Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Tommaso Gagliardoni

@tomgag@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Cryptography, privacy, quantum security, infosec, retro vibes.

I am a mathematician and cryptographer, specialized in quantum security and complex cryptographic protocols. I am also a privacy hacktivist and public speaker, blahblahblah, read my Linkedin bio for this s**t, this is my Mastodon corner.

I co-develop Shufflecake, an open source privacy disk encryption tool to help journalists, activists, and whistleblowers evade unjust prosecution.

I am an advocate of digital self-sovereignty. You will see me often ranting about Big Tech, enshittification, and surveillance capitalism.

Fascinated with anime, Japan, RPGs, retro computing, and all things 80-90's. Notice I wrote "fascinated", not "knowledgeable".

Here you won't find peace nor forgiveness, but just: #cryptography #privacy #quantum #security #infosec #retro vibes!

319 Followers
159 Following
39 Posts
Joined July 08, 2023
Homepage:
https://gagliardoni.net/
Linkedin:
https://www.linkedin.com/in/tommasogagliardoni/
Shufflecake:
https://shufflecake.net/
My own company:
https://www.lucumo.net/
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2w ago

I am happy to announce the followup to my original blog post Battle of Instant Messenger! Comments and evaluations of privacy-focused instant messengers:

https://gagliardoni.net/#20260918_im_battle_2

This is actually not a full update, but my comments to the freshly released videoguide by PrivacyGuides' Jonah Aragon (link in blog post).

#privacy #im #security #anonymity #signal #deltachat #xmpp #simplex #jami #threema #discord #slack #infosec #crypto #cryptography #quantum #postquantum #pqc

gagliardoni.net
4
0
2
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 3w ago

I just noticed that Google Maps now does not even allow to see business opening times if you don't log in. Surprised it took so long!

Enshittification continues!

#google #bigtech #googlemaps #gmaps #enshittification

infosec.exchange
3
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 14mo ago
This made me chuckle. #debian #humor #ipv6 #y2k38 #hackernews
621
1
312
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

BREAKING! Meshcore team splits over dispute over AI-generated code disclosure, and hostile trademark takeover.

Meshcore is an off-grid, decentralised mesh radio platform powered by low-cost and public access LoRa radio technology for reliable, long-range emergency text and embedded sensors communication. It can communicate across kilometres — no towers, no subscriptions, no single point of failure.

https://blog.meshcore.io/2026/04/23/the-split

#meshcore #meshtastic #lora #radio #opensource #foss #drama #privacy #security #selfsovereignty #ai #copyright #takeover

Meshcore.io - Why The Split? - MeshCore Blog
blog.meshcore.io

Meshcore.io - Why The Split? - MeshCore Blog

Migrating to the new meshcore.io site

82
19
139
2
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
It begins: https://マリウス.com/i-regret-migrating-to-codeberg/
マリウス.com
3
2
2
1
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago
Replying to
@hopeless I don't know enough to judge the full story, I am just reporting what the announcement says, and it mentions explicitly nondisclosure of AI in code production and hostile trademark registration and project takeover as reasons for the split. That said, it is always important to distinguish facts (above) from opinions (below): In my personal opinion: 1) Given the current (lack of) consensus on the ethics, quality, and legality of AI in code production, I think it is just good sense to disclose the use of AI when contributing (note this is also our policy at Shufflecake: AI code use is not forbidden, but must be disclosed); 2) in any case, appropriation of trademark in a community project can only be seen as community-unfriendly behavior at best, a jerk move at worst. And of course take this as a gut reaction without having still heard the other side of the story, which I'd be curious to hear since I started recently playing around MeshCore and I found it an interesting project.
10
15
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 11mo ago

Some big news regarding mobile OSes:

First, Graphene OS has confirmed a partnership with a large OEM to bring support to non-Pixel devices (Snapdragon SoC):

https://piunikaweb.com/2025/10/13/grapheneos-ending-pixel-exclusivity-new-oem/

This is good news, but IMHO it only delays the unavoidable demise of free AOSP-based projects since Google is now finally pulling the rug.

Second, the FSF announced Librephone, an initiative to bring real freedom to mobile devices:

https://www.fsf.org/news/librephone-project

This is also good, but it must be taken in the right perspective: Librephone, as far as I understand it, is not a new mobile OS, but rather an initiative to open-source existing proprietary firmware blobs. AOSP-based open source OSes like Lineage, Graphene, and even /e/OS, will hopefully benefit from this initiative, by being able to replace binary blobs with open-source firmware. But they still remain AOSP-based solutions, and therefore bound to the Google ecosystem.

