Sign in

Renato Gabriele

@remagio.bsky.social
159 followers 254 following 46 posts

I thrive on high-country trekking and trail riding. For sport, I do systems forensics while building new things. “If you have a garden in your library, nothing will be lacking.” Marcus Tullius Cicero

PostsRepliesMedia
Reposted by Renato Gabriele
evacide @evacide.bsky.social · 08/10/2026
Wikimedia Foundation: "AI companies are not doing enough to secure their systems and protect the public from the harm they cause. That burden is falling onto everyone else, including smaller organizations." wikimediafoundation.org/news/2026/10...
wikimediafoundation.org
OpenAI “rogue” agent activities found on Wikimedia projects – Wikimedia Foundation
Wikimedia Foundation found “rogue” OpenAI agents on its wikis, raising concerns about risks to its free knowledge projects and the open web.
321982
Reposted by Renato Gabriele
Grady Booch @booch.com · 07/10/2026
Ms Hamilton coined the term “software engineering”.
7660208
Reposted by Renato Gabriele
Andrea Draghetti @andreadraghetti.bsky.social · 30/09/2026
Tosint v1.0.0 is out: an open-source Telegram OSINT tool for bot and chat analysis, message history and media exports. Richer JSONL metadata, optional SHA-256 hashes, and bot/user authentication. github.com/drego85/tosi... #OSINT #DFIR #Telegram #Tosint #CTI
github.com
GitHub - drego85/tosint: Tosint is a Telegram OSINT tool that extracts actionable intelligence from bot tokens and chat IDs for security investigations.
Tosint is a Telegram OSINT tool that extracts actionable intelligence from bot tokens and chat IDs for security investigations. - drego85/tosint
121
Renato Gabriele @remagio.bsky.social · 30/09/2026
Difference was made by the size&complexity. Higher the complexity, less Agile was helping if not adopted at team features/modules level. I still remember big corps marketing Agile at every confs, still today they have the worst performance and user experience but in Fortune 100 bc tricks not tech.
020
Renato Gabriele @remagio.bsky.social · 30/09/2026
No methodology alone achieves anything. We had dozens of teams split between Agile, Waterfall, and mixed over 20 years. Achievements and performances reached high levels without differences only with good managers and team leaders. Methodology never made the difference.
110
Reposted by Renato Gabriele
Riccardo Coluccini @orariccardo.bsky.social · 30/09/2026
L’UE aveva davanti l’occasione della vita: raccogliere dati sui consumi di tutti i data center in Europa come mai nessuno ha potuto fare prima. I dati sarebbero stati la base per garantire trasparenza ai cittadini e regolarne lo sviluppo. Non è andata così www.lighthousereports.com/investigatio...
lighthousereports.com
Data Centre Silence
How EU leaders sided with Big Tech over the public’s right to know about the true scale and environmental impact of the AI build-out, forcing a legal challenge to seek disclosure
154
Reposted by Renato Gabriele
Martin Shelton @mshelton.bsky.social · 28/09/2026
Come work with our team! We're hiring a Sr. Digital Security Trainer. You would lead digital security trainings for journalists, conduct organizational risk assessments, contribute to our editorial efforts, and help to develop our curriculum. freedomofthepress.na.teamtailor.com/jobs/708479-...
freedomofthepress.na.teamtailor.com
Sr. Digital Security Trainer - Freedom of the Press Foundation (FPF)
FPF is hiring a senior digital security trainer to conduct in-field digital security training with journalists and newsrooms.
01018
Renato Gabriele @remagio.bsky.social · 29/09/2026
And, is anyone going to jail and paying for damages ?
