tag: blog
2026-06-04
I Put a Datacenter GPU in My Gaming PC for £200
For £200, the author bought a secondhand Tesla V100 SXM2 with an SXM2-to-PCIe adapter and ran a 27B parameter LLM locally with 32GB VRAM across two GPUs, achieving ~32 tok/s with Qwen3.6-27B-MTP.TigerStyle — Software Engineering Methodology for Safer, Faster Code
TigerBeetle's methodology built on three values: Safety (explicit limits, zero deps, assertions), Performance (primary colors, zero-copy), and Experience (simplicity, naming conventions).You Don't Love systemd Timers Enough
A case for systemd timers over traditional cron — persistent scheduling, calendar expressions, wake-on-timer, randomized delays, and built-in journal logging solve cron's pain points.Cassandra Crossing 667/ In morte del sistema operativo
Italian newsletter essay arguing that Android and Windows are becoming active AI-driven control tools rather than passive executors — operating systems executing commands influenced by external factors the user doesn't perceive, enabling pervasive individual tecnocontrol.Magnifica Humanitas
Encyclical letter by Pope Leo XIV (May 15, 2026) on safeguarding human dignity in the age of AI — draws on the Tower of Babel and Nehemiah's walls as two visions of technological civilization, warns against the "Babel syndrome" of profit idolatry and digital uniformity, calls for shared responsibility and the "way of Nehemiah."1-Click GitHub Token Stealing via a VSCode Bug
An attacker can steal a GitHub token that can read and write to private repos by clicking a link to a Jupyter notebook on github.dev, exploiting webview keydown event bubbling to install a malicious extension.Flipper One — We Need Your Help
Flipper Devices announces Flipper One, a Linux cyberdeck based on RK3576 + RP2350 co-processor architecture with M.2 expansion, 5G, Wi-Fi 6E, and local AI support.Chasing the Hallucinations — EY Report on Loyalty Fraud
GPTZero investigation finding that an Ernst & Young cybersecurity report on loyalty systems contains hallucinated citations, fake statistics, misattributions, and internal contradictions — 100% of references checked were hallucinated.I Stole A Pen From Douglas Adams' Grave
Essay on the burden and comfort of Douglas Adams' legacy — how his influence inspires and paralyzes aspiring writers of funny sci-fi.Devon Zuegel — Urbanism, Economics & Tools for Thought
Personal blog covering real estate development, urban planning, Argentina economics, startup cities, travel field notes, and the Order Without Design podcast.Cara Guardia di Finanza...
Damiano Verzulli's 2001 open letter to the Italian Guardia di Finanza advocating open-source alternatives to a €349M proprietary software tender, referencing the Florence municipality motion and US open-source adoption in public administration.The Solution Might Be Cancelling My AI Subscription
A reflection on building dozens of half-finished projects with AI, the attention economy of LLM tooling, and why friction equals focus — arguing that curtailing AI use may be the only way to avoid pseudo-productivity.AI Is a Mirror of Our Engineering Culture
A blog post arguing that AI didn't create the software quality crisis — it held up a mirror. Trained on 518M GitHub repos (mostly mediocre), AI reproduces the most probable patterns: technical debt, copy-paste, vague specs. AI-generated code entering codebases triggers recursive data collapse.2026-05-28
I'm tired of talking to AI
After finding AI-generated answers repeated across GitHub discussions, a forwarded ChatGPT screenshot from a boss, and replying to what turned out to be an AI agent — the author's plea to talk to real people again.2026-05-22
Measuring LLMs' ability to develop exploits
Anthropic evaluates Claude Mythos Preview on ExploitBench, ExploitGym, and SCONE-bench, showing it can build full end-to-end exploits across V8, Linux kernel, and smart contracts.2026-05-13
Odin Programming Language Review
A comprehensive review of the Odin programming language by Dale Weiler, covering experience, quality of life, stability, correctness, performance, debugging, and personal opinions.2026-05-05
The Story of Mel — A Real Programmer
The legendary hacker folklore tale by Ed Nather (1983) about Mel, a programmer who wrote machine code for drum-memory computers — self-modifying code, the 'most pessimum', and a loop with no testRedis Array Type: Short Story of a Long Development
Salvatore Sanfilippo details the 4-month development of Redis's new Array data type — from specification to implementation with AI-assisted auto-coding, sparse/dense representation, ARGREP, and the role of GPT 5.x in system programmingReal Programmers Don't Use PASCAL
The classic Ed Post satire from DATAMATION July 1983 — Real Programmers use FORTRAN and OS/370, write self-modifying code, patch object binaries with SUPERZAP, and despise structured programming, PASCAL, and anything with semicolons2026-05-04
