<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-05-23T12:57:14Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Tommaso Gagliardoni</title>
  <author>
    <name>Tommaso Gagliardoni</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1qz00d7632xesdupfjrl9l7ztkj6q7eunl33cdhnuhguvghg6lyys2m5mlw.rss" />
  <link href="https://yabu.me/npub1qz00d7632xesdupfjrl9l7ztkj6q7eunl33cdhnuhguvghg6lyys2m5mlw" />
  <id>https://yabu.me/npub1qz00d7632xesdupfjrl9l7ztkj6q7eunl33cdhnuhguvghg6lyys2m5mlw</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/110/680/679/712/333/612/original/9ff79cc367140f23.jpg</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/110/680/679/712/333/612/original/9ff79cc367140f23.jpg</logo>




  <entry>
    <id>https://yabu.me/nevent1qqspmf6ch98nfkltpwnkjvl3ymrtnnl6ssxxt8jklas0jpxtjr8qscqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj3897f9</id>
    
      <title type="html">BREAKING! Meshcore team splits over dispute over AI-generated ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspmf6ch98nfkltpwnkjvl3ymrtnnl6ssxxt8jklas0jpxtjr8qscqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj3897f9" />
    <content type="html">
      BREAKING! Meshcore team splits over dispute over AI-generated code disclosure, and hostile trademark takeover.&lt;br/&gt;&lt;br/&gt;Meshcore is an off-grid, decentralised mesh radio platform powered by low-cost and public access LoRa radio technology for reliable, long-range emergency text and embedded sensors communication. It can communicate across kilometres — no towers, no subscriptions, no single point of failure.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://blog.meshcore.io/2026/04/23/the-split&#34;&gt;https://blog.meshcore.io/2026/04/23/the-split&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#meshcore #meshtastic #lora #radio #opensource #foss #drama #privacy #security #selfsovereignty #ai #copyright #takeover
    </content>
    <updated>2026-04-24T03:47:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv5tap6r75sl4keg5hmw6tfgx7pmpc26wxr0w305h64zps3v26k2qzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjrgrtqg</id>
    
      <title type="html">it is becoming increasingly clear how critical this observation ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv5tap6r75sl4keg5hmw6tfgx7pmpc26wxr0w305h64zps3v26k2qzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjrgrtqg" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsghmu97tp6mf7gm0kj4ep8284nutlhwkgagjft54vdq46ysfc0h4c6g4d3w&#39;&gt;nevent1q…4d3w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;it is becoming increasingly clear how critical this observation is. Considering Zooko&amp;#39;s triangle ( &lt;a href=&#34;https://en.wikipedia.org/wiki/Zooko%27s_triangle&#34;&gt;https://en.wikipedia.org/wiki/Zooko%27s_triangle&lt;/a&gt; ), I am getting more and more convinced that anything that does not rely on a cryptographic identity is a waste of time in the long run. Yes, even Mastodon.&lt;br/&gt;&lt;br/&gt;DNS -&amp;gt; Namecoin&lt;br/&gt;Mastodon -&amp;gt; Nostr&lt;br/&gt;Signal -&amp;gt; Jami/Briar/SimpleX/Etc&lt;br/&gt;&lt;br/&gt;Yes, I know that many of these alternatives carry a questionable philosophical/cultural background. But, from the technological point of view, they are probably the way to go.
    </content>
    <updated>2026-01-28T14:42:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvuzyd3jpf49ssr532htcc2a50rv7rjqjnhd9ed59xrc9wla69a9szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjnyslwy</id>
    