There are two problems here that really need to be addressed.

The first one is political. Legislators and citizens must come to acknowledge that a democratic society where the full mobile ecosystem is in the hands of a corporate duopoly is not acceptable.

The second one is technological: AOSP is not a fully free OS, it's a trojan horse, a trap set by Google years ago that is springing right now. We need to move away from Android and embrace full GNU/Linux solutions, or even something completely new, at this point I don't even care. I've heard good opinions of Postmarket OS. Any feedbacks here?

Say what you want about Richard Stallman, but he saw this coming.

#android #aosp #google #lineageos #grapheneos #eos #postmarketos #libre #foss #floss #opensource #privacy #security #surveillance

piunikaweb.com
39
4
26
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@tante@tldr.nettime.org sorry, the "how will people enforce this" argument is real, dismissing it will not make it disappear. I am a regular Codeberg user, left GitHub in 2019, and co-maintain Libre projects that saw very little if none at all AI in development. And still I think this decision will backfire badly. I, like most of Codeberg users, was not even aware that this discussion was in place, did not vote. This only passed because of the anti-AI Luddite crowd. Which, mind you, has a point, I have very conflicting feelings about AI myself, and I think that the current trajectory is quite worrying. But this is just a knee-jerk reaction that has clearly not been thought of well enough. I applaude the philosophy, or the intent if you want, of not having Codeberg turn into another SlopHub. But this is fairy-tale wishful thinking. There is no way to reliably detect AI-generated code at scale in 2026. I can already smell the mutual witch hunts across projects and "camps". Anyway, I hope I'm wrong. #codeberg #ai #llm #drama #opensource #ludd #luddism #antiai #libre #foss #floss #slop #github
2
6
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

Oh great, just what I needed today.

Claude is rolling out identity verification through Peter Thiel's co-funded Persona.

This is like having your neighborhood crack gang selling narcotics out of convenience stores, rolling out loyalty card programmes, partnering with a contract security firm to inspect IDs of customers at checkout, and selling that data to the police in the hope of getting permission to sell inside Walmarts as well.

#palantir #politics #surveillance #ai #claude #anthropic #pentagon #usa #peterthiel #privacy #security #ageverification #idverification #anonimity #cypherpunk #humor

infosec.exchange
8
0
6
1
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

I've heard Elon Musk is about to launch an amazing new app called Xchat, but I'm confused: I recall using it already in the early 2000's!

#xchat #security #privacy #irc #elon #elonmusk #humor #2000s #goodoldtimes #retro

infosec.exchange
7
0
1
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

BREAKING! GnuPG introduces quantum-resistant ML-KEM (Kyber) as encryption algorithm!

https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html

This is great news! However, as I've been saying for a while, we should stop considering Harvest-Now-Decrypt-Later as the only thing to be immediately concerned about. The problem of signatures (Trust-Now-Forge-Later) is wrongly assumed to be way less urgent, but the reality is that rolling out a certificate migration will be extremely painful, and quantum attacks against signatures will be stealthy and of difficult attribution initially. Especially for a project like GnuPG, it's extremely important to adopt quantum-resistant signatures ASAP.

#crypto #cryptography #PGP #GnuPG #quantum #security #privacy #cypherpunk

lists.gnupg.org
5
0
2
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@ury@fedi.trough.lol didn't know this one. "Built on ATproto", which I'm not a big fan of, but will have a deeper look regardless, thanks!
1
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
And, just to be clear, since what I wrote seems prone to misinterpretation: If there were a magic spell able to flag with confidence code generated with AI by more than X% amount, whatever X or surrounding policy is, then it would all make sense. But I don't believe in magic, and you shouldn't either. Here are a few examples of what I'm afraid it's going to happen: FLOSS project "OpenHemorrhoid" splits over an intestine dev dispute on tabs-VS-spaces. Now we have "OpenHemorrhoid" and "LibreHemorrhoid" accusing each other of AI-generated code at every PR. Indie dating sim game "Kawaii Shinobi Kanojo" is targeted and harassed with unproven AI-gen reporting because the lack of nonbinary characters is interpreted as a queer-phobic political stance of the dev. Libre "ICE tracker and reporting" app is taken down not by US authority overreach, but by mass allegations of AI-generated code. Well, I hope I'm wrong, the community is very mature after all, I'm sure none of this will happen. #sarcasm
1
0
2
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

FYI, I'll be schmoozing around at EUROCRYPT 2026, May 10-14 in Rome. My employer Horizen Labs is a sponsor of this amazing cryptography conference. I'll be giving a talk at the affiliated event CAW (Cryptography Applications Workshop) on the latest updates of Shufflecake, including juicy news on hidden OS. Pass by to say hi!