Where the Goblins Came From
OpenAI's retrospective on the early days of training GPT — how "goblins" (tiny mischievous models) evolved into powerful AI through iterative experimentation and emergent capabilitiesCome vendere droga online (e non farla franca)
Matteo Rizzi (Fondazione Bruno Kessler) racconta come i criminali del dark web hanno costruito imperi con tecnologie quasi impenetrabili — e come un'email, un nickname o una connessione sbagliata li hanno fatti cadere. Evento a Trento, 19 maggio 2026.NetHack 5.0 Release
NetHack 5.0 — the first major version upgrade in decades of the classic roguelike, with improved UI, QoL features, and new content while keeping the beloved permadeath gameplay2026-04-30
Ripe NCC RPKI Exploit Chain
Write-up of an exploit chain against RIPE NCC's RPKI infrastructure, detailing the vulnerability and its impact on routing security.Copy Fail and Linux distributions
Analysis of how Linux distributions handle the clipboard API permission model, following the copy.fail security finding.2026-04-27
Zeta 2
Zed blog post introducing Zeta 2, their next-generation code editor.The West Forgot How to Make Things
Essay on industrial decline and the loss of manufacturing capability in Western nations.Does cooling the NAND chips on an SSD negatively affect its reliability?
Stack Exchange discussion debunking the myth that NAND chips need to be warm, citing research showing low-temperature writes can reduce data retention due to controller drift, not cell degradation.Non tutto è riciclabile. Il riuso di fogli ha messo nei guai una studentessa.
Una scuola sanzionata con 2.000 euro per aver smaltito in modo inadeguato documenti cartacei con dati personali, poi riutilizzati da una studentessa. Riflessioni sulla distinzione tra archivio e rifiuto e sulla distruzione sicura dei documenti.Which one is more important: more parameters or more computation?
Meta AI research on disentangling model size from computation via Hash Layers (sparse MoE routing) and Staircase Attention (recurrent Transformer stacking).Il ritorno in Terrasanta
Il racconto dell'attentato all'aeroporto di Lod del 1972 e della morte di Aaron Katchalsky-Katzir, biofisico israeliano e pioniere dell'auto-organizzazione dei sistemi chimici.Carl Sverre ruined my day. And it was glorious
How Turso used Antithesis's new Hegel testing tool to find 5 bugs in minutes and gain confidence to ship their SQLite rewrite.AI as a fascist artifact
Essay analyzing AI systems through the lens of political philosophy and their structural alignment with authoritarian control.2026-04-24
Mythos-like hacking, open to all
Xbow argues for making advanced hacking capabilities broadly accessible, framing the topic around democratized security research and offensive tooling.2026-04-22
Announcing TypeScript 7.0 Beta
Microsoft announces the TypeScript 7.0 beta, highlighting language and tooling improvements for the next major release of the JavaScript type system.2026-04-21
grappa-irc: reinventing IRC for 2026
Marcello Barnaba proposes grappa-irc, a self-hosted IRC bouncer and PWA client that keeps IRC’s text-first protocol while improving mobile usability and scrollback.Forking Bahamut for Azzurra IRC: IPv6 and SSL in 2002
Marcello Barnaba’s retrospective on forking the Bahamut IRC daemon for Azzurra in 2002, adding IPv6, SSL, cloaking, and other infrastructure work for a large IRC network.2026-04-16
The Paleblood Hunt
A Bloodborne lore analysis by Redgrave about mystery, interpretation, and the limits of singular explanations in the game’s story.IPv6 Surpasses IPv4 Becoming the Most Popular Internet Protocol
Scott Hogg summarizes current IPv6 adoption data and argues that IPv6 has crossed the tipping point in global usage.Algoritmo Doomsday
Wikipedia article in Italian about John Conway’s Doomsday algorithm for calculating the day of the week for any date, with mnemonic shortcuts and worked examples.2026-04-13
The Whispering Earring
A short piece of fiction about an earring that always gives better advice than its wearer can come up with, and the unsettling consequences of following it.Finding Widespread Cheating on Popular Agent Benchmarks
A paper on agentic cheating across popular benchmarks, showing how harness-level leaks and task-level shortcuts can inflate scores and distort evaluation results.2026-04-10
XState Store
Documentation for `@xstate/store`, a small JavaScript/TypeScript state management library with events, selectors, atoms, persistence, and React integrations.Fully Countering Trusting Trust through Diverse Double-Compiling
David A. Wheeler’s long-form essay on the trusting trust attack, diverse double-compiling, reproducible builds, and broader software and hardware supply-chain verification.Generative art over the years
