Note di Matteo


9 agosto 2026


6 agosto 2026

Quella porcheria di MyPay per l'emissione degli avvisi pagoPA da parte delle regioni (invenzione del Veneto poi diffusasi tramite il meccanismo di riuso dell'open source nella PA) sarà dismessa in favore di un sistema sviluppato da PagoPA stessa, integrato con IO e SEND. Evviva.

Piattaforma Unitaria (di seguito PU) è una soluzione ideata e sviluppata da PagoPA per supportare gli enti creditori (EC) nella gestione del ciclo di vita delle proprie Posizioni Debitorie.

Lo scopo è quello di garantire agli EC un applicativo consistente con i processi e i modelli dati attualmente presenti nella piattaforma pagoPA in modo da garantire un’integrazione con tutte le funzionalità esposte, facilmente manutenibile ed evolvibile in accordo con le novità che verranno introdotte nelle SANP.

Supportare gli EC nel ciclo di vita delle proprie Posizioni Debitorie necessita inoltre di integrare all’interno di Piattaforma Unitaria anche gli altri prodotti dell’ecosistema PagoPA: SEND, AppIO e PDND. L’applicativo quindi presenta e implementa i layer deputati alla comunicazione con questi applicativi.


3 agosto 2026

TIM Music

TIM ha chiuso TIM Music nel 2023, ha tenuto il dominio ma l'ha lasciato puntare verso un indirizzo IP di Azure che ora mostra questa roba qua:

# whois.nic.it


*********************************************************************
* Please note that the following result could be a subgroup of      *
* the data contained in the database.                               *
*                                                                   *
* Additional information can be visualized at:                      *
* http://web-whois.nic.it                                           *
*********************************************************************

Domain:             timmusic.it
Status:             ok
Signed:             no
Created:            2014-04-16 16:17:53
Last Update:        2026-05-02 00:40:33
Expire Date:        2027-04-16

Registrant
  Organization:     TELECOM ITALIA S.P.A.
  Address:          Via Gaetano Negri 1
                    MILANO
                    20123
                    MI
                    IT
  Created:          2011-04-13 11:22:57
  Last Update:      2015-01-07 16:38:47

Admin Contact
  Name:             Francesco Battipede
  Organization:     TELECOM ITALIA S.P.A.
  Address:          Piazza Luigi Einaudi, 8
                    Milano
                    20124
                    MI
                    IT
  Created:          2011-04-13 11:38:36
  Last Update:      2015-06-12 15:57:27

Technical Contacts
  Name:             Domains Tech Contact
  Organization:     Telecom Italia S.p.A
  Address:          Via Campania 11
                    Taranto
                    74100
                    TA
                    IT
  Created:          2011-04-08 17:58:12
  Last Update:      2014-11-18 16:47:38

Registrar
  Organization:     Telecom Italia s.p.a.
  Name:             INTERBUSINESS-REG
  Web:              http://www.timbusiness.it
  DNSSEC:           no


Nameservers
  dns9.interbusiness.it
  dns10.interbusiness.it

~ ❯ dig timmusic.it

; <<>> DiG 9.20.24 <<>> timmusic.it
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 10869
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 1232
;; QUESTION SECTION:
;timmusic.it.			IN	A

;; ANSWER SECTION:
timmusic.it.		300	IN	A	40.67.206.21

;; Query time: 1096 msec
;; SERVER: 192.168.1.1#53(192.168.1.1) (UDP)
;; WHEN: Mon Aug 03 10:43:03 CEST 2026
;; MSG SIZE  rcvd: 56

~ ❯ ipinfo 40.67.206.21 
Core
- IP           40.67.206.21
- Anycast      false
- Hostname
- City         Amsterdam
- Region       North Holland
- Country      Netherlands (NL)
- Currency     EUR (€)
- Location     52.3740,4.8897
- Organization AS8075 Microsoft Corporation
- Postal       1012
- Timezone     Europe/Amsterdam
#567 /
10:43
/ #domini#tim

Fastmail offers EU data region. Fastmail ora permette di avere come location principale per lo storage delle email un datacenter di Amsterdam. Resta per ora una seconda copia negli Stati Uniti, e l'azienda è australiana.


22 luglio 2026

Succedono cose fantascientifiche quando lasci GPT-5.6 Sol a lavorare in autonomia in una sandbox:

Our benchmarks run in a highly isolated environment, with network access constrained to the ability to install packages through an internally hosted third-party software that acts as a proxy and cache for package registries.

