c45048c500b9.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…9k5f no worries, I know it's normal to assume people don't use UO, although to be honest I always wonder how they survive on the internet without :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…9k5f Notice this is from Switzerland. In other non-GDPR aligned countries you would probably not even see the consent prompt. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…9k5f I have always Ublock origin on. This is regardless of. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Dear LinkedIn, It is great that you respect my privacy. But I'm confused: I thought I had previously already denied AT LEAST 89 OTHER TIMES my consent for you to profile me, track me with 3rd party cookies, anally probing me, and generally making my life a bit more miserable. To you and all the other countless buffoons out there: could you please kindly f**k off? #linkedin #privacy #ad #gdpr #enshittification #consent https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/288/918/051/802/631/original/5535bb1b8527996a.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…cd93 yes, I mean 2FA for webmail. Not for the mailbox itself (that wouldn't make sense since there is no 2FA for the POP/IMAP access) but fo rthe admin panel, which I consider more sensitive. So far I have tried "in-depth" Infomaniak, Mailbox, and Mailfence. They all have pros and cons, but overall they work well, I didn't have any problem reaching any other email address. Of the three, I have found Mailfence a bit more limited/buggy, although still OK-ish. I have no experience in mail self-hosting, sorry, that is somewhere in my "When I will be a grown-up" list :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting paper on Eprint: A Quantum-Safe Private Group System for Signal from Key Re-Randomizable Signatures https://eprint.iacr.org/2026/453 E2E encryption in group chats is complex, because security should be many-to-many while allowing for large, dynamic groups. Signal uses state of the art cryptography for this, but it's mostly based on discrete log, so quantum-vulnerable. This paper proposes a new, efficient quantum-resistant construction for this task. A few caveats by having just a quick skim at the paper: 1) Not everything is quantum-resistant, only parts of the protocol, namely those inherent to privacy. Authentication, instead, is left quantum-vulnerable. The rationale is that harvest-now-decrypt-later attacks are of a more immediate concern, and partial patching allows to not degrade performance too much. While this is a sensitive and pragmatic choice, I think the security community should stop underestimating the danger of trust-now-forge-later attacks, i.e. those involving signatures/authentication: In real-world scenarios, those would probably be much more dangerous than "we'll just switch to PQ signatures when quantum computers arrive". The paper considers this as well, though, as the choice of authentication mechanisms is modular, thereby providing crypto agility. 2) The role of the central server is still crucial to ensure correct execution of the protocol. This is just a reminder that Signal, at the end of the day, is a centralized service. It's way, way better than your Whatsapp, but if centralization is a concern, please consider federated or peer-to-peer alternatives (although Signal's encryption is undoubtedly the gold standard for now). #signal #cryptography #privacy #security #im #whatsapp #quantum #quantumcomputing #postquantum #pqc npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Hard LOL https://www.bye-dubai.com/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…5kt4 better than nothing, no? I mean, what's the alternative? 1) keep using Pixels only 2) use a still immature Linux mobile OS 3) embrace enshittification. It's not that I don't agree, mind you, but at this point any good news is good news IMHO. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…udtr good point! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…nqv0 @nprofile…px8j I agree, but I think this announcement points exactly at the fact that Motorola agrees to produce phones that meet GOS' stringent security features, even if no model has been released yet that's good news. In other words, this should mark the beginning of exactly what you said: avoiding reliance on Pixel phones only. Thread on the GOS forum from a few min ago: https://discuss.grapheneos.org/d/32656-motorola-partnership-announcement npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…px8j your choice I guess, but just FYI, I've been on GOS on Pixels for years and they work flawlessly. Only two things don't work: contactless payments (blame Google and politics, not GOS) and CERTAIN banking apps. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…px8j good news for you then: once you install GOS on it, bloatware will become a thing of the past :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…5kt4 Yes, I think that's the best part: Motorola phones are great hardware-wise but have terrible updates cycle. Graphene OS fits perfectly there, because they are only subject to the much faster AOSP release cycle! