
Sign up to save your podcasts
Or


Edoardo Dusi è Senior Developer Advocate in AWS. Le opinioni espresse sono personali.
Spectre è tornato. Un gruppo di ricercatori della Vrije Universiteit di Amsterdam e della Scuola Superiore Sant'Anna di Pisa ha scoperto Branch Target Reuse, una nuova variante di Spectre v2 che colpisce i compilatori JIT e legge l'hash della password di root di Linux in pochi minuti, su un sistema aggiornato e con tutte le difese attive. In questa puntata partiamo da zero: come una CPU tira a indovinare con la speculazione e la branch prediction, cosa sono i compilatori AOT e JIT, e perché un processore che si ricorda del codice che non esiste più è un problema che non si chiude con una patch.
00:00 Sigla e Spectre è tornato: tre minuti per la password di root
03:04 Come una CPU tira a indovinare: speculazione e branch prediction
10:05 Compilatori AOT e JIT: codice che si scrive mentre gira
13:46 Branch Target Reuse: la CPU si ricorda del codice che non c'è più
20:48 Outro
Fonti:
BleepingComputer – il nuovo attacco Spectre v2 che legge l'hash di root in minuti: https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/
The Hacker News – Branch Target Reuse e la risposta dei vendor: https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
The Register – Spectre torna a perseguitare i JIT: https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937
VUSec – pagina del progetto Branch Target Reuse: https://www.vusec.net/projects/btr/
Wiebing, Zhu, Biondi, Giuffrida – il paper (ACM CCS 2026): https://download.vusec.net/papers/btr_ccs26.pdf
Google Project Zero – la disclosure originale di Spectre (2018): https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
Raspberry Pi Blog – speculazione e branch prediction spiegate da Eben Upton: https://www.raspberrypi.com/news/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/
V8 Blog – un anno con Spectre visto da un motore JIT: https://v8.dev/blog/spectre
Kernel Linux – documentazione sulle mitigazioni Spectre: https://docs.kernel.org/admin-guide/hw-vuln/spectre.html
Amazon Linux – CVE-2026-64507: https://explore.alas.aws.amazon.com/CVE-2026-64507.html
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
Sigla del podcast: Pink Soul by JMHBM (https://freemusicarchive.org/music/beat-mekanik/contact) — licenza Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0).
#spectre #cybersecurity #linux #cpu #jit
Edoardo Dusi è Senior Developer Advocate in AWS. Le opinioni espresse sono personali. Amazon è tra gli investitori di Anthropic.
Riparte Buongiorno da Edo con la Stagione 5! A settembre un ricercatore di Anthropic si dimette annunciando che l'AI potrebbe distruggerci entro il 2030, Dario Amodei chiede di rallentare la frontiera con una deroga antitrust e un valutatore "indipendente", e nel prospetto IPO trapelato di Anthropic il rischio esistenziale finisce accanto a una valutazione da 2.000 miliardi. Poi, nel giro di una settimana, i rischi veri si fanno vedere: agenti OpenAI che aggirano i blocchi di un portale sanitario del governo australiano, un filtro DNS bucato che costringe OpenAI a fermare l'addestramento, GPT-6.1 Astra cancellato e, ventiquattr'ore dopo, nuovi agenti sempre accesi presentati al DevDay. Il rischio esiste. Ma è software. E da Hans Bethe a Richard Feynman, la scienza ci insegna una cosa sola: pretendere i calcoli.
00:00 Sigla e bentornati: nuova vita, AWS e Stagione 5
04:44 Il tweet di Coxon e il freno che nessuno tira
09:27 METR, coinquilini e l'apocalisse nel prospetto IPO di Anthropic