#cryptography #crypto #security #privacy #eurocrypt #iacr #horizenlabs #shufflecake #caw2026

infosec.exchange
4
1
1
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
Just to be clear: Not saying this is bad on them, Mailbox offers a very good service at a decent price IMHO. But it's sad that they too, probably, got impacted by the ridiculous, AI-driven hardware price increase.
1
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago

DeepSeek V4 released!

https://api-docs.deepseek.com/

#ai #china #digitalsovereignty #opensource

api-docs.deepseek.com
2
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 11mo ago

Great article by F-Droid on "What We Talk About When We Talk About Sideloading".

https://f-droid.org/2025/10/28/sideloading.html

A few excerpts:

It bears reminding that “sideload” is a made-up term. Putting software on your computer is simply called “installing” [...] the term “sideload” was coined to insinuate that there is something dark and sinister about the proces

You, the consumer, purchased your Android device believing in Google’s promise that it was an open computing platform and that you could run whatever software you choose on it. Instead, starting next year, they will be non-consensually pushing an update to your operating system that irrevocably blocks this right and leaves you at the mercy of their judgement over what software you are permitted to trust.

You, the state, are ceding the rights of your citizens and your own digital sovereignty to a company with a track record of complying with the extrajudicial demands of authoritarian regimes

#google #android #aosp #security #privacy #enshittification #bigtech #opensource #politics #fdroid

What We Talk About When We Talk About Sideloading | F-Droid - Free and Open Source Android App Repository
f-droid.org

What We Talk About When We Talk About Sideloading | F-Droid - Free and Open Source Android App Repository

We recently published a blog post with our reaction to the new Google Developer Program and how it impacts your freedom to use the devices that you own in th...