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni This made me chuckle, but also made me angry, because it's SO TRUE. The Norwegian Consumer Council, a government funded organization advocating for consumer's rights, released a report on the trend of "enshittification", and a funny four-minute video: A Day in the Life of an Ensh*ttificator https://www.youtube.com/watch?v=T4Upf_B9RLQ #enshittification #capitalism #norway #eu #politics #funny npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Motorola announces partnership with Graphene OS to bring us secure phones! https://motorolanews.com/motorola-three-new-b2b-solutions-at-mwc-2026/ So the mysterious manufacturer GOS was working with was Motorola, not OnePlus as early speculations suggested. This is good news, Motorola is owned by Lenovo and makes cool phones! Reminder that Graphene OS is still based on AOSP and therefore, IMHO, eventually doomed to succumb to Google's shenanigans. However, for now and for the foreseeable future, that's the best we can have. #grapheneos #motorola #android #aosp #linux #pixel #google #enshittification #security #privacy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I'm no particular fan of Anthropic, but seeing some spine in this timeline is... refreshing for once. https://www.anthropic.com/news/statement-department-of-war #anthropic #ai #darioamodei #hegseth #pentagon #trump #usa #politics npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting, it seems that Qwen 2.5 Coder is actually less aggressive than Qwen 3.5 in rejecting sensitive topics. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/136/585/450/107/128/original/921b30cb557870a9.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…8gzl I'm not sure, I don't have any beefy GPU 😅 you shoulkd ask this in the Ollama Reddit community (or similar). npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting, it seems that Qwen 2.5 Coder is actually less aggressive than Qwen 3.5 in rejecting sensitive topics. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/136/553/515/645/619/original/8d34f5e00873b438.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…gljh well, I'm running on local CPU with 32 GiB of RAM, so I wouldn't call it "fast". 3-5 tokens per second maybe? I guess it's OK if you give it a task and then go to grab a coffee 😅 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni First impressions of Mistral Small 3.2: seems pretty solid, it answers "uncomfortable" political question quite neutrally. I don't understand why #confer and #euria by #infomaniak are not based on this. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Heretic quantized versions of Qwen 3.5 have just been released but even the base Qwen 3.5 model seems to have issue with ollama currently, and I don't have bandwidth to do a manual patch now. Trying Mistral 3.2. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Going into the rabbithole of testing local LLMs right now. I don't have a dedicated GPU, but 32 GiB of RAM should be enough for anyone. #ai #huggingface #selfhost #localai #ollama #heretic #qwen #mistral npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Chinese censorship in Confer, the encrypted, privacy-preserving AI assistant by Moxie Marlinspike, creator of Signal: https://gagliardoni.net/#20260224_confer #ai #signal #confer #privacy #censorship #surveillance #china https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/127/003/781/263/664/original/fffd39a40f32542d.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting article: "Japan Is What Late-Stage Capitalist Decline Looks Like" https://oceandrops.substack.com/p/japan-is-what-late-stage-capitalist The article argues that the economic stagnation and cultural and social issues observed in Japan over the last decades are not unique anomalies, but rather a preview of the structural precarity now emerging in other late-stage capitalist nations like the US. Which reminds me of this other study: https://www.cambridge.org/core/journals/japanese-journal-of-political-science/article/japan-the-harbinger-state/2A9123B64A04C480B1BC5669FC2C8AF3 #japan #capitalism #politics #usa #economy #society #culture #recession npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I don't know if the news about the Palantir hack are true, but it is surely going to be popcorn time! #palantir #privacy #surveillance #hacking #usa #russia #china #conspiracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Oh I like this! #xckd #xkcd2501 #meme #cryptography #nerd #zkp #zeroknowledge https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/085/075/096/898/695/original/b730c55562ddc931.png npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Oh god, this is so wrong, I thought it was coming from XKCD... https://github.com/PulseBeat02/yt-media-storage Stores files onto YouTube by encoding them into lossless video and decoding them back to the original file. Why? Whyyy? #youtube #opensource #storage #madness #whoaskedforit npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I'm watching the drama about Discord's age verification thing and I'm like... yawwwnn Seriously, who ever thought Discord was a good idea at any point in time? Just trash that crap, please. I wrote about my... felings for Discord already: https://gagliardoni.net/#im_battle_2025 #discord #cryptography #privacy #ageverification #security #drama npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…ec4n just to be clear: I don't think Infomaniak is routing Euria queries to Alibaba, it is conceivable that their intentions are good. However, the problem is that they are using China-trained LLMs which, even if self-hosted by Infomaniak in Switzerland, behave like ComradeGPT :) which, I agree with you, is a problem. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Green, open and ethical? Chinese propaganda in Infomaniak's Euria, and a reflection on the role of Open Source AI: https://gagliardoni.net/#20260208_euria Infomaniak is a Swiss alternative to Big Tech, but focusing specifically on digital sovereignty for the Swiss and EU markets. Like too many others, they couldn't resist shoving AI down their customers' throats. So, last December they launched Euria, touted as "the free, sovereign AI assistant to no longer depend on the American giants". The road to Hell is paved with good intentions: as you can see, their model is heavily infused with Chinese state censorship. In this blog post I explain why and what the broader consequences are for "open source AI". #ai #euria #infomaniak #switzerland #eu #bigtech #llm #china #usa #qwen #censorship #digitalsovereignty #opensource #foss #floss #osi #tienanmen #politics https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/031/930/348/425/706/original/d4fa614f597e068d.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…38vg as a single data point: I use Conversation on Goggle-less Graphene OS, installed through Neo Store, and notifications work flawlessly. My 2 cents is that people using a similar setup will not want to have anything to do with FCM. Maybe it might be OK as long as it's strictly opt-in? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Conspiracy theory: I think LinkedIn's recommendation algorithm "deprioritizes" topics like this. I reposted the same content on my LinkedIn feed, and after two days it's not even 500 impressions. I'm not a big guy on social, but I regularly exceed 10'000 impressions on LinkedIn, with very few posts below 1'000. I think this is the lowest I've ever reached, and it's quite strange considering that it is a quite hot political + tech topic in the news. #linkedin #censorship #tiktok #epstein #politics #bigtech #conspiracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Wat. #surveillance #1984 #censorship #politics #bigtech #nottheonion #epstein #tiktok https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/966/391/562/500/468/original/448dd109cc92387d.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni It looks like I have to correct myself. It was not UBS changing how login works, it's just that, due to a junior UBS employee misunderstanding a request, they actually disabled my access card, so the login page message was actually correct: "no active means of access available" really means "your account nr exists, but I cannot find any valid card to access it". It took me just FIVE calls and visits to the branch to figure out the issue and fix it. Thank you UBS for keeping Firefox login available. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…xuk0 sure, as I wrote use proper disk encryption (LUKS), but if you care about plausible deniability, then the options are either VeraCrypt or Shufflecake. Which one is best suited depends on your use case and threat model. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Microsoft gave FBI a set of BitLocker encryption keys to unlock suspects’ laptops https://techcrunch.com/2026/01/23/microsoft-gave-fbi-a-set-of-bitlocker-encryption-keys-to-unlock-suspects-laptops-reports/ Because, of course, by default, BitLocker recovery keys are uploaded to Microsoft’s cloud, and it looks like you need to pay for the privilege of having the Pro edition if you want to have the option of opting out. Reject this BS. Use proper disk encryption! Or, even better, if you care about plausible deniability, use Shufflecake! https://shufflecake.net/ #shufflecake #truecrypt #veracrypt #microsoft #bitlocker #luks #security #privacy #fbi #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…g4vn @nprofile…khfk a bit of shameless self-promotion: it looks like we'll be able to launch a prototype for a fully hidden OS using #Shufflecake somewhere this year. And, no, we don't have an option for uploading encryption keys to "the Cloud" 😂 https://shufflecake.net/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…e965 @nprofile…khfk a bit of shameless self-promotion: it looks like we'll be able to launch a prototype for a fully hidden OS using #Shufflecake somewhere this year. And, no, we don't have an option for uploading encryption keys to "the Cloud" 😂 https://shufflecake.net/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…ynf4 a bit of shameless self-promotion: it looks like we'll be able to launch a prototype for a fully hidden OS using #Shufflecake somewhere this year. And, no, we don't have an option for uploading encryption keys to "the Cloud" 😂 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni It looks like I am one of the few lucky folks randomly selected to take part in the Swiss Federal Survey for Mobility and Traffic. https://www.bfs.admin.ch/bfs/de/home/statistiken/mobilitaet-verkehr/erhebungen/mzmv.html The request is easy: 1) download and install a proprietary app from the App Store or the Play Store. 2) The app makes use of GPS tracking and other sensors to track in real time your location. 