Tommaso Gagliardoni
banner
tomgag.infosec.exchange.ap.brid.gy
Tommaso Gagliardoni
@tomgag.infosec.exchange.ap.brid.gy
Cryptography, privacy, quantum security, infosec, retro vibes.

I am a mathematician and computer security scientist, with a strong interest in cryptography and […]

🌉 bridged from ⁂ https://infosec.exchange/@tomgag, follow @ap.brid.gy to interact
"Unfortunately We Are Unable To Provide Feedback"

No, you're not "unable", you are _unwilling_. And this is not OK.

https://gagliardoni.net/#20251227_nofeedback

Many cybersecurity and Web3 conferences refuse to provide an explanation of why a submission was rejected. The argument is that it […]
Original post on infosec.exchange
infosec.exchange
December 26, 2025 at 9:25 PM
Reposted by Tommaso Gagliardoni
I've finally switched to the @Vivaldi browser. I've been using Firefox for as long as I've been on the internet, but the focus on AI means it's no longer the browser for me. Thankfully unlike Chrome, Vivaldi supports the uBlock Origin extension which is the most important extension for being […]
Original post on mastodon.social
mastodon.social
December 17, 2025 at 11:25 PM
Imagine your name were "Jon" and everybody kept misspelling your name as "John". This is how I scream internally whenever people call me "Tomasso".
December 16, 2025 at 2:51 PM
Hey #mastodon this is something to look at! @soatok just announced v0.1.0 of their key transparency specification for the Fediverse!

https://soatok.blog/2025/12/15/announcing-key-transparency-fediverse/

This is an incredibly useful project, something really missing in a robust decentralized […]
Original post on infosec.exchange
infosec.exchange
December 15, 2025 at 3:16 PM
I just found this cool video explaining the DIffie-Hellman cryptographic key exchange with the analogy of mixing colors! I was not aware of this neat explanation! Cute!

https://youtu.be/YEBfamv-_do?t=160

#crypto #cryptography #security #privacy #education #video
December 15, 2025 at 3:12 PM
Reposted by Tommaso Gagliardoni
Today we are calling on institutions around the world to take control of their #digitalsovereignty, including their social accounts. Governments should communicate directly with their citizens on open platforms, not through the mouthpiece of a corporation […]
Original post on mastodon.social
mastodon.social
December 9, 2025 at 11:07 AM
I just received a letter from the Swiss Confederation about a "Mikrozensus Mobilität und Verkeher". Basically they ask me to participate in a survey by installing a tracking app on my phone to report my location as I drive my car around.

GIGALOL

#switzerland #privacy #madness
December 10, 2025 at 9:57 AM
Dear #mastodon can someone explain me why sometimes a thread gets "broken" and I cannot access part of it anymore?

Example:

I toot "A", other users reply to the toot as "B" and "C", and I reply to both with "BA" and "BC", respectively.

After some time I see that my original thread only shows […]
Original post on infosec.exchange
infosec.exchange
December 9, 2025 at 1:33 PM
Mastodon users: please, please remember to tag your toots with the correct language.
December 9, 2025 at 10:23 AM
Oh, this is so f***ing gold. This post is a juice concentrate of the many reasons why Matrix sucks:

https://yaky.dev/2025-11-30-self-hosting-matrix/

Among others:

> Users cannot be deleted
> This is simply not an option in the API. Server admin can perform a "deactivate" (disable login) and […]
Original post on infosec.exchange
infosec.exchange
December 1, 2025 at 11:58 AM
In a rare show of sanity, the Swiss Data Protection Officer has severely restricted the use of international cloud services – particularly hyperscalers like AWS, Google, or Microsoft – for Swiss federal authorities! […]
Original post on infosec.exchange
infosec.exchange
November 28, 2025 at 1:00 PM
The results of the 2025 elections for the president and board members at the International Association for Cryptologic Research (IACR) have been botched because the results of the super-secure cryptographic e-voting system cannot be retrived due to the "accidental loss" of a decryption key […]
Original post on infosec.exchange
infosec.exchange
November 22, 2025 at 10:07 AM
WTF IACR?

Conspiracy intensifies...