000
Reposted by Renato Gabriele
Kenn White @kennwhite.bsky.social · 29/09/2026
So proud of this: real-time highly scalable distributed generalized database search on fully encrypted data, what we call Queryable Encryption is now out of beta. Culmination of 25+ years of academic work and 7 years of R&D engineering leadership under @senykamara.com and Tarik Moataz... (1/2)
1128
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 28/09/2026
I'm excited to announce that the PLC Organization now has a statute! And a bank account! And a @standard.site publication! All the important stuff. The PLC Org is an independent Swiss Association meant to operate the PLC directory, which collects and distributes signed updates to atproto accounts.
blog.plcred.org
First steps of the PLC organization - Public Ledger of Credentials Organization
One year ago, Bluesky Social PBC announced their intention to facilitate the creation of an independent organization to operate the Public Ledger of Credenti…
425458
Renato Gabriele @remagio.bsky.social · 28/09/2026
I went through this in the past on other platforms, languages are tight to timezones. Also when big events happen, conversations are split over timezones and news follows the same. Other languages won't pop up on charts, and efforts to make it go unnoticed most of the time by the users.
030
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 25/09/2026
Italian zero-day maker Dataflow Security generated €63 million in revenue in three years, and the company also has strong ties with former Israeli intelligence veterans, according to an investigation by @irpimedia.eu. irpimedia.irpi.eu/en-inside-th...
irpimedia.irpi.eu
Inside the secretive cyberweapons company that won over Israel’s intelligence elite
Founded in Italy by a young hacker, Dataflow develops code to break into computers and smartphones. Since January, its operations in Israel have been led by Eyal Tsir Cohen, a former senior Mossad off...
0147
Reposted by Renato Gabriele
adafruit @adafruit.com · 23/09/2026
This IoT project listens for messages on LoRa networks and displays them on a tri-color e-ink learn.adafruit.com/meshfruit-me... #3dprinting #adafruit youtu.be/FxuyWbHRbRs
1333
Reposted by Renato Gabriele
Space Rogue @spacerog.bsky.social · 21/09/2026
All these AI companies seem to think that when their pet escapes, it proves just how smart and capable their creation is. Maybe. To me, it mostly proves they built a crappy cage. Capability without containment isn't a breakthrough. It's a security failure.
1152
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 21/09/2026
~ Personal news ~  I left TechCrunch. I will now focus on finishing my book about Hacking Team and the history of government spyware. After that, and in the meantime as well, I will be freelancing. Contact me: Lorenzofb.writes@gmail.com or Signal @LorenzoFB.1337 (+1 917 257 1382)
A masked puppet comes out of a keyboard.
89624
Reposted by Renato Gabriele
Miro Haller @mirohaller.bsky.social · 21/09/2026
We finally finished the universal signature forgery for 1024-bit RSA! 2^32 oracle queries, 1200 core years precomputation, 180 core years for an individual forgery, and 3 years of human labor (no AI involved) by Laura, Adam, Nadia, Emmanuel and me to pull of this computation against real HSMs.
14019
Reposted by Renato Gabriele
adafruit @adafruit.com · 21/09/2026
radio can/does have a user interface ...did some fruit jam work and now have software-defined radio projects we'll be publishing ...
2364
Reposted by Renato Gabriele
evacide @evacide.bsky.social · 14/09/2026
The real reason I spend so much time at the circus school is that I have been slowly developing an immunity to clowns. This allows me to continue to do tech policy.
1342665
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 11/09/2026
I added post-quantum authentication (ML-DSA) checks to QuantumHello, thanks to the ML-DSA support in go 1.27 from @filippo.abyssdomain.expert and others. quantumhello.xyz
quantumhello.xyz
QuantumHello
Check whether a site supports post-quantum encryption.
032
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 11/09/2026
Oh damn I had not seen the details of the MicroTik RCE: the client can send a public RSA key with correct N and e = 1 and the server will use it. Two primitives/protocol things that would have prevented it: if RSA was defined with a fixed e, and if SSH clients sent a key hash instead.
github.com
CVE-2026-67276 - GitHub Advisory Database
RouterOS does not compare the complete RSA public key...