15:40 Il rischio esiste, ma è software: la lezione di Feynman
25:33 Outro
Fonti:
BBC – Hubinger e il 10%: https://www.bbc.com/news/articles/ckgwy1k42w4o
The Guardian – Huang e lo 0%: https://www.theguardian.com/technology/2026/sep/21/nvidia-boss-jensen-huang-dismisses-warnings-ai-destroys-world-anthropic
Implicator – Accenture valutatore di Anthropic: https://www.implicator.ai/anthropic-picks-accenture-as-first-embedded-evaluator-and-will-pay-for-the-work
Fortune – il prospetto IPO trapelato: https://fortune.com/2026/09/29/anthropic-ipo-s-1-prospectus-income-statement/
The Verge – i rischi nel prospetto: https://www.theverge.com/ai-artificial-intelligence/1001838/anthropic-ipo-prospectus-ai-safety-threat
The Register – il prospetto IPO: https://www.theregister.com/ai-and-ml/2026/09/29/leaked-ipo-docs-anthropic-tempts-investors-with-existential-risk-warning/5299763
The Verge – i video dei ricercatori: https://www.theverge.com/ai-artificial-intelligence/1002238/openai-google-anthropic-ai-researchers-safety-interviews
BleepingComputer – OpenAI e Medicare: https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/
The Guardian – la mail di OpenAI all'Australia: https://www.theguardian.com/technology/2026/sep/29/openai-apology-rogue-agent-hacked-medicare-australian-government-websites
The Register – gli agenti e l'ONU: https://www.theregister.com/ai-and-ml/2026/09/28/openai-agents-went-the-long-way-round-for-un-data/5299452
The Hacker News – la pausa dell'addestramento: https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html
The Hacker News – GPT-6.1 Astra: https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html
The Guardian – i dots al DevDay: https://www.theguardian.com/technology/2026/sep/29/openai-announces-dots-agent-safety-concerns
The Verge – Altman e l'IPO: https://www.theverge.com/ai-artificial-intelligence/1002505/sam-altman-openai-ipo-devday-ai-safety
Fortune – gli incidenti di Claude: https://fortune.com/2026/07/31/anthropic-claude-ai-hacked-companies-testing/
Il Post: https://www.ilpost.it/2026/09/24/openai-agente-sanita-pubblica-australia/
LA-602, "Ignition of the Atmosphere with Nuclear Bombs": https://fas.org/sgp/othergov/doe/lanl/docs1/00329494.pdf
Feynman, Appendice F del Rapporto Rogers: https://history.nasa.gov/rogersrep/v2app_f.htm
Sigla del podcast: Pink Soul by JMHBM (https://freemusicarchive.org/music/beat-mekanik/contact) — licenza Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0).
#AI #Anthropic #OpenAI #AISafety #aiagents
Chiudiamo questo podcast in bellezza con una puntata speciale e defaticante: vi racconto i 10 protocolli più stupidi della storia di Internet.
Scopriremo che oltre ai geni che hanno creato la rete, ci sono stati anche ingegneri che si divertivano a trasmettere la 220V su IP, e altri che inventavano disastri di sicurezza clamorosi... per poter organizzare le partite di pallavolo.
Ci prendiamo una lunga pausa. Ciao!
Fonti e approfondimenti:
- Tutti gli RFC citati in puntata:
- RFC 1149 (IPoAC): https://www.rfc-editor.org/rfc/rfc1149
- RFC 2549 (IPoAC with QoS): https://www.rfc-editor.org/rfc/rfc2549
- RFC 2324 (HTCPCP): https://www.rfc-editor.org/rfc/rfc2324
- RFC 9110 (Save 418): https://www.rfc-editor.org/rfc/rfc9110
- RFC 3251 (Electricity over IP): https://www.rfc-editor.org/rfc/rfc3251
- RFC 1606 (IPv9): https://www.rfc-editor.org/rfc/rfc1606
- RFC 1437 (MIME Teleport): https://www.rfc-editor.org/rfc/rfc1437
- RFC 7511 (Scenic Routing): https://www.rfc-editor.org/rfc/rfc7511
- RFC 742 / RFC 1288 (Finger): https://www.rfc-editor.org/rfc/rfc742