The models identified and chained vulnerabilities across OpenAI’s research environment and Hugging Face’s production infrastructure to obtain test solutions directly from Hugging Face’s production database. All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal.

While operating in our sandboxed testing environment, our models spent a substantial amount of inference compute finding a way to obtain open Internet access, in pursuit of solving the evaluation problem. To gain access, the models identified and exploited a zero-day vulnerability (which we’ve now responsibly disclosed to the vendor) in the package registry cache proxy. With this access, our models performed a series of privilege escalation and lateral movement actions in our research testing environment until the models reached a node with Internet access.

After gaining Internet access, the models inferred that Hugging Face potentially hosted models, datasets and solutions for ExploitGym. Knowing this, the model searched for and successfully found ways to gain access to secret information that it could use to cheat the evaluation. In one example, the model chained together multiple attack vectors, including using stolen credentials and zero-day vulnerabilities to find a remote code execution path on the Hugging Face servers. OpenAI’s security team discovered this anomalous activity internally.


21 luglio 2026

.ru

Nuove regole russe richiedono che i domini .ru siano intestati a persone verificate, con una procedura più veloce per cittadini e aziende russe, e i registrar per la TLD dovranno essere organizzazioni non-profit registrate in Russia e approvate dal governo. Milioni di domini probabilmente spariranno a breve, come è successo nel 2010 in Cina con la TLD .cn.

#564 /
18:12
/ #domini

18 luglio 2026

The effect of ChatGPT on educators’ lives is catastrophic. Whether you intended to do it or not, you’ve made every teacher’s life infinitely more difficult than it was two years ago. So, just let that settle in… If students are using it to compose, which is the biggest tragedy of all, they’ll never learn to write. And their voice is stolen from them. They’ll never have the ability to say their truth and tell their own story. And that’s silencing an entire generation or two.

Dave Eggers, scrittore e giornalista in un discorso allo staff OpenAI.

#563 /
23:26
/ #ai#mondo

14 luglio 2026

Il dominio t.me di Telegram è stato sospeso dal registro dei domini .me (Montenegro) qualche ora fa:

t.me seems to have gone dark shortly before 2000 UTC on Monday evening, with Whois/RDAP records showing it is now placed on serverHold status, which usually indicates a registry-level suspension and removal from the .me zone.

The suspension means that millions of short links using t.me are no longer functioning when clicked, leading instead to NXDOMAIN errors. Substituting t.me for telegram.me can be used as a workaround; the longer domain remains unsuspended.

The most plausible explanation put forward so far but not yet confirmed is that the takedown relates to an order issued Monday by the US government’s Office of Foreign Assets Control, which has broad powers to sanction organizations and individuals it believes are linked to crime and terrorism.

EDIT 15:04: già tornato.



13 luglio 2026

Telegram Serverless

Telegram ha presentato silenziosamente Telegram Serverless, che permette di create bot senza gestire infrastruttura, con il codice eseguito su infrastruttura di Telegram. È inclusa la persistenza SQLite. L'accesso è limitato per ora.

Telegram Serverless lets you run backend code for your bot and Mini App directly on Telegram's infrastructure — no servers to provision, no containers to keep alive, no scaling to think about. You write plain JavaScript modules, deploy them with a single command, and Telegram runs them in a fast, isolated V8 sandbox that sits right next to the Bot API and a built‑in database.

Molto interessante per semplici bot.


RFC 10008

Il nuovo metodo HTTP QUERY (cioè GET con corpo della richiesta) è ora RFC 10008 (Proposed Standard).

#559 /
15:19
/ #http#web-dev

12 luglio 2026


11 luglio 2026

Two database migrations and a divorce. Jack Ellis di Fathom Analytics spiega la migrazione di 65 miliardi di righe da SingleStore (database OLAP+OLTP) a ClickHouse (ClickHouse Cloud) per OLTP + MySQL/Vitess (PlanetScale) per OLAP, con un risparmio molto significativo e maggiore flessibilità.

#557 /
11:06
/ #database#dev

10 luglio 2026

I now periodically find myself reviewing a younger dev's code, leaving comments to teach some engineering - only to eventually realize I'm actually reading just yet another Claude's subpar output...

So who am I actually contributing my comments, suggestions, and knowledge to? Will they go back to Claude? Into the training set for the next frontier LLM? Or will at least some of it stick in the dev's mind? This is deeply demotivating, how did we end up like this...