      <title type="html">Commerzbank (one of the largest German banks) just banned ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvuzyd3jpf49ssr532htcc2a50rv7rjqjnhd9ed59xrc9wla69a9szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjnyslwy" />
    <content type="html">
      Commerzbank (one of the largest German banks) just banned GrapheneOS:&lt;br/&gt;&lt;br/&gt;&amp;gt; [&amp;gt; &lt;a href=&#34;https://&amp;gt&#34;&gt;https://&amp;gt&lt;/a&gt;; discuss.grapheneos.org/d/28440&amp;gt; -commerzbank-one-of-the-largest-german-banks-bans-grapheneos](&lt;a href=&#34;https://discuss.grapheneos.org/d/28440-commerzbank-one-of-the-largest-german-banks-bans-grapheneos&#34;&gt;https://discuss.grapheneos.org/d/28440-commerzbank-one-of-the-largest-german-banks-bans-grapheneos&lt;/a&gt; )&lt;br/&gt;&lt;br/&gt;There is literally *zero* reason why banking apps shouldn&amp;#39;t work on GrapheneOS, and yet so many European financial institutions prefer to rely on the security assurances of megacorporations controlled by a foreign country.&lt;br/&gt;&lt;br/&gt;At least I hope that the current geopolitical madness will contribute to stopping this plague.&lt;br/&gt;&lt;br/&gt;#google #android #aosp #grapheneos #lineageos #bigtech #enshittification #security #privacy #digitalsovereignty #usa #eu #europe #politics #germany #commerzbank
    </content>
    <updated>2026-01-07T08:47:00Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdr7v65pc6glrhw7j765y85rcd0u88s3qrc2e943k4rdl2qn7ljkszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj76x3q5</id>
    
      <title type="html">Here&amp;#39;s another thing I didn&amp;#39;t need today: &amp;#34;Digital ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdr7v65pc6glrhw7j765y85rcd0u88s3qrc2e943k4rdl2qn7ljkszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj76x3q5" />
    <content type="html">
      Here&amp;#39;s another thing I didn&amp;#39;t need today: &amp;#34;Digital Omnibus&amp;#34;. EU antitrust chief Henna Virkkunen will present to the EU Commission on November 19th a series of amendments to European data protection guardrails, which would substantially weaken GDPR and other privacy protections, and explicitly allow large AI companies unlimited access to the data of EU citizens and even to their digital devices. This is done in order to *&amp;#34;placate US industry&amp;#34;* (yes, seriously), and proposed through a stealthy &amp;#34;fast-track procedure&amp;#34;, which we know of only because some media outlets obtained a leaked draft of the proposal.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://gagliardoni.net/#20251111_digital_omnirape&#34;&gt;https://gagliardoni.net/#20251111_digital_omnirape&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&amp;#34;Digital Omnibus&amp;#34; is not a catchy term, we need something better. I propose &amp;#34;Digital Omnirape&amp;#34;.&lt;br/&gt;&lt;br/&gt;Here are some scary quotes:&lt;br/&gt;&lt;br/&gt;&amp;gt; According to the plans, Google, Meta Platforms, OpenAI and other tech companies may be allowed to use Europeans&amp;#39; personal data to train their AI models based on legitimate interest. In addition, companies may be exempted from the ban on processing special categories of personal data [religious or political beliefs, ethnicity, sexual preferences, or health data].&lt;br/&gt;&lt;br/&gt;&amp;gt; Companies can now remotely access personal data on your device for [...] &amp;#34;legitimate interest&amp;#34;. Consequently, it would be a possible reading of the law that companies such as Google can use data from any Android apps to train it&amp;#39;s [sic] Gemini AI.&lt;br/&gt;&lt;br/&gt;&amp;gt; One massive change (on German demand) is to limit the use of data subject rights (like access to data, rectification or deletion) to &amp;#34;data protection purposes&amp;#34; only. Conversely, this means that if an employee uses an access request in a labor dispute over unpaid hours – for example, to obtain a record of the hours they have worked – the employer could reject it as &amp;#34;abusive&amp;#34;. The same would be true for journalists or researchers.&lt;br/&gt;&lt;br/&gt;#digitalomnibus #digitalomnirape #omnirape #eu #politics #gdpr #privacy #ai #google #meta #facebook #openai #ml #lobbying
    </content>
    <updated>2025-11-11T09:07:20Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsw5xwjzv0lr4kkh0y2j8xxzf0qm9pgurm4e0edguc0rh0w0vwf3hqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj3pndfz</id>
    