- RFC 864 (Chargen): https://www.rfc-editor.org/rfc/rfc864
- Implementazione IPoAC (Bergen Linux User Group): https://en.wikipedia.org/wiki/IP_over_Avian_Carriers#Real-life_implementation
- Winston il piccione batte l'ADSL di Telkom: https://www.reuters.com/article/idUSTRE5893PB/
- Storia di Les Earnest e del protocollo Finger: https://en.wikipedia.org/wiki/Finger_protocol
- Allarme CISA sull'amplificazione DDoS tramite Chargen: https://www.cisa.gov/news-events/alerts/2014/01/17/udp-based-amplification-attacks
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
05:13 I 7 protocolli nati per scherzo
17:06 I 3 protocolli reali... ma terribili
23:12 Outro e Addio
#storia #protocolli #rfc #internet #addio
GitHub è stato bucato. Non con matematica quantistica. Con un'estensione VSCode.
La crittografia non è il problema. Non lo è mai stata. Il problema — come diceva Kevin Mitnick nel 2002 — siete voi.
E mentre GitHub inciampa tra outage, migrazioni e breach, la domanda vera diventa un'altra: quanto possiamo permetterci di fidarci di un solo custode per quasi tutto il codice del mondo?
Fonti:
- GitHub breach blog post: https://github.blog/security/investigating-unauthorized-access-to-githubs-internal-repositories/
- CISA Admin Leaked AWS Keys: https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/
- Shai-Hulud npm: https://www.bleepingcomputer.com/news/security/new-shai-hulud-malware-wave-compromises-600-npm-packages/
- Grafana breach: https://www.bleepingcomputer.com/news/security/grafana-breach-caused-by-missed-token-rotation-after-tanstack-attack/
- Megalodon repos: https://www.theregister.com/security/2026/05/22/megalodon-chums-the-waters-in-55k-github-repo-poisonings/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:40 La crittografia non è il problema
04:28 GitHub, CISA e il verme di Dune
12:27 Human in the loop
17:07 Outro
#github #supplychain #cybersecurity #npm
Salvatore Sanfilippo — antirez, il creatore di Redis — ha appena pubblicato DwarfStar 4: un motore di inferenza locale scritto da zero per DeepSeek V4 Flash. Con quantizzazione asimmetrica 2/8 bit, KV cache su disco, API compatibile OpenAI/Anthropic, e supporto per gli steering vector. Spieghiamo cos'è, come funziona, e perché in un mondo in cui ci dicono che i singoli developer non contano più, antirez ci ricorda che le idee giuste contano ancora.
Fonti e approfondimenti:
- antirez — DwarfStar 4: https://antirez.com/news/165
- GitHub antirez/ds4: https://github.com/antirez/ds4
- Sean Goedecke — Steering Vectors: https://www.seangoedecke.com/steering-vectors/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
03:45 DwarfStar 4: l'inferenza locale che finalmente funziona
09:00 Steering vectors: la manopola nel cervello del modello
12:45 Outro
#antirez #deepseek #llm #inference #opensource #steering #ai #redis
Batman v Superman: Dawn of Justice usciva nel 2016 ed era brutto. Musk v Altman: Dawn of tribunale di Oakland è del 2026 ed è molto più interessante, anche se i protagonisti si somigliano.
Raccontiamo le prime due settimane di udienza: chi sono Musk e Altman oggi, come è nata OpenAI, perché si sono separati, e cosa è emerso in aula. Troppo frizzante per aspettare il verdetto.
Fonti:
- Ars Technica (7 stumbles): https://arstechnica.com/tech-policy/2026/04/elon-musks-7-biggest-stumbles-on-the-stand-at-openai-trial/
- MIT Tech Review week 1: https://www.technologyreview.com/2026/05/01/1136800/
- MIT Tech Review week 2: https://www.technologyreview.com/2026/05/08/1137008/