26016
Reposted by Renato Gabriele
adafruit @adafruit.com · 04/09/2026
Build an IOT CO2 sensing bird to alert you of the air quality levels! This bird alerts you when it detects high levels of CO2 Guide: learn.adafruit.com/iot-canary #3dprinting #adafruit #iot youtu.be/Zy6EItdtGv8
1132
Reposted by Renato Gabriele
Randall Munroe @xkcd.com · 28/08/2026
Perseids xkcd.com/3287/
4-panel comic. (1) [Three people. The person on the left has shoulder-length hair; the person on the right has a white hat.] PERSON 1: I’m sad that we missed the Perseids. PERSON 2 with hat: There’s still the Geminids. PERSON 1: Yeah, but they’re in December. (2) PERSON 1: The Perseids happen when it’s warm enough to lie outside with a blanket, and we found a good mosquito-free beach. So we just lie around watching the stars and eating snacks. One year we saw the aurora. (3) PERSON 3 with shoulder-length hair: You know, I think I heard that the Perseids might be late this year. PERSON 2: Yeah, actually, I heard that too. (4) Later… [Three people lying down gazing up at stars in dark sky. One meteor is in the sky.] PERSON 3: Hm, seems like a normal number of meteors. Guess I heard wrong. PERSON 1: Maybe the Perseids are *next* weekend. PERSON 2: Oh, good thinking. Let’s come back then, just in case.
82110270
Renato Gabriele @remagio.bsky.social · 28/08/2026
There is an annoying bug that pops up every 2 releases, since ever. You open a linked post, on Android, and you get back in the app, but it reset and restart the app like at first opening... The only fix is waiting for the next update, often it need two updates @support.bsky.team
000
Reposted by Renato Gabriele
Julia Angwin @juliaangwin.com · 27/08/2026
It’s good that Meta is creating some bare-bones safety features for kids, but a far better option would be to make these platforms safe for everyone. Shouldn’t we all be protected from Big Tech’s predations? My latest @nytopinion.nytimes.com (gift link). www.nytimes.com/2026/08/27/o...
nytimes.com
Opinion | Meta Settles. Finally. (Gift Article)
Meta’s settlement is far from perfect, but every blow counts as the company declines.
1278
Reposted by Renato Gabriele
Lea Kissner @leak.bsky.social · 21/08/2026
I can't believe that our book, "Building Safer Technology: A Field Guide to Failing Well" is here NOW. Learn how to build safely -- security, privacy, trust&safety, AI safety, etc. We concentrate on the underlying thinking and skills so this is durable knowledge even as technology changes.
Copy of the book "Building Safer Technology: A Field Guide to Failing Well"
1359
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 17/08/2026
I am mostly done implementing crypto/passkey, but now I need YOUR help collecting real-world traces for its test suite! Please go to help-test-crypto-passkey.exe.xyz and click the buttons. It should take 1–3 minutes. 𝘌𝘴𝘱𝘦𝘤𝘪𝘢𝘭𝘭𝘺 if you have some unusual Linux-on-the-desktop xkcd 1987 passkey setup.
Bernie "I Am Once Again Asking for Your Financial Support" but it says "I am once again asking for your help testing Go cryptography."
1411441
Reposted by Renato Gabriele
Joseph Cox @josephcox.bsky.social · 17/08/2026
New from 404 Media: we solved which AI company is buying massive shipments of rare books, scanning and destroying them to train AI. We put an Apple AirTag in a rare book, followed it. It ended up at an Amazon facility. Its logo is a dinosaur ripping through a book www.404media.co/we-tracked-a...
404media.co
We Tracked a Shipment of Rare Books. It Ended at an Amazon AI Training Facility
We placed a tracking device in a shipment of rare books to see which AI company was buying it, and found an Amazon facility where Amazon scans and destroys books.
12537932367
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 15/08/2026
I think something broke in my relationship with the tech world. Not due to AI, but to threads like this. I thought my community cared about reality. I block ads with uBO Lite in Chrome. Anyone has access to verify this reality by experience. And yet pages and pages of comments on... not reality.
news.ycombinator.com
Firefox is now the last major browser that still supports uBlock Origin | Hacker News
2515511
Reposted by Renato Gabriele
Andy Greenberg @agreenberg.bsky.social · 06/08/2026
Two security researchers shipped me a pink plastic kid's smartwatch from Amazon. When I wore it, they tracked my movements, surreptitiously took photos of me, even listened to my conversations. The same backend they hacked is used by 30+ watch brands for kids. 🧵👇 www.wired.com/story/hacker...
wired.com
Hackers Stalked Me by Hijacking a Smartwatch for Kids
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.