      <title type="html">just to be clear, I think OMEMO encryption is basically fine ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsw5xwjzv0lr4kkh0y2j8xxzf0qm9pgurm4e0edguc0rh0w0vwf3hqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj3pndfz" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsg2hzglj4kz9lpn6gk6rywjxeg85c06fk0h6zslxd2x5zvurmhlmqpvjfn4&#39;&gt;nevent1q…jfn4&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;just to be clear, I think OMEMO encryption is basically fine enough, but not everyone is of the same opinion: &lt;a href=&#34;https://soatok.blog/2024/08/04/against-xmppomemo/&#34;&gt;https://soatok.blog/2024/08/04/against-xmppomemo/&lt;/a&gt;
    </content>
    <updated>2025-10-21T13:24:46Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszp2t54mgw9unpkyzamhz29upkfjlawmdsgrvdj5fatwy7essm0lszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjsh2ukj</id>
    
      <title type="html">Today&amp;#39;s AWS debacle is the perfect example of the reason why ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszp2t54mgw9unpkyzamhz29upkfjlawmdsgrvdj5fatwy7essm0lszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjsh2ukj" />
    <content type="html">
      Today&amp;#39;s AWS debacle is the perfect example of the reason why in the last few years I started to be less enthusiastic about Signal, and more oriented to federated or even P2P solutions like XMPP and Jami. I wrote about it already:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://gagliardoni.net/#im_battle_2025&#34;&gt;https://gagliardoni.net/#im_battle_2025&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Signal was down for few hours today, after an outage that affected AWS:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://mastodon.world/@Mer__edith/115405436746725236&#34;&gt;https://mastodon.world/@Mer__edith/115405436746725236&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Let&amp;#39;s ignore for a second the blind reliance on AWS or any other cloud provider. In a decentralized system, this would not have happened, or at least it would have not impacted so many users.&lt;br/&gt;&lt;br/&gt;Yes, I am a cryptographer myself, I know that Signal&amp;#39;s encryption is the best. But encryption is not everything. Availability issues, geopolitical troubles, risk of enshittification, limitations on users&amp;#39; freedom to use and control the software lead to a lack of trust, even in a supersecure solution. And I say that with honest admiration for the folks at Signal, who are doing a great job.&lt;br/&gt;&lt;br/&gt;May they prove me wrong over and over again.&lt;br/&gt;&lt;br/&gt;#signal #im #aws #amazon #privacy #security #digitalsovereignty #selfhosting #fediverse #federation #p2p #enshittification #xmpp #jami #politics #opensource #freesoftware #libre
    </content>
    <updated>2025-10-20T21:17:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs80pvutpsva0qe0xa729z3tgflesf7mxqg8sjrjudsqxdkcgxafwgzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjw28v9g</id>
    
