Tommaso Gagliardoni

234 Followers
129 Following
644 Posts

Cryptography, privacy, quantum security, infosec, retro vibes.

I am a mathematician and computer security scientist, with a strong interest in cryptography and anonymity, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner.

I co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution.

I am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism.

Fascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote "fascinated", not "knowledgeable".

Here you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!

Homepagehttps://gagliardoni.net/
Linkedinhttps://www.linkedin.com/in/tommasogagliardoni/
Shufflecakehttps://shufflecake.net/
My own companyhttps://www.lucumo.net/
@bms48 no worries, I know it's normal to assume people don't use UO, although to be honest I always wonder how they survive on the internet without :)
@bms48 Notice this is from Switzerland. In other non-GDPR aligned countries you would probably not even see the consent prompt.
@bms48 I have always Ublock origin on. This is regardless of.

Dear LinkedIn,

It is great that you respect my privacy. But I'm confused: I thought I had previously already denied AT LEAST 89 OTHER TIMES my consent for you to profile me, track me with 3rd party cookies, anally probing me, and generally making my life a bit more miserable.

To you and all the other countless buffoons out there: could you please kindly f**k off?

#linkedin #privacy #ad #gdpr #enshittification #consent

Sums up my experience growing up

@coding yes, I mean 2FA for webmail. Not for the mailbox itself (that wouldn't make sense since there is no 2FA for the POP/IMAP access) but for the admin panel, which I consider more sensitive.

So far I have tried "in-depth" Infomaniak, Mailbox, and Mailfence. They all have pros and cons, but overall they work well, I didn't have any problem reaching any other email address. Of the three, I have found Mailfence a bit more limited/buggy, although still OK-ish.

I have no experience in mail self-hosting, sorry, that is somewhere in my "When I will be a grown-up" list :)

Anyway, anything is better than Gandi at this point IMHO. How to kill a good business, really...

@tynstar I did research Migadu back in the time. They seem OK, but a few things to consider: Migadu is based in Switzerland but its servers are in France. No registrar, email hosting only. The plan I saw back in the time was very tight: 20 outgoing email/day limit with $19/year package and 100 outgoing email/day for $9/month is very expensive. No encryption at rest on their servers, which seems a bit weird to me, for two reasons. First, it makes disposal of old hardware a bit riskier. Second, there are many documented cases, even in Europe, of illegal police raids where servers are stolen without a court order. The court subsequently declares the raid illegal and the police is forced to hand back the servers and destroy the acquired data, but this can take years and you have no guarantee that the data is not copied elsewhere. Overall they seem cool folks and the rest of their threat model is sound IMHO (see https://www.migadu.com/procon/ ) but these are things to consider. Overall I had the impression that they are more targeted to SMEs.
Migadu Email

I traced $2 billion in nonprofit grants and 45 states of lobbying records to figure out who's behind the age verification bills

https://linux.community/post/4606267

A long and WELL sourced post on exactly who has been behind all the state level legislation aimed at OS level age verification.

"I traced $2 billion in nonprofit grants and 45 states of lobbying records to figure out who's behind the age verification bills. The answer involves a company that profits from your data writing laws that collect more of it."

*EDIT*
Direct link to the GitHub dataset:

https://github.com/upper-up/meta-lobbying-and-other-findings

Original redlib post and comments:

https://redlib.catsarch.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/

#AgeVerification #Infosec #Privacy #Discord #Mastodon #Meta #Zuckerberg #FollowTheMoney

GitHub - upper-up/meta-lobbying-and-other-findings

Contribute to upper-up/meta-lobbying-and-other-findings development by creating an account on GitHub.

GitHub

This is big but not unexpected: Meta built a multi-channel influence operation to pass age verification laws.

https://github.com/upper-up/meta-lobbying-and-other-findings

The original Reddit posts were removed, but they are archived:

https://web.archive.org/web/20260313090844/https://www.reddit.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/

https://web.archive.org/web/20260313125244/https://old.reddit.com/r/linux/comments/1rshc1f/i_traced_2_billion_in_nonprofit_grants_and_45/

This is your daily reminder that if you're a cryptographer and work for Meta - including taking their grant money - you need some serious 4d chess creativity to look at yourself in the mirror.

#security #privacy #cryptography #meta #surveillance #politics #censorship #lobbying #ageverification

GitHub - upper-up/meta-lobbying-and-other-findings

Contribute to upper-up/meta-lobbying-and-other-findings development by creating an account on GitHub.

GitHub