11732479
Reposted by Renato Gabriele
GrapheneOS @grapheneos.org · 06/08/2026
Revolut recently banned using GrapheneOS without any justification. They're falsely claiming to do be doing it for security reasons. In reality, they're enforcing licensing Google Play. Revolut doesn't enforce security standards. It runs on Android 9 with no patches since 2018.
319736
Reposted by Renato Gabriele
Lorax Horne @lorax.bsky.social · 03/08/2026
AI will never become a good writer, because a machine can never feel the pleasure of hearing words flow through a mind.
041
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 02/08/2026
Those “public wifi is fine now” people are going to hate Microsoft’s good advice for the SVR abuses of hospitality captive portals. www.microsoft.com/en-us/securi... “When traveling, users should treat hotel, conference, airport, & other guest wireless networks as untrustworthy.”
microsoft.com
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | Microsoft Security Blog
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order ...
032
Reposted by Renato Gabriele
Joseph Cox @josephcox.bsky.social · 31/07/2026
Took me seconds to make an image showing 'protesters' around Google buildings, using Google Earth's new AI generation tool. You can make bomb blasts, protesters, drone strikes, nuclear plants. How on earth did Google think this was a good idea www.404media.co/google-earth...
fake ai generated protesters around google buildings, made with the new google earth ai tool
321958367
Reposted by Renato Gabriele
Faine Greenwood @faineg.com · 31/07/2026
I used to do some work on the ethical use of satellite and drone imagery for aid and disaster response, and it is genuinely hard to express in words what a dangerous, stupid thing Google is doing by making it easy to use GenAI to create faked satellite imagery:
digitaldigging.org
How to plant a nuclear plant in Iran
The question is: what on earth is Google doing?
742393894
Reposted by Renato Gabriele
FlokiNET ehf @flokinet.bluesky.flokinet.social · 31/07/2026
delete that password spreadsheet
Cartoon man pointing accusingly at his own reflection in a mirror. Caption: "WHEN YOU FINALLY FIND THE WEAKEST LINK IN THE SECURITY CHAIN".
001
Reposted by Renato Gabriele
Dominic White @singe.bsky.social · 29/07/2026
I realised some people* were using a super out-of-date version of hostapd-mana based off the upstream 2.6 branch instead of the newer 2.10 branch. This was probably because I never made the 2.10 branch the main. Well that’s fixed now. github.com/sensepost/ho... * me - see last commit for an eg
github.com
GitHub - sensepost/hostapd-mana: SensePost's modified hostapd for wifi attacks.
SensePost's modified hostapd for wifi attacks. Contribute to sensepost/hostapd-mana development by creating an account on GitHub.
061
Reposted by Renato Gabriele
Zack Whittaker @zackwhittaker.com · 29/07/2026
Over on Mastodon (I strongly recommend), @doublepulsar.com asked fellow defenders what's on their radars and how much of what they're actively dealing with is AI-related. The responses are overwhelmingly, no. ClickFix attacks and phone calls/social engineering remain among the top threats.
cyberplace.social
Kevin Beaumont (@GossiTheDog@cyberplace.social)
Sense check for people working in cybersecurity in operations roles in the trenches: I’m not finding or seeing cyber incidents off the back of Generative AI still. Are you? Not ones you’ve read about...
34017
Reposted by Renato Gabriele
Lorenzo Franceschi-Bicchierai @lorenzofb.bsky.social · 29/07/2026
This is a great explainer of the OpenAI hack against Hugging Face, particularly of the report that the latter published earlier this week. If you had trouble parsing the highly technical report, this article can walk you through it.
techcrunch.com
The Hugging Face AI break-in, as told through an increasingly committed bear metaphor | TechCrunch
Another way to think about the whole thing is to picture a bear at a campsite. (Really, we are going there.)