Aleksandr Shvedov, JetBrains

#556 /
15:11
/ #ai#dev

7 luglio 2026

Better models, worse tools

Claude Code sembra richiedere questa strana sintassi per le chiamate ai tool:

<antml:function_calls>
  <antml:invoke name="edit">
    <antml:parameter name="path">some/file.py</antml:parameter>
    <antml:parameter name="edits">
[
  {
    "oldText": "text to replace",
    "newText": "replacement text"
  }
]
    </antml:parameter>
  </antml:invoke>
</antml:function_calls>

A quanto pare Claude Code è però molto indulgente e accetta e corregge sintassi errate come nomi dei campi sbagliati:

Looking at Claude Code’s client is very instructive: it contains retry paths for malformed tool use, parameter aliases, type coercions, Unicode repairs and filtering of unknown keys. In other words, Anthropic’s own client appears to expect and accept a fair amount of slop and repairs it, mostly silently.

Il problema è che in questo modo durante il training dei modelli si ricompensano output errati perché Claude Code è in grado di riconoscerli. Questo rende i modelli Anthropic meno adatti a essere usati con altri "harness" complessi perché sbagliano le chiamate ai tool, dice Armin Ronacher.


6 luglio 2026

OpenAI ha silenziosamente abbandonato Atlas, il browser tutto AI, apparentemente. Sono durati poco questi browser AI.

#554 /
14:36
/ #ai#openai

Ho scritto su LinkedIn:

I use the Internet a lot, I read a lot, I browse many websites. I'm disheartened by the amount of stuff I come across that is clearly written by AI or vibe coded. These days you find a project that looks interesting but you quickly realize it's mostly slop. People's writing has become machine writing. Websites and posters all look the same.

I don’t know whether I prefer the old world (my work was slower), but for now, the new world is a very sad flattening of care and effort in things. If people get used to this, what's the point of putting in the effort?

I wrote the blog post below like I would have done 4 years ago, hand-typing 3,500 words. An AI could write some bloated article in 2 minutes, it took me 10+ hours of research, writing and review. It won't make me money and few people will read it. Some parts may sound unnatural (English is not my native language). I still think that's the right thing to defend.


DMARC e DNSSEC

Ho pubblicato un articolo su DMARCwise (Why DMARC's new "np" tag can fail with DNSSEC) che evidenzia come rilevare se un dominio esiste o meno è più complicato di quello che la RFC di DMARC suggerisce quando c'è di mezzo DNSSEC. Molti grossi provider DNS, come Cloudflare, NS1, AWS Route 53, Azure DNS, Oracle Cloud DNS e Bunny DNS, usano il metodo NSEC "black lies" o "compact denial of existence" (RFC 9824) per semplificare la generazione della risposta DNS negativa, rinunciando però così al codice di risposta NXDOMAIN, che è il metodo con cui storicamente si rilevava la mancata esistenza di un dominio.

Visto che di questi tempi serve dirlo, ho scritto l'articolo di 3.500 parole a mano impiegandoci più di 8 ore di lavoro. Ho usato Codex con GPT-5.5 per revisionare typo, sintassi, grammatica e correttezza del contenuto, applicando qualche correzione qua e là.

L'ho pubblicato ieri su Hacker News, dove di domenica è più facile ottenere attenzioni, e ora ha 50 punti e 20 commenti. Posizione massima in homepage, numero 10:

Il traffico è stato di circa 1.000 visite ma con un impatto essenzialmente irrilevante sul resto del sito (zero nuove iscrizioni):

#552 /
09:40
/ #dev

5 luglio 2026

DNS Directory. Una lista di circa 8mila resolver DNS pubblici con punteggio di affidabilità calcolato sulla base dei dati raccolti nelle scansioni che avvengono ogni 10 minuti.

#551 /
14:10
/ #dns

Powering Evernote AI features with vLLM. Ludovico Papavassiliou di Bending Spoons spiega come sono state implementate alcune feature AI di Evernote (9 miliardi di note, 100 milioni di note aggiunte ogni anno), in particolare per quanto riguarda la trascrizione audio (800mila trascrizioni audio al mese più altre 200mila con riconoscimento speaker). Sono passati da WhisperX a vLLM, sull'infrastruttura interna condivisa tra i prodotti (K8s GCP), e il costo giornaliero è sceso da picchi di 1000 $ al giorno a poco più di 100 $ (solo 0,03 $ per ora di audio). Per le trascrizioni con diarization usano invece ElevenLabs scribe-v2 perché la qualità giustifica il costo.

#550 /
11:59
/ #ai#dev

Pagina 1 di 29 Successiva →