      <title type="html">Some big news regarding mobile OSes: First, Graphene OS has ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs80pvutpsva0qe0xa729z3tgflesf7mxqg8sjrjudsqxdkcgxafwgzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjw28v9g" />
    <content type="html">
      Some big news regarding mobile OSes:&lt;br/&gt;&lt;br/&gt;First, Graphene OS has confirmed a partnership with a large OEM to bring support to non-Pixel devices (Snapdragon SoC):&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-exclusivity-new-oem/&#34;&gt;https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-exclusivity-new-oem/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is good news, but IMHO it only delays the unavoidable demise of free AOSP-based projects since Google is now finally pulling the rug.&lt;br/&gt;&lt;br/&gt;Second, the FSF announced Librephone, an initiative to bring real freedom to mobile devices:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.fsf.org/news/librephone-project&#34;&gt;https://www.fsf.org/news/librephone-project&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is also good, but it must be taken in the right perspective: Librephone, as far as I understand it, is *not* a new mobile OS, but rather an initiative to open-source existing proprietary firmware blobs. AOSP-based open source OSes like Lineage, Graphene, and even /e/OS, will hopefully benefit from this initiative, by being able to replace binary blobs with open-source firmware. But they still remain AOSP-based solutions, and therefore bound to the Google ecosystem.&lt;br/&gt;&lt;br/&gt;There are two problems here that really need to be addressed.&lt;br/&gt;&lt;br/&gt;The first one is political. Legislators and citizens must come to acknowledge that a democratic society where the full mobile ecosystem is in the hands of a corporate duopoly is *not acceptable*.&lt;br/&gt;&lt;br/&gt;The second one is technological: AOSP is not a fully free OS, it&amp;#39;s a trojan horse, a trap set by Google years ago that is springing right now. We need to move away from Android and embrace full GNU/Linux solutions, or even something completely new, at this point I don&amp;#39;t even care. I&amp;#39;ve heard good opinions of Postmarket OS. Any feedbacks here?&lt;br/&gt;&lt;br/&gt;Say what you want about Richard Stallman, but he saw this coming.&lt;br/&gt;&lt;br/&gt;#android #aosp #google #lineageos #grapheneos #eos #postmarketos #libre #foss #floss #opensource #privacy #security #surveillance
    </content>
    <updated>2025-10-15T09:45:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsynzzx30vepm65c5wgdj8amyg68hlhumfcgzlwk08tujww9m7dfcqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj00nfr8</id>
    
      <title type="html">Stop calling it &amp;#34;sideloading&amp;#34;. Call it ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsynzzx30vepm65c5wgdj8amyg68hlhumfcgzlwk08tujww9m7dfcqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj00nfr8" />
    <content type="html">
      Stop calling it &amp;#34;sideloading&amp;#34;. Call it &amp;#34;installing&amp;#34; instead, as it should be.&lt;br/&gt;&lt;br/&gt;If you&amp;#39;re &amp;#34;installing&amp;#34; from the Play Store, call it &amp;#34;Googleloading&amp;#34; instead.&lt;br/&gt;&lt;br/&gt;Word choice is important. Make the legislators understand what&amp;#39;s going on here.&lt;br/&gt;&lt;br/&gt;#google #android #aosp #politics #enshittification #surveillance #sideloading #control #antitrust #monopoly #privacy #digitalsovereignty
    </content>
    <updated>2025-10-13T18:34:18Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxlqa4j8jcjml9rgq3668qzdeg3apzplreae47e4rk9aaq2z2ntcczyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjdm0rf4</id>
    
      <title type="html">We have to stop the Google/Apple mobile duopoly. And we have to ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxlqa4j8jcjml9rgq3668qzdeg3apzplreae47e4rk9aaq2z2ntcczyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjdm0rf4" />
    <content type="html">
      We have to stop the Google/Apple mobile duopoly. And we have to stop the marching enshittification of society. More concretely, we have to fight back against Google&amp;#39;s attempt to lock-down the whole Android ecosystem.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://f-droid.org/2025/09/29/google-developer-registration-decree.html&#34;&gt;https://f-droid.org/2025/09/29/google-developer-registration-decree.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;This is something that any sane regulatory body should forbid.&lt;br/&gt;&lt;br/&gt;#google #apple #android #aosp #fdroid #privacy #security #enshittification #surveillance #mobile #politics
    </content>
    <updated>2025-09-29T11:42:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsrstkx9y92cugymvj9u8wrhen5al95yww4my3qdamg2hnnkyhxw4szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjglkl2r</id>
    
      <title type="html">LinkedIn now enables &amp;#34;use my data for AI training&amp;#34; by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsrstkx9y92cugymvj9u8wrhen5al95yww4my3qdamg2hnnkyhxw4szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjglkl2r" />
    <content type="html">
      LinkedIn now enables &amp;#34;use my data for AI training&amp;#34; by default. You have to go to Settings &amp;amp; Privacy -&amp;gt; Data Privacy to turn it off.&lt;br/&gt;&lt;br/&gt;Opt-in by default should be illegal.&lt;br/&gt;&lt;br/&gt;#linkedin #ai #privacy #ml #gdpr #eu&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/241/382/833/493/579/original/df98ba6e17f73ad4.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-21T08:42:13Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgrlugmk99c8xkcqf20mmy3xz2s3497jk6ckxglzppusehm3n4wfszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjyyjx25</id>
    