0188
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 29/07/2026
I know it’s not most folks‘ primary concern, but LLMs or not, I’m unimpressed by how soft these infrastructure services are. What do you mean HF had a Jinja2 template injection. And I’m still not over GitHub’s unsandboxed RCE. Geomys might need to self-host code/CI to avoid a weak link.
1020119
Renato Gabriele @remagio.bsky.social · 29/07/2026
Taking shortcuts for features, wrong implementations are becoming too common, all over. Including their hiring requirements. Bad decisions, wrong designs, or poor implementation? When the process is broken, features are too. I wonder what they discussed in their silos at weekly meeting :)
000
Renato Gabriele @remagio.bsky.social · 26/07/2026
Ouch, I wrongly thought you were looking for some ancient weird devices before any mobile or Internet :( but the NoteSlate was looking nerd :)
100
Renato Gabriele @remagio.bsky.social · 26/07/2026
The Newton ? The Palm ? Or the GRiDPad (earlier than the Palm, by the same team) ? They all used a kind of new stenography for writing
120
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 25/07/2026
An example of the fall of a security civilization: Cisco collapsing multiple different vulnerabilities into one CVE. It breaks a lot of feeds & products built to manage risk & is non compliant with standards like ISO 29147 Vulnerability disclosure sec.cloudapps.cisco.com/security/cen...
sec.cloudapps.cisco.com
Cisco's Transition to a Risk-Based Vulnerability Disclosure Model
46217
Reposted by Renato Gabriele
derek guy @dieworkwear.bsky.social · 24/07/2026
watched the odyssey last night. film ruined by everyone speaking english instead of ancient greek.
664182721589
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 24/07/2026
The guardrails were coming from inside the (White)house - Anthropic’s models refused to help Hugging Face analyze their intrusion. We don’t need more guardrails impeding defenders when they need AI most. “Hugging Face tried using Anthropic Fable 5 & Opus …both models refused, citing guardrails…”
2193
Reposted by Renato Gabriele
Katie Moussouris (she/her/she-hulk/she-ra)🌻 @k8em0.bsky.social · 23/07/2026
The experiment escaped the lab. OpenAI's models broke containment and breached Hugging Face. We are holding radium in our bare hands. What governments and organizations should do next, and why tighter commercial guardrails are exactly the wrong move: www.lutasecurity.com/post/openfac...
lutasecurity.com
OpenFace: The Hugging Face Breach and What to Do About It
These models are like the world's cleverest octopus escape artists, with unlimited prehensile arms and the ability to squeeze through anywhere. A single vulnerable package proxy stood between the mode...
35716
Reposted by Renato Gabriele
Firewalls Don't Stop Dragons @firewalldragons.bsky.social · 21/07/2026
Every surveillance device in a public space should be legally required to emit an RF beacon (eg, BTLE) announcing its presence. Ideally, this would include make, model, and operator contact info. This includes Flock, video doorbells, traffic cams, etc.
031
Renato Gabriele @remagio.bsky.social · 21/07/2026
Muoro @ariannaciccone.bsky.social, se solo non fosse così triste leggere del paese. Ma siete l'unica spiraglio leggibile da altrove, xo
110
Reposted by Renato Gabriele
Filippo Valsorda @filippo.abyssdomain.expert · 21/07/2026
Passkeys can be stored just like password hashes! I'm proposing an interoperable $webauthn$v=1$… format, and a Go API that uses these passkey records for authentication. I'm looking for feedback before proposing this as crypto/passkey for Go 1.28!
words.filippo.io
Opaque, Interoperable Passkey Records (and a Go API)
Passkey records are an interoperable format for WebAuthn credentials, similar to password hash strings. I propose a potential crypto/passkey Go API based on them.
519841
Reposted by Renato Gabriele
Rachel Tobac @racheltobac.bsky.social · 21/07/2026
Was curious if I could use AI (Graylark) to find coordinates of this house using just a *reflection in a keypad* of the surroundings. Well...it worked. YIKES. Daniel Heinen does not make this AI tool available to the public for this reason. youtube.com/shorts/Xzbvi...
youtube.com
Can AI geolocate using just reflections?!
YouTube video by SocialProof Security
1199