Tommaso Gagliardoni

266 Followers
142 Following
701 Posts

Cryptography, privacy, quantum security, infosec, retro vibes.

I am a mathematician and computer security scientist, with a strong interest in cryptography and anonymity, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner.

I co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution.

I am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism.

Fascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote "fascinated", not "knowledgeable".

Here you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!

Homepagehttps://gagliardoni.net/
Linkedinhttps://www.linkedin.com/in/tommasogagliardoni/
Shufflecakehttps://shufflecake.net/
My own companyhttps://www.lucumo.net/

Claude Opus 4.8 has quite a few annoying quirks, and it's important to be precise about which ones, because this is the typical claim that needs to be substantiated by facts rather than hinted at. This is not just uncanny — it's painful to look at.

#anthropic #claude #opus #opus48 #ai #llm #humor #emdash

Hey #nostr I was thinking: is anyone developing an Android app (and related NIP) for Nostr key management, similar to #Amber but, instead of relays, using local/near field connections? Like, NFC, USB/serial, Bluetooth? So it wouldn't require network connection between signing device and Nostr client?

#security #privacy #digitalselfsovereignty #bitcoin #cryptography #crypto

I found that crafted #MeshCore node names could compromise #HomeAssistant instances running meshcore-card, with an XSS leading to remote root access on the HA host. An attacker could then access anything controlled or visible through Home Assistant. The attacker doesn't need to be near the target, as MeshCore advertisements are repeated over the mesh, which is dense in NL.

This also affects around 20 public MeshCore analyzer websites. Some of those run CoreScope, where it looks like a vibecoding bot broke the XSS filter while hallucinating a bugfix. The analyzers are mostly public data though. In addition, the less popular MeshCore-Home-Assistant-Panel-v2 is likely also affected, but I was unable to make contact with the maintainer.

MeshCore node names are only 32 bytes, and each rendered in a different place in the page, so I had to be creative to run a more substantial payload. I found a way with three node names using an iframe feature I never heard of before.

https://mxsasha.eu/posts/meshcore-xss-home-assistant/

Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name

A crafted MeshCore node name could compromise any Home Assistant instance running meshcore-card as soon as someone viewed a dashboard with that card. MeshCore …

Today Letsencrypt announced their plans for PQC migration and, oh boy, it's refreshing! TL;DR, Letsencrypt considers migration to quantum-resistant certificates a priority, and lays down a reasonable path to migrate. In so doing, they take the time to explain how, so far, the security community has been mainly focused on the problem of quantum-resistant secrecy (encryption) rather than authentication (signatures/certificates), and they explain why the sentiment is changing now, and why it is particularly relevant for Letsencrypt.

https://letsencrypt.org/2026/06/03/pq-certs

Not wanting to be the "told you so" guy, I've been saying this for at least 2 years now:

https://gagliardoni.net/#20260603_hndl

This is not to say that Harvest-Now-Decrypt-Later is a less urgent threat, but it's not as asymmetric as people have been believing so far. Glad to see things are changing!

#cryptography #crypto #security #quantum #pqc #postquantum #quantumsecurity #letsencrypt #ai

A Post-Quantum Future for Let's Encrypt

Let’s Encrypt is committed to a post-quantum-safe Web PKI. The path we’re planning to take is Merkle Tree Certificates (“MTCs”), a new approach that adds post-quantum authentication to the web without sacrificing the speed and reliability that have made TLS universal. This post is about these plans and why we believe MTCs are worth pursuing as a key to a post-quantum future. An increasingly urgent problem For much of the last several years, the conversation about post-quantum cryptography has been a conversation about encryption. The reasoning was straightforward: an attacker who records encrypted traffic today might be able to decrypt it years from now once quantum computers can break the underlying math. Authentication, the part of TLS that indicates a server is who it says it is, has been a less urgent problem. A quantum computer needs to forge a signature in real time, not retroactively, so threats to authentication hinge on the existence of a cryptographically relevant quantum computer (CRQC).

When a software update causes a PTSD trigger.

#xzutils #security #hacking #foss #floss #opensource

I have been dragged into the rabbit hole of GnuPG/LibrePGP VS Sequoia/OpenPGP and, boy it is ugly. Yeah, yeah, I know, PGP is bad, but of all the ugly things that could have happened to the FOSS crypto space, this is really unwelcome. I wish people would just sit at a table and talk.

#pgp #gpg #sequoia #crypto #cryptography #security #foss #floss #libre #drama #ietf #privacy #openpgp #librepgp

Rise and Fall of Hosting Provider Gandi.net

https://gagliardoni.net/#20260528_gandi_downfall

The sad story of Gandi.net is a textbook example of enshittification, which I think is interesting to talk about, because of the many expectations that were betrayed, and the deeper reflection linking to vampire capitalism. I also report the user-hostile process that I had to undergo in order to migrate away from them.

#gandi #gandi_net #enshittification #capitalism #it #france #privacy #privateequity

Tommaso Gagliardoni's Homepage

Fellow scholars, I admit I don't understand the need of splitting a manuscript into multiple .tex files (abstract.tex, introduction.tex, etc) and use main.tex to wrap them all. How ugly and inconvenient is that? It's a paper, not a codebase! I suspect this is an ancestral fear of merge conflicts from the SVN era!

Gone are the days of dreadful SVN,
When clashing scribes brought ruin to the pen.
Now we have Git, and blessed be it.
Fear no concurrency, nor let thy .tex be split!

#latex #science #academia #humor #svn #poetry #paper #peerreview

Ahhhhh less than 2 hours to the #Asiacrypt2026 deadline!

Dear spammer: when dealing with automated marketing campaigns, AI is not just your friend, it is also my friend. And I also have another good friend: GDPR. I am taking great delight in automating GDPR requests that border legal threats against your undesired email campaign. This typically escalates quickly from "canned AI response" to "automated AI response trying to do damage mitigation" to "concerned human replying apologetically because its AI agent alerted them that someone with a lawyer is genuinely angry". Ah, the little joys of life!

Your business does not deserve to exist. What you call "your job" is parasitic. Do you think your mom would be proud of you?

#ai #gdpr #privacy #spam #marketing #capitalism #parasite #justice #shame