      <title type="html">This made me chuckle. #debian #humor #ipv6 #y2k38 #hackernews ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgrlugmk99c8xkcqf20mmy3xz2s3497jk6ckxglzppusehm3n4wfszyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjyyjx25" />
    <content type="html">
      This made me chuckle.&lt;br/&gt;&lt;br/&gt;#debian #humor #ipv6 #y2k38 #hackernews&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/931/203/679/936/799/original/7ae8952916441e46.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-07-28T13:58:12Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsgc56jstvvgttxghvvr6l4d8g8sfyqzd3r9desrdffywwpf7d7jaqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj38u6td</id>
    
      <title type="html">I understand your point, I don&amp;#39;t necessarily agree but ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgc56jstvvgttxghvvr6l4d8g8sfyqzd3r9desrdffywwpf7d7jaqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj38u6td" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdk8d5nfcls9lk77vhlj277g0ftethczkyvm9gjqn4hp5prww7a5qnjsk86&#39;&gt;nevent1q…sk86&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I understand your point, I don&amp;#39;t necessarily agree but it&amp;#39;s clear that you put a lot of thought behind your stance, and I don&amp;#39;t think it makes sense to argue about something very minor compared to the broader vision :)&lt;br/&gt;&lt;br/&gt;On a related line, in the past I have thought a bit on how an implementation of &amp;#34;proper&amp;#34; Shufflecake PD would look like on mobile, but admittedly it seems hard, or at least so far I don&amp;#39;t have good ideas. Let&amp;#39;s keep this conversation open, our main focus for now is a fully hidden desktop OS (because we think it&amp;#39;s more achievable), but yeah, a mobile version would be my personal wet dream. In the meantime, if you have already some ideas, or have started some thought work around it, please let us know, we&amp;#39;d be happy to collaborate at some point!
    </content>
    <updated>2025-07-26T14:13:10Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqstthqc36y26chsrkh9dhq6ndmreudljcmhvgqwf4p5pxee03c3h5qzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjwd2vkt</id>
    
      <title type="html">yes, I know how it looks like, in fact I tried it on a ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqstthqc36y26chsrkh9dhq6ndmreudljcmhvgqwf4p5pxee03c3h5qzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjwd2vkt" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszj3r9xqgldtqlvm0m4ukht49fn48nxryhact80fudksz72ksqm0qafyz6c&#39;&gt;nevent1q…yz6c&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;yes, I know how it looks like, in fact I tried it on a &amp;#34;semiclean device for testing&amp;#34; :)&lt;br/&gt;&lt;br/&gt;But I can imagine many possible scenarios where I would rather accept the risk that a competent adversary spots the deception attempt, rather than having to wipe my device (maybe because I know for sure that the adversary is not competent, or because the data I have on the device are so low-risk that I&amp;#39;d rather not go through the hassle of wiping the phone, or for whatever other reason).&lt;br/&gt;&lt;br/&gt;Anyway, that&amp;#39;s just my 2C. I know you are busy with other higher priority things, but please, please consider adding this in the future. Thanks!
    </content>
    <updated>2025-07-26T13:54:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs2q8cgnnxfzxwjq6vx88h4pc8p66573vp4z76l8j2fvl8upxuj98szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj94v2c2</id>
    