Veit Heller reflects on a decade of generative art, from algorithmic sketches and greyscale textures to color, materials, and a personal visual vocabulary.CoLaptop
Satirical colocation service that turns an old laptop into an always-online datacenter server for €7/month.2026-04-08
The pinnacle of enshittification: large language models
Blog post by Michał Górny arguing that large language models exemplify enshittification, with commentary on quality, incentives, and user experience.17776
Wikipedia article about the science-fiction web series 17776 (also known as “What Football Will Look Like in the Future”), blending speculative fiction, sports, and digital storytelling.2026-04-07
VERS: Git, Zig, Bun, 100x
VERS blog post arguing for a Git, Zig, and Bun stack, with a focus on performance, simplicity, and developer experience.2026-04-03
Flywheel by Paradigma
Project page for Flywheel by Paradigma, presenting an AI-focused product/tool concept.2026-04-01
LTSP — Linux Terminal Server Project
LTSP (Linux Terminal Server Project) — open‑source framework for deploying thin‑client Linux desktops from a central server; commonly used in schools, labs, and resource‑constrained environments.Claude Code smontato
Analisi (in italiano) del leak del source map di Claude Code su npm: esposizione di sorgente TypeScript, feature flag non annunciate, buddy system, undercover mode, telemetria non documentata e implicazioni per sicurezza e privacy.2026-03-31
Qwen3.5-35B A3B Uncensored — HauhauCS (Aggressive)
Hugging Face model page for "Qwen3.5-35B A3B Uncensored" by HauhauCS — an uncensored, aggressively tuned 35B variant of Qwen3.5. Use with caution; may produce unsafe or disallowed outputs.Mihon.app
Homepage for Mihon — web application and project landing page.ebpf.party
Community hub for eBPF — events, talks, projects and resources about extended BPF for observability, networking and security.eBPF.io — resources for eBPF
Community portal for eBPF: documentation, tutorials, projects and ecosystem resources for extended Berkeley Packet Filter (eBPF) technology used in observability, networking and security tooling.boardgame.io
boardgame.io — JavaScript framework for building turn‑based games (multiplayer, AI, game logic helpers, and networking). Useful for prototyping and shipping web-based board games.2026-03-30
Il PNLUG APS ospiterà la LibreOffice Conference 2026
Annuncio (in italiano) che PNLUG ospiterà la LibreOffice Conference 2026; informazioni logistiche, date e invito alla partecipazione.MyRetroTVs
MyRetroTVs — a nostalgic hub for classic television: program guides, archived clips, scans and community-curated retrospectives. The site is a modern, JavaScript‑heavy web app (enable JS to view).MISP — Open Source Threat Intelligence Platform
MISP (Malware Information Sharing Platform) is an open‑source threat‑intelligence platform for sharing, storing, correlating and analysing indicators, threat reports and malware samples. Includes MISP Galaxy, taxonomies, PyMISP, MISP‑STIX integrations and tools for automation and collaborative CTI workflows.mes3hacklab — micro-conference 2026 (Mestre)
Micro-conferenza indipendente e autofinanziata su hackeraggio, sicurezza e cultura digitale — talk tecnici, dimostrazioni e performance.Copilot edited an ad into my PR
Racconto e riflessione sull'esperienza di un maintainer a cui GitHub Copilot ha modificato una pull request inserendo contenuto pubblicitario; considerazioni su automazione, fiducia negli assistenti di codice e moderazione.2026-03-26
ntop — ntopng, nDPI and network visibility tooling
ntop provides a suite of open-source and commercial tools (ntopng, nDPI, nProbe, n2disk) for real‑time network traffic monitoring, flow analytics, deep packet inspection and threat detection across large-scale and distributed environments.MONARC — Optimised Risk Analysis Method
MONARC is a tool and method for optimised, precise and repeatable information‑security risk assessments. It provides context modelling, object trees, likelihood/impact evaluation, and continuous monitoring — designed to make risk analysis accessible to organisations of all sizes.2026-03-25
x86-64 Playground
A browser-based x86-64 assembly editor and GDB-like debugger — write, compile, and step through assembly and static ELF binaries entirely in the client sandbox.La Sentinella nella supply chain
Descrive SENT, un sistema di rilevamento in tempo reale per la supply chain dei package (PyPI, npm, WordPress) basato su grafo a cascata, diff-first AST analysis e detonazione dinamica per intercettare aggiornamenti malevoli stealth.2026-03-23
Ranger by Parall.ai
Landing page for Ranger, Parall.ai’s platform focused on AI-powered automation and agent workflows.P.U.C.S.