#IACR #helios #crypto #cryptography #politics #conspiracy
November 22, 2025 at 8:55 AM
Interesting take from Christopher Butler on " What AI is Really For".

https://www.chrbutler.com/what-ai-is-really-for

> The best case scenario is that AI is just not as valuable [...] The worst case scenario is that the people with the most money at stake in AI know it’s not what they say it […]
Original post on infosec.exchange
infosec.exchange
November 20, 2025 at 8:46 AM
Reposted by Tommaso Gagliardoni
RE: n.social/@noybeu/115531153839682864" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">https://mastodon.social/@noybeu/115531153839682864

@tomgag
@noybeu @edri see my crash-out on this above. Most of us don't want this and we understand that the implementation of this would be way more catastrophic than chatcontrol and impossible for us to escape. Let "us" know what to do to […]
Original post on mstdn.canarylabs.eu
mstdn.canarylabs.eu
November 11, 2025 at 1:44 PM
Reposted by Tommaso Gagliardoni
@tomgag

Sorry to dump on your post like this, but after seeing this mentioned a couple times I couldn't hold back anymore. is there a public pressure, direct action, or/and information campaign that we can join or start similar to what was done for #chatcontrol? Who do we point our voices and […]
Original post on mstdn.canarylabs.eu
mstdn.canarylabs.eu
November 11, 2025 at 11:45 AM
Here's another thing I didn't need today: "Digital Omnibus". EU antitrust chief Henna Virkkunen will present to the EU Commission on November 19th a series of amendments to European data protection guardrails, which would substantially weaken GDPR and other privacy protections, and explicitly […]
Original post on infosec.exchange
infosec.exchange
November 11, 2025 at 9:09 AM
Reposted by Tommaso Gagliardoni
🇪🇺⚠️ A perfidious trick? The EU Council Presidency wants to introduce mandatory #chatcontrol through the backdoor 🚪: An Art. 4 amendment would MANDATE "all appropriate risk mitigation measures," including scanning, enforced with sanctions! 😡 […]
Original post on digitalcourage.social
digitalcourage.social
November 5, 2025 at 7:20 AM
You will be SHOCKED to know that a NONZERO number of Italian politicians replied to the letters I sent by post last month last month to speak up against ChatControl!

https://gagliardoni.net/#20251106_chatcontrol_butti

#chatcontrol #privacy #eu #italy #politics
gagliardoni.net
gagliardoni.net
November 6, 2025 at 8:33 AM
Great article by F-Droid on "What We Talk About When We Talk About Sideloading".

https://f-droid.org/2025/10/28/sideloading.html

A few excerpts:

> It bears reminding that “sideload” is a made-up term. Putting software on your computer is simply called “installing” [...] the term “sideload” […]
Original post on infosec.exchange
infosec.exchange
October 28, 2025 at 9:01 PM
Ah, the joys of calling my ISP's support number to complain that the new fiber modem they sent me is as configurable as a tamagotchi, and spending 15 minutes at the phone with the operator trying to let her understand that, yes, I have already tried clicking on the top white bar of my browser […]
Original post on infosec.exchange
infosec.exchange
October 28, 2025 at 8:46 AM
Today's AWS debacle is the perfect example of the reason why in the last few years I started to be less enthusiastic about Signal, and more oriented to federated or even P2P solutions like XMPP and Jami. I wrote about it already:

#imi.net/#im_battle_2025" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">https://gagliardoni.net/#im_battle_2025

Signal was down for few […]
Original post on infosec.exchange
infosec.exchange
October 20, 2025 at 9:17 PM
Ah, the joys of half of the internet relying on AWS because "Cloud". Among too many other things, also Signal is down.

https://mastodon.world/@Mer__edith/115405436746725236

#aws #amazon #outage #cloud #down #signal
Meredith Whittaker (@Mer__edith@mastodon.world)
PSA: we're aware that Signal is down for some people. This appears to be related to a major AWS outage. Stand by.
mastodon.world
October 20, 2025 at 9:06 AM
Here is my morning trying to convince Gemini that, no, the --discard option in Debian's losetup is pure hallucination.

#ai #ml #hallucination #linux #debian #opensource #google #gemini
October 20, 2025 at 8:53 AM