3) Never turn off your phone or put it in flight mode during the survey period assigned to you (usually one day per week). They are quite insisting too, I have already received the second solicitation begging me for my "invaluable help"! I mean... I am flattered but... I find it super hilarious that I was picked as a participant 😂 Of course I trashed the letter. #switzerland #privacy #android #apple #security #swiss #suisse npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…xhd4 @nprofile…7v08 it seems that it works if I use a YubiKey (Firefox on Linux). Quite inconvenient I must say, I understand security is important but shouldn't it be opt-in? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…khyj Now, that's an interesting interdisciplinary mix. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Signal creator Moxie Marlinspike wants to do for AI what he did for messaging. https://arstechnica.com/security/2026/01/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what-he-did-for-messaging/ The idea might sound nice, but there are caveats. First of all, PassKeys? This screenshot is what I see on my Firefox 146.0.1 on Linux. Hopefully I can use a FIDO2 token like a YubiKey instead? I will test it later. Second, the whole security seems to rely on TEEs, which are notorious for... well... https://en.wikipedia.org/wiki/Software_Guard_Extensions#List_of_SGX_vulnerabilities I'll be honest, I'm not sure AI assistants can ever be made really private, save for self-hosting open source models. But still, much much better than the current Gemini, ChatGPT, etc. Like Signal was not the perfect solution for IM but moved the world toward a better state overall, I wish @nprofile…7v08 all the best with Confer.to because it would be good for all of us. #ai #llm #signal #confer #yubikey #passkeys #linux #privacy #security https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/888/595/767/145/688/original/4e59fd2de2b2d61b.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I hope it's only a temporary glitch, but suddenly the UBS home banking login page does not seem to work on Firefox anymore (it works with Chrome). This also happens with a fresh Firefox install (no addons, mods, anything). If this is true, then this means that from now on, the largest Swiss bank only allows customers to use their home banking with either their proprietary app (which of course requires Google Play Protection and does not work on Graphene OS), or with a hardware token plus a US-megacorp controlled browser (Chrome, Edge, Safari). #ubs #switzerland #banking #enshittification #foss #floss #firefox #chrome #safari #edge #google #microsoft #apple #privacy #security #opensource #android #ios #grapheneos #lineageos https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/866/492/443/657/717/original/db26b66f997211a9.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni European Commission issues call for evidence on open source: https://lwn.net/Articles/1053107/ The European Commission has opened a "call for evidence" to help shape its European Open Digital Ecosystem Strategy. The commission is looking to reduce its dependence on software from non-EU countries. #foss #floss #eu #politics #bigtech #digitalsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…u6wm I was with Commerzbank like 15 years ago, when it still didn't suck too much, but now I've been out of Germany for some time, so I really don't know what's there. But I recently saw a curated list on the GrapheneOS website of compatible banking apps, maybe you can start from there? Or even better, choose a bank that offers a hardware token as 2fa. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Commerzbank (one of the largest German banks) just banned GrapheneOS: https://discuss.grapheneos.org/d/28440-commerzbank-one-of-the-largest-german-banks-bans-grapheneos There is literally zero reason why banking apps shouldn't work on GrapheneOS, and yet so many European financial institutions prefer to rely on the security assurances of megacorporations controlled by a foreign country. At least I hope that the current geopolitical madness will contribute to stopping this plague. #google #android #aosp #grapheneos #lineageos #bigtech #enshittification #security #privacy #digitalsovereignty #usa #eu #europe #politics #germany #commerzbank npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…hlh9 I visited https://bastyon.com just out of curiosity and Думаю, это привело к развитию у меня деменции головного мозга. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…pjjl I know, right??? And for some reasons a lot of people call me "Matteo"! npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Imagine your name were "Jon" and everybody kept misspelling your name as "John". This is how I scream internally whenever people call me "Tomasso". npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…n926 I shouldn't post in a flamebait thread, but here are my few data points: 1) I am Italian, born and raised in a small city in Central Italy. My grandfathers were farmers, my grand-grandmother passed away when I was 13 years old. 2) I can guarantee 100% that, in my family, recipes do get passed generations by generations, from granma to grandchildren. 3) I have personally met people who still make this as a family recipe: https://en.wikipedia.org/wiki/Testaroli 4) Most Italians I know cringe when they see how "immigrant Italian cuisine" looks like. Let me rephrase: What a foreigner calls "Italian cuisine" is not what I call "Italian cuisine". 5) The reason for 4) is undoubtedly the "marketing" component, and I agree that many of the "iconic" dishes that are considered "Italian cuisine" in folklore come from the 50-60's. 6) That said, Alberto Grandi is a notorious troll who literally made a career out of overinflating sensationalistic claims with the precise goal of feeding the flames. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…l8gu extremely cool, thanks! Just one question: I see you mention Ed25519 specifically. Any chance of considering some form of crypto agility for signatures? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Hey #mastodon this is something to look at! @nprofile…l8gu just announced v0.1.0 of their key transparency specification for the Fediverse! https://soatok.blog/2025/12/15/announcing-key-transparency-fediverse/ This is an incredibly useful project, something really missing in a robust decentralized architecture. #fedi #fediverse #crypto #cryptography #authentication #security #federation #digitalsovereignty #digitalselfsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni I just found this cool video explaining the DIffie-Hellman cryptographic key exchange with the analogy of mixing colors! I was not aware of this neat explanation! Cute! https://youtu.be/YEBfamv-_do?t=160 #crypto #cryptography #security #privacy #education #video npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Dear #Mastodon can someone explain me why sometimes a thread gets "broken" and I cannot access part of it anymore? Example: I toot "A", other users reply to the toot as "B" and "C", and I reply to both with "BA" and "BC", respectively. After some time I see that my original thread only shows one "branch": it has become A->B->BA. The other branch still exists, I can see it from my "posts and replies" feed, but it appears as detached from the main "A" thread. What's going on? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Mastodon users: please, please remember to tag your toots with the correct language. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…g38k @nprofile…9dq6 @nprofile…rjdn Yes, I saw the announcement via Hacker News, this is great, I'm keeping my eyes on that! Totally agree that the way forward is beyond Android. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…d3h0 @nprofile…dwhh thanks for the clarification, will keep this in mind. What features does it have that improve on Signal? npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…92wj yes, I need to do a part 2 of that blog post, and Delta Chat is something I will cover for sure. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…dwhh well, it's a bit like Signal (centralized) but paid, and with worse security: https://soatok.blog/2021/11/05/threema-three-strikes-youre-out/ See also this discussion: https://discuss.privacyguides.net/t/threema-instant-messenger/1679 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Oh, this is so f***ing gold. This post is a juice concentrate of the many reasons why Matrix sucks: https://yaky.dev/2025-11-30-self-hosting-matrix/ Among others: Users cannot be deleted This is simply not an option in the API. Server admin can perform a "deactivate" (disable login) and "erase" (remove related data, which claims to be GDPR-compliant) on user accounts, but the accounts themselves stay on the server forever. LOL. Here is my take on why you should trash Matrix and use XMPP, or ta least Signal instead: https://gagliardoni.net/#im_battle_2025 #im #matrix #jabber #xmpp #signal #privacy #security #enshittification #cypherpunk npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…x0rg yeah OK, maybe "cloud services" is a bit oversimplifying, but it's correct enough in spirit I think. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni In a rare show of sanity, the Swiss Data Protection Officer has severely restricted the use of international cloud services – particularly hyperscalers like AWS, Google, or Microsoft – for Swiss federal authorities! https://www.heise.de/en/news/Switzerland-Data-Protection-Officers-Impose-Broad-Cloud-Ban-for-Authorities-11093477.html #security #privacy #cloud #politics #digitalsovereignty #bigtech #google #aws #microsoft #azure #amazon #switzerland npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…mkrw Sorry, I don't want to share my opinion on the matter, just posting to be on this thread which has the potential to achieve legendary divisiveness status 😂 Kidding apart, one argument I didn't see discussed which is potentially against hybrids, at least for encryption, is the possibility of better kleptographic attacks: https://eprint.iacr.org/2022/1681.pdf The idea is that you can design a circuit that uses e.g. ECDH to embed kleptographic data on ML-KEM public keys. In a pure ML-KEM hardware implementation, this would be easy to spot, because of the conspicuous amount of EC-related circuitry that shouldn't be there. But with a hybrid, that's much more difficult to spot. DISCLAIMER: I AM NOT ARGUING FOR HYBRID VS NON-HYBRID, JUST REPORTING THE FACT, FOR THE LOVE OF GOD PLEASE DO NOT JUMP AT MY THROAT. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Sorry, I don't want to share my opinion on the matter, just posting to be on this thread which has the potential to achieve legendary divisiveness status 😂 Kidding apart, one argument I didn't see discussed which is potentially against hybrids, at least for encryption, is the possibility of better kleptographic attacks: https://eprint.iacr.org/2022/1681.pdf The idea is that you can design a circuit that uses e.g. ECDH to embed kleptographic data on ML-KEM public keys. In a pure ML-KEM hardware implementation, this would be easy to spot, because of the conspicuous amount of EC-related circuitry that shouldn't be there. But with a hybrid, that's much more difficult to spot. DISCLAIMER: I AM NOT ARGUING FOR HYBRID VS NON-HYBRID, JUST REPORTING THE FACT, FOR THE LOVE OF GOD PLEASE DO NOT JUMP AT MY THROAT. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…e72p Elia and I have bee quite under the water recently, but we've been quietly working to this new release - mostly Elia, TBH :) In addition to the long due test units and dev guide, we worked a lot on FLUSH and FUA requests for block device I/O. We got SCARY performances, very close and at times beyond dm-crypt in fio tests! I think it is safe to say that performances won't be our priority from now on (at least for the Lite scheme), and we can keep focusing on new features and the roadmap to our Holy Grail: a fully hidden Linux OS! #shufflecake #crypto #cryptography #privacy #veracrypt #plausibledeniability #linux #cypherpunk npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni The results of the 2025 elections for the president and board members at the International Association for Cryptologic Research (IACR) have been botched because the results of the super-secure cryptographic e-voting system cannot be retrived due to the "accidental loss" of a decryption key. https://iacr.org/news/item/27138 While human mistakes happen, this accident comes under very troubling circumstances. Why an e-voting system of an association like IACR does not support t-out-of-n threshold decryption? Why is a system where a single party can collude to invalidate the vote considered acceptable? Wouldn't be wiser to freeze to the date of November 20th the eligibility status for voting instead of "calling to arms" IACR members who had previously decided to opt out from Helios emails? Does the identity of some of the candidates to Director represent a problem for IACR? #iacr #crypto #cryptography #politics #evoting npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni WTF IACR? Conspiracy intensifies... #iacr #helios #crypto #cryptography #politics #conspiracy https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/592/491/313/950/743/original/55b777ee4331eb01.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni BTW, it's funny, sometimes I duplicate also on LinkedIn the same posts that I write on Mastodon and that link to my website (so-called POSSE philosophy), and every time I rant about bad AI or Big Tech I get much more reactions and engagement on Mastodon than on LinkedIn. I understand the audience is very different but it feels almost... if... LinkedIn's algorithms do not want to show around some topics too much? Conspiracy intensifies. #conspiracy #linkedin #mastodon #bigtech #ai npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…4e5a what tshirt is that? Curious :) npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Interesting take from Christopher Butler on " What AI is Really For". https://www.chrbutler.com/what-ai-is-really-for The best case scenario is that AI is just not as valuable [...] The worst case scenario is that the people with the most money at stake in AI know it’s not what they say it is. The observation is that, while the AI bubble might burst, the multibillion deals for building datacenters will hand over ownership of energy infrastructure, land and water to a few individuals. Forever. The value of AI can drop to nothing, but owning the land and the flow of water through it won’t. #ai #ml #capitalism #politics #dystopia #technocracy npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…nlrw @nprofile…87np @nprofile…nguw @nprofile…z26c @nprofile…s38p @nprofile…x90w @nprofile…h5vr I feel your pain. It's really hard to spend time and energy over and over again to fight this BS. I think we're on the right track by spreading the voice and joining initiatives such as the ones against ChatControl, I also did my part by sending letters to Italian politicians and I might do the same about #omnirape if the proposal gets presented. For now this is a call to arms and signaling to everyone reading this that, no, we're not OK with this, and we'll do everything we can to fight back. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Look, I even felt creative today! https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/530/480/244/257/158/original/fc08ae0f3677fd4a.jpg npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Here's another thing I didn't need today: "Digital Omnibus". EU antitrust chief Henna Virkkunen will present to the EU Commission on November 19th a series of amendments to European data protection guardrails, which would substantially weaken GDPR and other privacy protections, and explicitly allow large AI companies unlimited access to the data of EU citizens and even to their digital devices. This is done in order to "placate US industry" (yes, seriously), and proposed through a stealthy "fast-track procedure", which we know of only because some media outlets obtained a leaked draft of the proposal. https://gagliardoni.net/#20251111_digital_omnirape "Digital Omnibus" is not a catchy term, we need something better. I propose "Digital Omnirape". Here are some scary quotes: According to the plans, Google, Meta Platforms, OpenAI and other tech companies may be allowed to use Europeans' personal data to train their AI models based on legitimate interest. In addition, companies may be exempted