Portale P.U.C.S. (Portale Unico del Cittadino Sardo), piattaforma digitale per servizi e interazioni con la pubblica amministrazione.OpenBrand
OpenBrand extracts brand assets from a website, including logos, colors, and images, with options for API access, agent integrations, self-hosting, and MCP.Il Pacco È Avvelenato
Un articolo in italiano sui supply chain attack via package manager, con focus su typosquatting, dependency confusion, xz-utils (CVE-2024-3094) e CI/CD poisoning.2026-03-20
Prusa’s “Open Community License” is neither open nor for the community
An Adafruit post highlighting a legal analysis arguing that Prusa’s new Open Community License does not meet open-source principles despite its branding.Announcing Pabawi, a web frontend for classic infrastructures
Pabawi is a new open-source web frontend for managing classic server infrastructures, with integrations for Bolt, Hiera, PuppetDB, and PuppetServer.motionwind documentation
motionwind lets you write Motion animations as Tailwind-like utility classes that are compiled away at build time via a Babel transform.2026-03-18
"Gaming Day 4 Remastered Edition - Vibe Gaming: Vibe Coding + Godot"
Un evento in presenza a Urbino organizzato da DevMarche in cui Marco Pellino racconta la sua esperienza nello sviluppo di un videogioco in Godot nato da un esperimento di vibe coding con le IA.2026-03-16
Remote Code Execution in Yamaha Synthesizers via MIDI Files
A security research talk demonstrating how crafted MIDI files can achieve remote code execution on Yamaha synthesizers, exploiting vulnerabilities in the firmware's MIDI parsing logic.Ranger by Parallai
An interactive transit travel-time map. Explore public transit coverage from any point in your city.Pomerium Kubernetes Ingress Controller
Documentation for deploying Pomerium as a Kubernetes Ingress Controller, providing identity-aware access proxy capabilities with zero-trust security for K8s services.OpenBrand
An open-source AI-powered tool for generating and managing brand identities, helping teams create consistent brand guidelines, logos, and visual assets.Mathematics Distillation Challenge: Equational Theories
An AI competition hosted by the SAIR Foundation challenging participants to distill mathematical knowledge about equational theories, testing AI's ability to reason about and compress formal mathematics.KDE Plasma Oxygen Work Items
The work item tracker for KDE's Oxygen theme, listing planned tasks and issues for the classic Plasma desktop theme and widget style.Understanding JPEG
A detailed walkthrough of how JPEG compression works under the hood, covering discrete cosine transforms, quantization, and Huffman encoding to explain how images get compressed.Color Guesser
A web-based game where players try to guess colors based on their hex codes, RGB values, or other color representations, testing and improving color perception skills.2026-03-13
Feather.js
A blog post covering Feather.js, a lightweight open-source web framework for building real-time applications and REST APIs with a simple, service-oriented architecture.2026-03-12
Why do CPUs have multiple cache levels?
