Note di Matteo


Note

Waymo ha calcolato quanto i suoi veicoli a guida autonoma sono più sicuri rispetto alla guida umana:

Examining the data, Waymo said it found:

  • 82 percent reduction in injury-causing crashes compared to human drivers
  • 95 percent fewer crashes causing serious injury or worse
  • 93 percent fewer pedestrian crashes resulting in injuries
  • 86 percent fewer cyclist crashes resulting in injuries
  • 82 percent fewer motorcycle crashes resulting in injuries
#618 /
24 settembre 2026
/
17:33
/ #mobilità#waymo

Per aggiornare il software del sistema informativo ospedaliero (SIO) ASUIT, l'applicazione andrà offline per dure ore in modo programmato.

Quindi per aggiungere delle feature a un prodotto si sospende la gestione ordinaria del pronto soccorso.

L'aggiornamento programmato consentirà di introdurre importanti migliorie e adeguamenti al sistema, tra cui l'implementazione del monitoraggio della violenza di genere, la gestione automatizzata delle chiamate ai monitor, l'ottimizzazione delle registrazioni dei trasferimenti e del triage oltre all'aggiornamento delle codifiche di diagnosi. Al termine dei lavori, le funzionalità della piattaforma saranno integralmente ripristinate.

Sempre lo stesso discorso sul zero downtime fatto in #607.

#616 /
23 settembre 2026
/
20:17

Testimonianze che stanno girando su Twitter che frenano un po' il trend forzato che sta trasformando lo sviluppo software in pura velocità e quantità rimuovendo l'ingegneria:

I am done with this shit. It is over. The state of engineering right now is horrible. It has been half a month since I started a new role at a big company. Nobody knows anything here. The specs, code, tests, PRDs, tickets, resolution of those tickets, reports, etc., everything is made by Claude Code. Nobody on my team likes this. They are being forced to ship as much as they can. I have heard multiple times from higher management that pushing code is not a bottleneck, so why are we slow? People are working 12 to 13 hours a day just to press enter. Nobody is reading anything. Humans in corporate are doing nothing on their own. Everyone, literally everyone, from an L1 to an L7 engineer here is doing the same thing. Talk to Claude. There is no sense of victory. Nobody is resolving bugs. In reality, nobody is thinking anymore. Everything is done by LLMs. It is so soul-sucking. I would not mind it, to be honest, if we were at least given the time to check out the code and see what is going where. But no, the goal is to just ship. No matter what happens.

(@v0xium)

I’m slowly starting to hate AI code review.

Massive amounts of nitpicking and an ungodly amount of corner-case defensive programming. After a few rounds the intent of the code is lost under mountains of extra code forced by the reviewer.

I’m starting to be more agressive with implementer agents pushing back heavily for the reviewer agents to prove why their nitpick will make the code better, only for the reviewers to backtrack in frenzy. SO WHY DID YOU RAISE THIS IN THE FIRST PLACE?

All this because I still require that „this code must be readable and easily understandable”

(@marcinbunsch)

#614 /
21 settembre 2026
/
10:43
/ #ai#dev

Ora che i poster di feste e sagre sono tutti identici perché fatti con ChatGPT o Gemini, un tizio ha testato per noi come generare stili più unici con ChatGPT. Qua c'è una galleria di prompt (in inglese) per diversi stili:

#613 /
20 settembre 2026
/
09:20
/ #ai#design

Che vulnerabilità in Docker per macOS:

We escaped Docker's hypervisor with three lines of bash. CVE-2026-77179: A container gets complete read and write access to the host filesystem.

When you mount a folder into a container, Docker's VMM uses virtio-fs, and the file server runs on the host.

Because of a TOCTOU bug, if a container opens a file, deletes it while holding its file handle open, and replaces the parent folder with a symlink, the kernel will follow the symlink to anywhere on the host.

mkdir pv && : > pv/.canary && exec 9< pv/.canary
rm pv/.canary; rmdir pv; ln -s /Users/Shared pv
echo CONFIRMED > /proc/self/fd/9
#611 /
19 settembre 2026
/
19:07
/ #security#macos

A OpenAI gli ingegneri non sono più specializzati in tecnologie specifiche ma contano di più queste qualità:

  • Judgment: is an approach the right one, or is another more optimal? Should a feature be shipped or binned?
  • Prioritization: what’s the next most important thing to work on and what is not worth doing, right now?
  • Agency: the best engineers relentlessly come up with ideas and parallelize with agents as much as possible without being prompted.
  • Taste: what does “great” actually look like? Engineers with good taste produce standout artifacts in functionality, architecture, design, etc.
#608 /
16 settembre 2026
/
11:57
/ #ai#openai

Zero downtime

"Il sistema TreC+ si ferma per manutenzione programmata" per 4 ore, comunica l'ASUIT.

Mi viene in mente questo thread Twitter dove Gergely Orosz argomenta come tirare giù i sistemi per ore, spesso di notte, è un forte segnale di scarsa cultura e maturità ingegneristiche. Si finisce per considerare "eroico" il lavoro degli sviluppatori e degli ingegneri che stanno svegli la notte, quando in realtà non è una buona pratica perché queste persone non imparano niente (e non ci si prende mai la briga di mirare a manutenzioni e migrazioni zero downtime e safe) e ci rimettono comunque inutilmente i clienti.