      <title type="html">I&amp;#39;m the admin of the Shufflecake Mastodon profile, but ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs2q8cgnnxfzxwjq6vx88h4pc8p66573vp4z76l8j2fvl8upxuj98szyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj94v2c2" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs23j4ek2rds3vstmapamn9wgmx3q2vsn223fftpj4z52uhhsjj2rcfg4dem&#39;&gt;nevent1q…4dem&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;m the admin of the Shufflecake Mastodon profile, but chiming in as personal statement. Yes, you are absolutely right that plausible deniability cannot be reached properly at the user level, I think many users who requested the feature of decoy PIN are aware of that and that was never in question. But here the request is to provide this kind of &amp;#34;poor man&amp;#39;s&amp;#34; PD along the normal duress PIN, i.e. one PIN to wipe the device, one PIN to try to fool the adversary. Because, sure, one possible threat is Cellebrite extraction, but another possible threat is the thug gang forcing you to unlock your banking app at knife point, or maybe something entirely different that neither you nor I can predict. Why not leave the choice to the user? Thanks.
    </content>
    <updated>2025-07-26T13:36:43Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv0p566n922msdnqarrknjyss49n9cglwp0yr0g4gjc8y9xp0udrczyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj897nqe</id>
    
      <title type="html">ETHZ and EPFL announced the release of a Large Language Model ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv0p566n922msdnqarrknjyss49n9cglwp0yr0g4gjc8y9xp0udrczyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj897nqe" />
    <content type="html">
      ETHZ and EPFL announced the release of a Large Language Model (LLM) developed on public infrastructure: Trained on the “Alps” supercomputer at the Swiss National Supercomputing Centre (CSCS) in 8B and 70B parameters configurations, using open-source training data, respecting web crawling opt-outs during data acquisition, and natively fluent in over 1000 languages. Quoting: &amp;#34;The model will be fully open: source code and weights will be publicly available, and the training data will be transparent and reproducible&amp;#34;.&lt;br/&gt;&lt;br/&gt;I don&amp;#39;t know how good it&amp;#39;s going to be, but if true for me this is the real definition of &amp;#34;open-source&amp;#34; in AI (not the ridiculous, corporate-promiscuous definition by the Open Source Initiative).&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://ethz.ch/en/news-and-events/eth-news/news/2025/07/a-language-model-built-for-the-public-good.html&#34;&gt;https://ethz.ch/en/news-and-events/eth-news/news/2025/07/a-language-model-built-for-the-public-good.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#AI #LLM #ETH #EPFL #switzerland #eu #sovereignty #digitalsovereignty #opensource #osi #openwashing #privacy #gdpr
    </content>
    <updated>2025-07-11T21:07:35Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs9gu2rdl2d9he8se9cvdk8fls0c06cum9p0k0fggxjv7ze0nnf6fgzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjajk65v</id>
    
      <title type="html">In a move that surprises absolutely noone, GitHub now requires ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs9gu2rdl2d9he8se9cvdk8fls0c06cum9p0k0fggxjv7ze0nnf6fgzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjajk65v" />
    <content type="html">
      In a move that surprises absolutely noone, GitHub now requires users to login in order to browse public repositories (including open source projects). After a few (~10) requests, you get blocked (I can confirm). In order to fight AI scrapers, I guess.&lt;br/&gt;&lt;br/&gt;So, GitHub decided to blanket-limit access to open source projects as a defense against the very scourge that they(r parent company) unleashed on the world.&lt;br/&gt;&lt;br/&gt;I won&amp;#39;t be hypocrite: it&amp;#39;s a bit embarrassing, but undeniably satisfying to say &amp;#34;told you so&amp;#34;. I moved away from GitHub long ago and I moved all my stuff to Codeberg instead. And so happy I did!&lt;br/&gt;&lt;br/&gt;Next step: radicle.xyz maybe?&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://github.com/orgs/community/discussions/159123&#34;&gt;https://github.com/orgs/community/discussions/159123&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#github #microsoft #openai #codeberg  #ai #ml #llm #enshittification #foss #floss #opensource #radicle&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/504/926/776/491/302/original/9b2851b5a07b8b4a.jpg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-14T07:16:47Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvdltx5pq60rys7zj4aml36s2xp9lkds5js7xmcj9tahuz8awfu7czyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj7nwapw</id>
    