from the ban on processing special categories of personal data [religious or political beliefs, ethnicity, sexual preferences, or health data]. Companies can now remotely access personal data on your device for [...] "legitimate interest". Consequently, it would be a possible reading of the law that companies such as Google can use data from any Android apps to train it's [sic] Gemini AI. One massive change (on German demand) is to limit the use of data subject rights (like access to data, rectification or deletion) to "data protection purposes" only. Conversely, this means that if an employee uses an access request in a labor dispute over unpaid hours – for example, to obtain a record of the hours they have worked – the employer could reject it as "abusive". The same would be true for journalists or researchers. #digitalomnibus #digitalomnirape #omnirape #eu #politics #gdpr #privacy #ai #google #meta #facebook #openai #ml #lobbying npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Great article by F-Droid on "What We Talk About When We Talk About Sideloading". https://f-droid.org/2025/10/28/sideloading.html A few excerpts: It bears reminding that “sideload” is a made-up term. Putting software on your computer is simply called “installing” [...] the term “sideload” was coined to insinuate that there is something dark and sinister about the proces You, the consumer, purchased your Android device believing in Google’s promise that it was an open computing platform and that you could run whatever software you choose on it. Instead, starting next year, they will be non-consensually pushing an update to your operating system that irrevocably blocks this right and leaves you at the mercy of their judgement over what software you are permitted to trust. You, the state, are ceding the rights of your citizens and your own digital sovereignty to a company with a track record of complying with the extrajudicial demands of authoritarian regimes #google #android #aosp #security #privacy #enshittification #bigtech #opensource #politics #fdroid npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Great article by F-Droid on "What We Talk About When We Talk About Sideloading". https://f-droid.org/2025/10/28/sideloading.html npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Ah, the joys of calling my ISP's support number to complain that the new fiber modem they sent me is as configurable as a tamagotchi, and spending 15 minutes at the phone with the operator trying to let her understand that, yes, I have already tried clicking on the top white bar of my browser, digited 192.168.1.1 and pressed ENTER. #sunrise #switzerland #isp #annoying #tech #tamagotchi npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…us0z yes, I did not mean to bash AWS in particular, it could have been anyone else. My point is that decentralized systems are way less suceptible to this kind of issues. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…wqsx just to be clear, I think OMEMO encryption is basically fine enough, but not everyone is of the same opinion: https://soatok.blog/2024/08/04/against-xmppomemo/ npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…cr4r I and most of my contacts were. I guess it depends on your geographic area. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Today's AWS debacle is the perfect example of the reason why in the last few years I started to be less enthusiastic about Signal, and more oriented to federated or even P2P solutions like XMPP and Jami. I wrote about it already: https://gagliardoni.net/#im_battle_2025 Signal was down for few hours today, after an aoutage that affected AWS: https://mastodon.world/@Mer__edith/115405436746725236 Let's ignore for a second the blind reliance on AWS or any other cloud provider. In a decentralized system, this would not have happened, or at least it would have not impacted so many users. Yes, I am a cryptographer myself, I know that Signal's encryption is the best. But encryption is not everything. Availability issues, geopolitical troubles, risk of enshittification, limitations on users' freedom to use and control the software lead to a lack of trust, even in a supersecure solution. And I say that with honest admiration for the folks at Signal, who are doing a great job. May they prove me wrong over and over again. #signal #im #aws #amazon #privacy #security #digitalsovereignty #selfhosting #fediverse #federation #p2p #enshittification #xmpp #jami #politics #opensource #freesoftware #libre npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…0kmn it's many different obstacles, to name three: the fact that most apps people use are deeply integrated in the Play Store, the fact that AOSP security patches are released by a Google team, and too many binary blobs. But, in general, it's really the Android model that sucks. The whole idea that, in order to be considered "secure", users should not be allowed to unlock their bootloader and install whatever apps they want, is bollocks. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Some big news regarding mobile OSes: First, Graphene OS has confirmed a partnership with a large OEM to bring support to non-Pixel devices (Snapdragon SoC): https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-exclusivity-new-oem/ This is good news, but IMHO it only delays the unavoidable demise of free AOSP-based projects since Google is now finally pulling the rug. Second, the FSF announced Librephone, an initiative to bring real freedom to mobile devices: https://www.fsf.org/news/librephone-project This is also good, but it must be taken in the right perspective: Librephone, as far as I understand it, is not a new mobile OS, but rather an initiative to open-source existing proprietary firmware blobs. AOSP-based open source OSes like Lineage, Graphene, and even /e/OS, will hopefully benefit from this initiative, by being able to replace binary blobs with open-source firmware. But they still remain AOSP-based solutions, and therefore bound to the Google ecosystem. There are two problems here that really need to be addressed. The first one is political. Legislators and citizens must come to acknowledge that a democratic society where the full mobile ecosystem is in the hands of a corporate duopoly is not acceptable. The second one is technological: AOSP is not a fully free OS, it's a trojan horse, a trap set by Google years ago that is springing right now. We need to move away from Android and embrace full GNU/Linux solutions, or even something completely new, at this point I don't even care. I've heard good opinions of Postmarket OS. Any feedbacks here? Say what you want about Richard Stallman, but he saw this coming. #android #aosp #google #lineageos #grapheneos #eos #postmarketos #libre #foss #floss #opensource #privacy #security #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Stop calling it "sideloading". Call it "installing" instead, as it should be. If you're "installing" from the Play Store, call it "Googleloading" instead. Word choice is important. Make the legislators understand what's going on here. #google #android #aosp #politics #enshittification #surveillance #sideloading #control #antitrust #monopoly #privacy #digitalsovereignty npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…j5lu "i need to access my email every time" is that such a horrible thing? For me, yes, for the reasons I wrote above. Even if one doesn't care about security, at least should care about waiting those extra 2-10 seconds to receive email, open it, read code, input code. or of course people just never logout, and never have to face this email/login dance very often at all? Well, beyond being bad security practice (and of course we can argue whether a booking.com login is sensitive enough or not, I'd rather not risk my kids accidentally booking a stay at the Hilton that split second that I get distracted away from the keyboard), this wouldn't work for people, like me, who mostly browse on Incognito. Part of me thinks that this might be the real reason for website adopting this monstrousity: adding extra friction for privacy conscious users. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…j5lu in not particular order: slower more annoying unencrypted I need access to my email every time The last point is particularly painful in certain setups. For example, if I travel to some problematic countries I would rather bring a burner phone with minimal personal accounts on it. But then, if I want to use, say, Booking.com, now I have three options: 1) use their fantastic mobile app 2) also keep on my burner phone the credentials for my main email 3) register my Booking,com account with ANOTHER, lower security tier email. Option 3) might sound wise, but then remember that you have to do this for EVERY website that uses this cursed method of authentication. Which, don't get fooled, it's only done BECAUSE it's 2025 and websites (and their users) can't get a grasp of 2FA, websites need to enable it for compliance, but users don't want it. So the genius solution is to say "we don't need to enable 2FA authentication for our users, because their 2FA is their email". npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…tm69 this login method is so wrong for so many reasons I don't even know where to start cursing. I will probably write a blog post about it. TL;DR it's just for compliance: they can say they don't have the burden of authenticating the user, because that burden is now unloaded on the email provider. npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni May whoever invented the "We sent a one-time login code to your registered email address" login method find a little dog turd in their sandwich. #security #hacking #curse #rage #compliance #humor #annoying #email #authentication npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni Finally some good news! I feel I really needed them! We are finally able to write with good news! The Member States could not find a consensus in their meeting today, and the planned vote to approve a chat control regulation has been removed from next week's agenda of the ministers of home affairs. In other words: no version of chat control will be accepted for now. (from the academic open letter initiative at https://csa-scientist-open-letter.org/Sep2025 ) #chatcontrol #privacy #eu #politics #civilrights #surveillance npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…6w56 They finally fixed it tonight on Beta. Beyond a serious bug like this slipping unnoticed from nightly to beta, it took 5 days to fix. For Mozilla. It makes me feel more confident of how we treat these thing on Shufflecake 😅 npub1un4zcpgku6z6cgaqd67haeq4mym8u5teeqdw5r4kaa5eye8x8vcs87tqn3 Tommaso Gagliardoni @nprofile…r0kn 100% this, I moved all my domains away from Gandi since it went south. Not to Porkbun though, but to EU-based registrars instead 😛