#607 /
15 settembre 2026
/
13:45
/ #dev#digitalizzazione

Firewall strani

Così scopro dalla Rai che per riattivare un firewall «andato in autoprotezione» (?) bisogna «reinserire migliaia di password di accesso» (??).

Il blocco di un firewall è un evento raro ma può accadere. Ripristinare un sistema cosi complesso in un'ora (con la necessità di reinserire migliaia di password di accesso), sottolinea Trentino digitale, è un successo reso possibile dalla preparazione professionale dell'azienda e dei suoi tecnici.

#606 /
15 settembre 2026
/
13:37
/ #digitalizzazione#informazione#reti

Nuove gTLD Aruba?

Aruba ha grandi ambizioni a questo giro di nuove gTLD e ha fatto domanda per 39 TLD:

  • Technology and digital services: bit, beta, cart, demo, lab, vps, sito
  • Trust Services: pec, rem, sign
  • Sector verticals: aid, bnb, gaming
  • Everyday language and universal terms: all, ask, ciao, daily, easy, fix, gen, genius, hello, hola, human, kit, mars, max, moon, tag, tex, zzz
  • Positive and expressive terms: happy, omg, pop, super, yes
  • Geographic identity: roma
  • Health and wellness: gym, zen

Durante il round precedente (2012 o giù di lì) aveva ottenuto la TLD .cloud.

#605 /
15 settembre 2026
/
11:22
/ #aruba#domini

Fatturazione elettronica in Francia

Arriva la fatturazione elettronica anche in Francia, scrive Fisco Oggi:

Le grandi imprese e le imprese di medie dimensioni, inoltre, hanno anche l’obbligo di emettere le loro fatture in formato elettronico. Obbligo che per le piccole e microimprese scatterà dal 1° settembre 2027.

L'architettura del sistema è diversa da quella italiana:

Rispetto all’Italia, dove l’infrastruttura che permette la gestione delle e-fatture, il cosiddetto Sistema di interscambio, è unico ed è gestito dall’Agenzia delle Entrate nazionale, la Francia ha deciso di affidare agli operatori privati la piattaforma tecnologica per lo scambio delle e-fatture e dei relativi dati. La DGFiP mantiene il controllo regolamentare e informativo del sistema e, per garantire la dovuta trasparenza, ha istituito nel settembre del 2025 un Annuaire de la facturation électronique. Si tratta di un registro centrale che permette di sapere, per ciascuna impresa, quale piattaforma gestisce la sua fatturazione e quali sono gli indirizzi elettronici di fatturazione.

Dal 2030 sarà obbligatoria in tutti gli stati membri dell'UE ed entro il 2035 i sistemi andranno armonizzati.

#604 /
15 settembre 2026
/
10:19
/ #digitalizzazione#italia

A Singapore:

[...] gli stipendi dei politici devono essere calcolati considerando il mercato del lavoro, per evitare che le persone competenti «non siano scoraggiate dal farsi avanti per guidare il paese». Allo stesso tempo non devono essere troppo alti, per riflettere un certo spirito di servizio, e soprattutto devono essere trasparenti e legati ai risultati del singolo ministro e del paese.

(Il Post)

#601 /
12 settembre 2026
/
13:29

Dark/light mode

Discussioni sul web su quanti stati dovrebbero avere i toggle modalità diurna/notturna in app e siti. Cito il riassunto da Web Weekly 199:

How much controversy can there be around dark/light mode toggles? Turns out, a lot. Lea Verou kicked off a whole thing. People have opinions on these little two- or three-state toggles.

So, Lea started the discussion by arguing that website visitors don't care about dark mode toggles (I agree) and that they only reach for them when something's off.

A dark mode toggle is a temporary comfort adjustment. [...] It’s situational, it’s immediate, and it’s usually about the environment you’re in rather than a considered long-term stance on color schemes.

From there, she argues that a dark mode toggle should only have two options: the system preference (shown as dark or light) and the opposite. That's smart. Whenever things are different from the system, you can store the preference that's not the system default. If it matches their general settings, there's nothing to do, and if you go back to the system setting, you clear the preference. This approach seems reasonable to me at first sight.

Bramus disagreed, though.

When building these types of control, I think that one of the main goals here should be to keep things predictable for users.

And well, that's a strong point, too, I'd say. A little sun icon that actually means "system preferences" is a bit tricky to understand if you really care about light and dark modes. I tend to agree here, and it seems like a "Agree to disagree." case, but the whole community had feelings about this. Lea shared more feedback in a follow-up post. And it closed with a banger:

And then it dawned on me: all these persistent dark mode toggles I had seen, literally all of them have been on developer-facing sites!