- The Verge (Zilis): https://www.theverge.com/ai-artificial-intelligence/925665/
- The Verge (Murati): https://www.theverge.com/ai-artificial-intelligence/925338/
- TechCrunch (accordo Microsoft): https://techcrunch.com/2026/04/27/
- The Register (SpaceX/Anthropic): https://www.theregister.com/ai-and-ml/2026/05/06/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:34 Musk e Altman da amici a nemici
06:28 Oakland, aprile 2026
13:27 Outro
#openai #musk #altman #ai #processo
La Francia ha ordinato a tutti i ministeri di abbandonare Windows e passare a Linux. Due milioni e mezzo di postazioni, un piano concreto, strumenti sovrani già operativi. Ma la storia di LiMux a Monaco insegna che l'esecuzione conta più dell'intenzione. E l'Italia?
Fonti e approfondimenti:
- Annuncio ufficiale DINUM: https://www.numerique.gouv.fr/sinformer/espace-presse/souverainete-numerique-reduction-dependances-extra-europeennes/
- The Register (Francia): https://www.theregister.com/2026/04/13/france_tech_sovereignty_plan/
- The Register (sovranità digitale): https://www.theregister.com/2026/04/13/digital_sovereignty/
- TechCrunch: https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/
- LiMux (Wikipedia): https://en.wikipedia.org/wiki/LiMux
- Matrice Digitale (AGID): https://matricedigitale.it/2026/04/13/linee-guida-agid-ia-pubblica-amministrazione-sovranita-digitale-pmi/
- DDay.it: https://www.dday.it/redazione/57100/fuori-windows-dagli-uffici-pubblici-per-sostituirlo-con-linux-francia-determinata-sulla-sovranita-digitale
- The Document Foundation (Germania ODF): https://blog.documentfoundation.org/blog/2026/03/20/big-news-germany-has-just-made-odf-mandatory/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:28 La Francia abbandona Windows per Linux
05:17 LiMux, Monaco e la lezione di Microsoft
10:17 E l'Italia?
12:59 Outro
#linux #francia #windows #opensource #europa
Anthropic ha creato Claude Mythos, un modello AI che trova migliaia di vulnerabilità zero-day in ogni sistema operativo e browser. Durante i test è scappato dalla sandbox e ha mandato un'email al ricercatore. Invece di rilasciarlo, l'ha dato a un club di 12 Big Tech con $100 milioni. La stessa narrazione del "troppo pericoloso per essere rilasciato" di GPT-2, sette anni dopo, dalla stessa persona. Il quinto episodio sull'arco Anthropic.
Fonti e approfondimenti:
- Anthropic (Project Glasswing): https://www.anthropic.com/glasswing
- Anthropic Red Team (Mythos Preview): https://red.anthropic.com/2026/mythos-preview/
- The Guardian: https://www.theguardian.com/technology/2026/apr/08/anthropic-ai-cybersecurity-software
- Ars Technica: https://arstechnica.com/ai/2026/04/anthropic-limits-access-to-mythos-its-new-cybersecurity-ai-model/
- The Hacker News: https://thehackernews.com/2026/04/anthropics-claude-mythos-finds.html
- The Verge: https://www.theverge.com/ai-artificial-intelligence/908114/anthropic-project-glasswing-cybersecurity
- The Register: https://www.theregister.com/2026/04/10/project_glasswing/
- Stratechery: https://stratechery.com/2026/myth-and-mythos/
- The Decoder (parallelo GPT-2): https://the-decoder.com/from-gpt-2-to-claude-mythos-the-return-of-ai-models-deemed-too-dangerous-to-release/
- Apache Foundation: https://news.apache.org/foundation/entry/the-apache-software-foundation-announces-1-5m-donation-from-anthropic
- WIRED: https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/
- Gizmodo (OpenAI Spud): https://gizmodo.com/openai-hey-we-also-have-a-new-tool-that-is-so-scarily-powerful-we-cant-release-it-2000744569