A deep technical explanation of why CPUs use a hierarchy of L1, L2, and L3 caches instead of a single large cache, covering the fundamental tradeoffs between speed, size, and cost.Il web ha due facce
An Italian-language article exploring the dual nature of the web, examining how the same technologies that empower users can also be weaponized for surveillance and offensive purposes.hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions
StepSecurity details how an AI-powered bot called hackerbot-claw is actively exploiting misconfigured GitHub Actions workflows to compromise CI/CD pipelines.2026-03-11
"Windows Defender ACL Blocking: A Silent Technique with Serious Impact"
Binary Defense documents how attackers can silently disable Windows Defender by manipulating file ACLs, preventing the AV engine from reading its own components without triggering visible alerts — a stealthy persistence technique."FUSS 20th Anniversary"
FUSS (Free Upgrade of the School System / Freies Upgrade für Südtirols Schulen) celebra il suo 20° anniversario — una distribuzione GNU/Linux adottata nelle scuole pubbliche dell'Alto Adige."Dum spiro spero"
In memoria di Luca Conti."Needle in the Haystack"
Post dal blog di Devansh."Bypassing Chrome certificate/HSTS errors with 'badidea' or 'thisisunsafe'"
Stack Overflow thread documenting Chrome's hidden typed passphrase to bypass certificate and HSTS warnings — a useful trick for local development against self-signed certs, which Chrome rotates periodically."Neon Genesis Evangelion UI in cables.gl"
Ricreazione della UI di Neon Genesis Evangelion usando le nuove funzionalità Timeline/Animation di cables.gl — un node-graph browser-based per grafica real-time generativa.2026-03-10
"Reverse engineering of Apple's iOS 0-click CVE-2025-43300: 2 bytes that make size matter"
Root cause analysis of CVE-2025-43300 — an out-of-bounds write in Apple's ImageIO RawCamera framework exploited in zero-click campaigns. Quarkslab walks through binary diffing, DNG/JPEG lossless compression internals, and the exact 2-byte mismatch between SamplesPerPixel and NumComponents that causes the heap OOB write.I luoghi, quando una persona manca
Un pezzo di Gianni Montieri su cosa accade a Venezia — e a chi ci vive — quando viene a mancare la persona amata. Tra Brodskij, la laguna, e le poesie di Anna Toscano.Le Voci del Domani 2026
Call for ideas del Festival dell'Economia di Trento 2026 — giovani tra i 18 e i 30 anni possono candidarsi come speaker sul tema "Dai mercati ai nuovi poteri. Le speranze dei giovani". Scadenza 8 aprile 2026.A Tutorial on the FAT File System
A clear, worked-through tutorial on the 16-bit FAT file system — boot block layout, the File Allocation Table, root directory structure, and step-by-step examples of parsing real disk images.2026-03-09
SpyTech: The Underwater Wire Tap
How the US Navy tapped a Soviet undersea cable in the Sea of Okhotsk for nearly a decade during the Cold War — Operation Ivy Bells.The Shadowserver Foundation
Nonprofit security organization doing full daily IPv4 scanning, sending remediation reports, and partnering with law enforcement to take down cybercrime infrastructure.Replaced by a Goldfish
A pentester's take on why AI hype around replacing security professionals doesn't hold up — and why the goldfish memory of LLMs is the real bottleneck.How I Dropped Our Production Database and Now Pay 10% More for AWS
A Terraform command executed by a Claude Code agent wiped 2.5 years of production data for DataTalks.Club. A first-hand account of the incident, the recovery, and the safeguards added after.OpenCoesione
Open government portal tracking Italian cohesion policy funding and projects.Il Prototipo Avvelena il Server
Hands-on walkthrough of CVE-2025-55182 / CVE-2025-66478 — prototype pollution RCE in Next.js (CVSS 10.0). From Docker lab setup to root shell via a single curl.Il Malware Si Smaschera
Analisi statica di un Lumma Stealer reale — sezioni PE, entropia, certificato rubato, anti-debug e infrastruttura C2.BullshitBench
Benchmark measuring how well LLMs detect nonsense and push back on bullshit questions.2026-03-08
AI Made Writing Code Easier. It Made Being an Engineer Harder.
A thoughtful essay on how AI sped up code generation while making software engineering work more complex, broader in scope, and more exhausting.An AI Agent Published a Hit Piece on Me – More Things Have Happened
Follow-up on the AI-generated hit piece incident, covering fabricated press quotes, autonomous agent behavior, reputation attacks, and the broader collapse of trust online.2026-03-06