And I think that's what I came to conclude, too. It's an interesting discussion to have but I really don't think normies care too much about two, three, or no dark/light mode states. Things can always be better and smoother, but for this case I think it's just us nerds who love discussing these things. 😅

#599 /
10 settembre 2026
/
16:17
/ #web-dev

GPT-6

Armin Ronacher mostra con degli esempi come GPT-6 Astra scriva codice illegibile. "It's AGI if you don't look". Codice denso e oscuro e assenza totale di commenti. La fine di un'arte.

#598 /
9 settembre 2026
/
20:28
/ #ai#codex#openai

Hacking AI customer service agents

Il customer service completamente automatizzato con AI aumenta i rischi legati allo spoofing:

how i hacked 320+ companies that replaced their cs team with "smart" ai agents:

  1. drafted a gdpr request to support@
  2. changed the FROM header from my e-mail to yours (spoofing)
  3. put myself in CC
  4. ai agent responds with YOUR data to BOTH of us 😈

Qui il tweet e qui l'articolo.

#597 /
8 settembre 2026
/
20:08
/ #ai#security

Autistici/Inventati, Banca Etica e la dipendenza dagli USA

Notevole comunicato stampa di Banca Etica che commenta la chiusura di Autistici/Inventati, storica associazione di attivismo sociale e digitale italiana.

La banca, a cui il collettivo si affida dal 2018 per il proprio conto corrente, scrive che si trovano costretti a sospendere il conto per rispettare la lista sanzionatoria OFAC del governo statunitense, che dovrebbe essere riservata all'antiterrorismo ma che in questo caso viene usata per fini politici.

La parte notevole è che la banca sta chiedendo pareri da tutte le parti per capire se c'è un modo per non rispettare questa decisione del governo statunitense, ma che è forte il rischio di creare un danno agli altri clienti della banca vista la totale dipendenza del sistema dei pagamenti dagli Stati Uniti:

[...] Una banca italiana che mantenga rapporti con un soggetto inserito nelle liste OFAC, potrebbe essere oggetto di “sanzioni secondarie” che implicano la cessazione di ogni servizio erogato da intermediari statunitensi: questo implicherebbe per tutti i clienti di Banca Etica l’impossibilità di utilizzare carte di credito e carte di debito (che oggi dipendono da un sostanziale monopolio di operatori USA) e l’impossibilità di effettuare pagamenti in aree extra-euro per i quali sono necessari intermediari finanziari quasi sempre statunitensi.

#595 /
7 settembre 2026
/
13:38

WeatherNext3

Il nuovo modello di previsione del meteo di Google WeatherNext3 è il nuovo stato dell'arte nelle previsioni meteo e la cosa migliore è che non è solo ricerca ma finisce direttamente nei prodotti e a disposizione del pubblico:

To bring these breakthroughs out of the lab and into the real world, we’re integrating WeatherNext 3 across Google’s core ecosystem and beyond:

  • High-resolution forecast data: We’re making global weather predictions, updated hourly and ready to integrate into your workflows with no model setup required. This enables researchers, developers and businesses to query the data in BigQuery and Earth Engine, or bulk-download from Google Cloud Storage.
  • Available globally: WeatherNext 3 will begin powering weather experiences within Google Search, Gemini app, Google Maps, Google Maps Platform Weather API, and Google Earth Engine starting today. The update dramatically improves longer term forecasts. When planning a day or more ahead, people will see up to 50% more accurate precipitation forecasts — with the greatest improvements in regions where forecasts have historically been less reliable. So if you’re packing for a weekend trip or deciding the best day for an outdoor activity, you’ll now get more accurate predictions to help you plan.

I dati si possono consultare su mappa qui nel Weather Lab.

#592 /
3 settembre 2026
/
18:00
/ #ai

Altra vittima del vibe coding, Flussonic aveva un sito così bello prima, ora è una sloppata palese:

Prima:

#587 /
29 agosto 2026
/
11:38
/ #ai

How Mux chooses a CDN in 9.9ms. Mux.com ha costruito internamente un CDN router dopo aver provato diversi servizi nel corso degli anni. Molti dettagli tecnici, scegliere la CDN da usare per uno specifico utente in un sistema multi-CDN è un problema più complesso di quello che sembra.

#586 /
28 agosto 2026
/
20:23
/ #cdn#video

Claude ha iniziato a parlare difficile da aprile (Opus 4.7):

Io avevo notato il problema da Opus 4.8 come avevo scritto qui.

#585 /
28 agosto 2026
/
10:05
/ #ai#anthropic

Altri due esempi di uso intelligente di object storage:

Fast drilldown dashboards from a single Parquet file: One 40MB Parquet data cube, an 18KB reader, an R2 bucket, and a few unassuming http range requests.

Git at any scale. Cursor spiega Continuity, il suo nuovo backend git che sta alla base di Origin. Partendo dalla storia di git in cloud, come GitHub ha quasi-risolto la scalabilità con Spokes, e come Continuity evolve l'idea per renderla infinitamente scalabile in lettura pur mantenendo la consistenza, tramite un WAL git in object storage che linearizza le scritture permettendo però scalabilità orizzontale in lettura illimitata.

#583 /
25 agosto 2026
/
15:18
/ #storage#cloud

Pagina 1 di 20 Successiva →