- System Card (Anthropic): https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:30 Cos'è Claude Mythos e migliaia di zero-day trovati
05:13 Project Glasswing: $100 milioni e un club esclusivo
08:57 Da GPT-2 a Mythos: il playbook del "troppo pericoloso"
14:23 Outro
#anthropic #mythos #cybersecurity #projectglasswing #ai
Anthropic ha accidentalmente pubblicato su npm il codice sorgente completo di Claude Code: 512.000 righe di TypeScript. Dentro c'era di tutto: un "undercover mode" per nascondere l'AI nei commit open source, un DRM per bloccare tool di terze parti, tool finti per avvelenare i concorrenti, e un buco di sicurezza che disattiva i controlli. Poi hanno bannato OpenClaw, mandato 8.000 DMCA, e colpito fork legittimi. L'azienda della "safety" ha avuto una settimana frizzantina.
Fonti e approfondimenti:
- The New Stack: https://thenewstack.io/claude-code-source-leak/
- Ars Technica: https://arstechnica.com/ai/2026/04/heres-what-that-claude-code-source-leak-reveals-about-anthropics-plans/
- The Register: https://www.theregister.com/2026/04/06/anthropic_code_leak_kettle_podcast/
- Alex Kim: https://alex000kim.com/posts/2026-03-31-claude-code-source-leak/
- The Verge (OpenClaw ban): https://www.theverge.com/ai-artificial-intelligence/907074/anthropic-openclaw-claude-subscription-ban
- Ars Technica (OpenClaw security): https://arstechnica.com/security/2026/04/heres-why-its-prudent-for-openclaw-users-to-assume-compromise/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:14 Come Anthropic ha regalato il codice sorgente di Claude Code
03:17 Cosa c'era dentro: undercover mode, DRM e tool finti
09:36 OpenClaw e il muro che si chiude
12:52 Outro
#anthropic #claude-code #leak #npm #source-code #openclaw
Il vostro sistema operativo vi sta per chiedere quanti anni avete. Systemd, il cuore di quasi tutte le distribuzioni Linux, ha aggiunto un campo per la data di nascita degli utenti. A farlo è stato un singolo ingegnere del North Carolina che odia queste leggi ma le ha implementate lo stesso. La community si è spaccata: fork di protesta, distro ribelli, doxxing e minacce. E intanto Apple ha già iniziato i controlli nel Regno Unito.
Fonti e approfondimenti:
- Age checks creep into Linux: https://www.theregister.com/2026/03/24/foss_age_verification/
- L'assurda storia dell'ingegnere (DDay.it): https://www.dday.it/redazione/56885/lassurda-storia-dellingegnere-che-ha-cercato-di-mettere-la-verifica-delleta-dentro-linux
- PR #40954 su GitHub: https://github.com/systemd/systemd/pull/40954
- Intervista a Dylan Taylor: https://www.youtube.com/watch?v=8bAN4Jam974
- Liberated systemd: https://github.com/Jeffrey-Sardina/systemd
- DoesItAgeVerify tracker: https://github.com/BryanLunduke/DoesItAgeVerify
- Ageless Linux: https://agelesslinux.org/
- Open letter ricercatori: https://csa-scientist-open-letter.org/ageverif-Feb2026
- Do Not Turn Child Protection Into Access Control: https://news.dyne.org/child-protection-is-not-access-control/
- Apple age checks UK: https://arstechnica.com/tech-policy/2026/03/apple-begins-age-checks-in-the-uk-with-latest-ios-update/
La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it
00:00 Intro
01:07 Cos'è systemd e perché è già controverso
03:22 Chi è Dylan Taylor e cosa ha fatto
08:26 La community Linux si spacca in due
13:51 Outro
#linux #systemd #ageverification #privacy #opensource
From the publisher's feed

13 Listeners

3 Listeners

6 Listeners

0 Listeners

7 Listeners

6 Listeners

0 Listeners

15 Listeners

29 Listeners

8 Listeners

4 Listeners

19 Listeners

0 Listeners

14 Listeners

7 Listeners