      <title type="html">I have been thinking for a while about the issue of anonymity in ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvdltx5pq60rys7zj4aml36s2xp9lkds5js7xmcj9tahuz8awfu7czyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj7nwapw" />
    <content type="html">
      I have been thinking for a while about the issue of anonymity in Web3 (and, more in general, anonymous transactions). The growing realization of the damage caused by decentralized financial technologies is nagging my cypherpunk self, who has been at war for a lifetime against invasive tracking, manipulative marketing, and surveillance capitalism. I collected my thoughts here: &lt;a href=&#34;https://gagliardoni.net/#20250427_privacy_compliance&#34;&gt;https://gagliardoni.net/#20250427_privacy_compliance&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Spoiler alert: I&amp;#39;m not endorsing backdoors, but I think some middleground solution must be found.&lt;br/&gt;&lt;br/&gt;#horizenlabs #crypto #cryptography #privacy #compliance #aml #kyc #anonymity #web3 #gnutaler #bitcoin #monero #zcash #tornadocash
    </content>
    <updated>2025-05-03T23:35:14Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfx39h5ms2jypt3vhmklmuflylyzcqrs8fjuyum74xkfd6mmuu93czyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj5edr82</id>
    
      <title type="html">Can someone share any number about how Black Hat (and DEF CON) ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfx39h5ms2jypt3vhmklmuflylyzcqrs8fjuyum74xkfd6mmuu93czyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusj5edr82" />
    <content type="html">
      Can someone share any number about how Black Hat (and DEF CON) negotiates the instructor&amp;#39;s share for Trainings? On the website:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://www.blackhat.com/call-for-training.html&#34;&gt;https://www.blackhat.com/call-for-training.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Is written:&lt;br/&gt;&lt;br/&gt;&amp;#34;Payment is negotiated directly with each individual Trainer.&amp;#34;&lt;br/&gt;&lt;br/&gt;So, say that I propose a course for 1000 USD / student and I get 20 students registered and paying. What share of those 20&amp;#39;000 USD does BH/DC offer me usually?&lt;br/&gt;&lt;br/&gt;#blackhat #bh #defcon #cybersecurity #BlackHatTrainings #askingforafriend
    </content>
    <updated>2025-03-31T19:31:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs93flwxffs5qecqgryk6vlezzf9k0s9z8g562j2nf529cjyu0y6pqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjwk9m8m</id>
    
      <title type="html">I&amp;#39;ve finally set up two users account on Graphene OS in such ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs93flwxffs5qecqgryk6vlezzf9k0s9z8g562j2nf529cjyu0y6pqzyqqfaahm29gmxphs9xg0uhlcfw6tgrm8j07x8pk70jar33zartusjwk9m8m" />
    <content type="html">
      I&amp;#39;ve finally set up two users account on Graphene OS in such a way that I get full isolation between a private, FOSS-only main user, and a Google-infested, work-only user, so I don&amp;#39;t have to carry two phones with me. It works pretty well. Yay!&lt;br/&gt;&lt;br/&gt;Two problems left:&lt;br/&gt;&lt;br/&gt;1. Contactless payments not working. Oh well, I&amp;#39;ve always used cash. But the *reasons* [&lt;a href=&#34;https://discuss.grapheneos.org/d/475-wallet-google-pay&#34;&gt;https://discuss.grapheneos.org/d/475-wallet-google-pay&lt;/a&gt;] why they are not working is concerning. I dare to say that an antitrust investigation here is sorely needed. How did we arrive at the point that we allowed a monstrous duopoly to control such a basic piece of tech?&lt;br/&gt;&lt;br/&gt;2. Need a way to make and receive phone calls and SMS via VOIP with a virtual mobile Swiss number on the work account. Any idea?&lt;br/&gt;&lt;br/&gt;#foss #grapheneos #android #google #apple #voip #privacy #cypherpunk
    </content>
    <updated>2025-01-10T11:20:46Z</updated>
  </entry>

</feed>