7
2
6
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 9mo ago
Replying to
@Gargron@mastodon.social @Vivaldi@social.vivaldi.net I'm not sure whether moving to Vivaldi makes sense or not, but this is a very wise sentence: uBlock Origin [...] is the most important extension for being able to browse the web nowadays. Seriously, recently I happened to browse random stuff from a "normie Chrome" and, fuck my life, how do people manage to live with that? No wonder everybody seems to be getting crazier by the day.
3
1
2
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago
Replying to
@hopeless I don't know who blocked you, but from my point of view your contribution to the conversation was misdirected. You are trying to make a point pro-AI, which can be agreed upon or not, but the story was about a dev who used AI to contribute code without disclosing it. And that's only the minor side of the story, from my point of view it was much more about the trademark registration thing. Regardless of one's stance about AI, the facts stand that a sizeable share of folks don't like it, so it is IMHO a bit disrepectful to not disclose its use in a community project.
1
1
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago
Replying to
@nhamiel@infosec.exchange ROTFL all things as usual I see 😉
1
1
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 8mo ago
Replying to
@thedarktangent@defcon.social it is becoming increasingly clear how critical this observation is. Considering Zooko's triangle ( https://en.wikipedia.org/wiki/Zooko%27s_triangle ), I am getting more and more convinced that anything that does not rely on a cryptographic identity is a waste of time in the long run. Yes, even Mastodon. DNS -> Namecoin Mastodon -> Nostr Signal -> Jami/Briar/SimpleX/Etc Yes, I know that many of these alternatives carry a questionable philosophical/cultural background. But, from the technological point of view, they are probably the way to go.
en.wikipedia.org
2
2
1
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 6mo ago
Replying to
@sophieschmieg@infosec.exchange from a quick look, this seems a bit... audacious? under plausible assumptions, the runtime for discrete logarithms on the P-256 elliptic curve could be just a few days for a system with 26,000 physical qubits
1
1
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 8mo ago
Replying to on bsky.brid.gy
@malb.bsky.social Now, that's an interesting interdisciplinary mix.
1
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 10mo ago
Replying to
@nomad99@techhub.social @jolla@techhub.social @fdroid Yes, I saw the announcement via Hacker News, this is great, I'm keeping my eyes on that! Totally agree that the way forward is beyond Android.
1
2
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@nokke@mstdn.social all understandable, but how does banning certain projects help? This is what I don't understand.
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to on gruene.social
@JonathanTreffler@gruene.social @tante@tldr.nettime.org that clarifies, thanks.
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Here is my favourite new insult: you are load—bearing (em-dash on purpose). #humor #ai #llm #chatgpt #claude #anthropic #opus #emdash
0
0
1
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 42m ago
Here is how I wasted the last 30 minutes with #mozilla #thunderbird Suddenly, the "add attachment" dialogue window stopped appearing. I could not attach memes to my emails anymore. I messed a bit around, unsuccessfully. Nothing appears anywhere in logs. I also checked #bugzilla , but that bug tracker is a huge mess and I can't wrap my head around it. Defeated, I tried #ai , which, I have to admit, helped. But not immediately. It went carefully through discarding possible culprits one by one, starting from the most common issues, until it found the cause. The culprit, in my case, is a ridiculous #bug (anyone feel free to report it, I won't touch Bugzilla with a stick) I deleted the last directory which I had last used to attach a file from. This path remains stored as default "last used" directory. Thunderbird did not find the directory anymore and decided to FREAK OUT SILENTLY instead of doing something sensible, like defaulting to my home, or at least alerting me that the directory could not be found. I want my 30 minutes back :( #rant #linux #opensource #foss #floss
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 7mo ago
Replying to
@dyne nooo, don't go to Matrix! https://gagliardoni.net/#im_battle_2025
gagliardoni.net
0
1
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@mailbox_org@social.mailbox.org I tried some of your competitors. I chose you for many reasons, but one important one for me (which I couldn't find in most others) is the ability, when using custom domains, to send an email with a custom "From" address with any arbitrary *@mydomain.com chosen on the fly when I am sending from an admin account mailbox with catch-all enabled. Thanks for this sane choice!
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 4mo ago
Replying to
@sash@hachyderm.io that's pretty cool!
0
0
1
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 5mo ago
Replying to
@scopecreeppress @hopeless to be fair, Meshtastic is a toy compared to Meshcore, at least according to my tests.
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 1mo ago
Replying to
@SomeAnoTooter@mastodon.online @mattblaze@federate.social @GrapheneOS@grapheneos.social before AOSP started to become trash, and Google removed full disk encryption and replaced it with file-based encryption in order to have the LOAD-BEARING feature of alarm clock, screensaver and other LIFE-SAVING amenities even when the phone has just rebooted, it was possible to have TWO unlock mechanisms: one, usually more secure, at boot (e.g., a long passphrase after a reboot), and one, more convenient, for screen unlock (PIN or biometrics). This was very useful if your phone didn't have (or you didn't want to rely on) a TPM, because that's the whole security layer nowadays: a TPM makes guessing even a short PIN unpractical (at the cost of rooting the phone). https://gagliardoni.net/#android_dual_cryptfs_dec_2020 Not a good security model nowadays anyway: PIN + Graphene OS is best we can reasonably get against searches on mobile. Until we get all implanted with mind-controlled chips driving an NFC emitter of course. Looking forward to that!
gagliardoni.net
0
1
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2w ago

@lcamtuf@infosec.exchange I'm trying to find a meme showing myself ripping my bloody eyeballs off my skull, but I can't because I'm blind now.

0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@tante@tldr.nettime.org Just to be clear, since most of the crowd here seems to miss my point: If there were a magic spell able to flag with confidence code generated with AI by more than X% amount, whatever X or surrounding policy is, then it would all make sense. But I don't believe in magic, and you shouldn't either. Here are a few examples of what I'm afraid it's going to happen: FLOSS project "OpenHemorrhoid" splits over an intestine dev dispute on tabs-VS-spaces. Now we have "OpenHemorrhoid" and "LibreHemorrhoid" accusing each other of AI-generated code at every PR. Indie dating sim game "Kawaii Shinobi Kanojo" is targeted and harassed with unproven AI-gen reporting because the lack of nonbinary characters is interpreted as a queer-phobic political stance of the dev. Libre "ICE tracker and reporting" app is taken down not by US authority overreach, but by mass allegations of AI-generated code. Well, I hope I'm wrong, the community is very mature after all, as this thread shows, I'm sure none of this will happen.
0
0
0
0
Open post
Tommaso Gagliardoni @tomgag@infosec.exchange
· 2mo ago
Replying to
@LillyHerself@mastodon.social So true
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 21:33:15 UTC