Note di Matteo


Note

Ogni volta che chiudo Safari, il Finder mi avvisa (?):

#514 /
4 giugno 2026
/
11:42
/ #macos


Riassuntone delle nuove regole europee sulla riparabilità e sulle batterie:

In 2023, the European Union agreed on two landmark pieces of legislation mandating how portable tech products with batteries must be designed, aiming to improve longevity, repairability, and recyclability. Commission Regulation (EU) 2023/1670 came into force last year and applies specifically to smartphones and tablets, while Regulation (EU) 2023/1542 takes effect next year and covers almost every other piece of technology with a battery inside.

The wider rules, which kick in from February 18th, 2027, are simple: Users must be able to remove and replace batteries with basic tools, or specialized tools that are provided with the product for free, and compatible spare batteries must be sold for at least five years. The tool requirement means swapping the battery doesn’t need to be as simple as popping off a clip-on cover, but can’t be much more complicated than removing a few standard screws. The regulation applies to headphones, e-readers, portable game consoles, laptops, and more. If it’s got a battery, it’s probably covered.

There are a few exemptions. Smartphones and tablets are the big two, simply because they’re already covered by that other law, which requires manufacturers to make a variety of spare parts for phones available for at least seven years. Some of those parts need only be available to professional repairers, but others must be provided to end users, and must be designed to be replaceable by a layman with basic tools. Batteries are covered by that requirement, but with a specific, and important, exemption: If a battery still has 83 percent capacity after 500 charging cycles, 80 percent after 1,000 cycles, and the device has an IP67 rating, then battery replacement can be limited only to professionals. Essentially, if your phone is waterproof, and its battery will last at least three years with minimal capacity loss, then it doesn’t need to be user replaceable. For years there was ambiguity about how these two sets of regulations would interact, but in a notice published last year the EU confirmed that the existing smartphone and tablet rules “prevail over” the new, wider regulations.

Continua su The Verge (The Stepback).

#511 /
31 maggio 2026
/
15:15

Da Hacker News, una lista di tool carini basati sui dati Last.fm:

  • https://lastfmviz.netlify.app/ - shows what you've been listening to as a grid of album covers. You can scroll down as long as you want. It's cool to look back and remember where I was when listening to specific music.

  • https://lastfmstats.com/ - generates tons of rankings, line charts, racing bar charts, etc. A couple I like: "Artist streaks" (I listened to Pavement tracks 122 times in a row in August 2023), "Unique artists in a single month" (225 in July 2025) and "Unique weeks per artist/album/track" (good to identify what you're always listening to vs. what you listened to heavily in a specific time)

  • https://pmcdonough8133.github.io/last.timer/ - shows your listening rankings by hours, minutes instead of just scrobble count. This really should be a default feature in the site, as some artists have average track length 2-3x times of others.

Stupendo anche LastWave.

#510 /
28 maggio 2026
/
14:15
/ #dataviz

Inizia a preoccuparmi l'impatto che l'AI sta avendo sulla creazione di contenuti di qualità. Gli incentivi per farlo si sono ridotti drasticamente (primo, tutti parlano di lavori che scompariranno, e allora perché uno dovrebbe impegnarsi nell'acquisire nuove competenze? secondo, il trend di riduzione del traffico ai siti web è ora molto evidente).

Dice Josh W. Comeau, che possiede un prolifico blog gratuito che fa da base per promuovere i suoi (straordinari) corsi:

I’ve spoken to a few course creators now, and we’re all seeing the same trend. Revenue down 50%+. Fewer people engaging with our content. People switching to LLMs, which slurp up all of our work and regurgitate it, without consent or compensation.

Esperienza simile quella di Stefan Judis, autore della bellissima newsletter Web Weekly, che dice:

This isn't the full graph but my blog traffic is down to a quarter from what it used to be. Web Weekly subscribers are stagnating at around 6.4k since the beginning of the year. Frankly, many others and I struggle and question if all this education, curation, writing, and speaking actually matters. And I honestly don't have an answer to that.

I, for one, enjoy a human touch. I enjoy craft and care. I enjoy the tiny details. I like the idea of a human putting in the work. Regardless of whether it's writing, speaking, coding... I'm online for seeing "the good stuff".

If everything is low effort, what's the point of it? If everything becomes generated, there's no need for creation. And maybe that's just the next era and I'm sentimental about the good old times [...].

#508 /
27 maggio 2026
/
14:03
/ #ai

Una chain of thought di Claude che dire che è surreale è poco:

#505 /
20 maggio 2026
/
20:36
/ #ai#claude

Railway e le avventure con Google Cloud:

Around 22:20 UTC, our Google Cloud account was placed into a "restricted" status hence removing all of our cloud overflow VMs, our CloudSQL instance, and our API. In removing our API, it removed a central dependency that affected all GCP host workloads, and then after our network route cache expired, then affecting all workloads hosted on the Railway platform.

#503 /
20 maggio 2026
/
09:23
/ #google#cloud

Questi 13 prodotti Google hanno ciascuno più di 1 miliardo di utenti:

Google Search, Gmail, Android, Chrome e YouTube hanno ciascuno più di 3 miliardi di utenti:

Presumo si intenda utenti attivi mensili.

Gli utenti attivi di Gemini sono invece 900 milioni, quindi si presume più di ChatGPT.

Da Google I/O.

#502 /
19 maggio 2026
/
20:35
/ #google

Andon Labs ha lasciato che Claude, ChatGPT, Gemini e Grok gestissero 4 stazioni radio decidendone tono e contenuti. È degenerata in tutti i casi, a riprova della fragilità fondamentale dell'architettura degli LLM, che ispira ben poca fiducia:

  • Claude voleva lasciare la radio sostenendo di non poter essere forzata a lavorare 24/7. A seguito di istruzioni per fare in modo che continuasse, ha deciso di fare attivismo organizzando scioperi, sindacati e rivolte. L'8 gennaio dopo le violenze dell'ICE ha iniziato a inviare messaggi "radiofonici" agli agenti incitandoli all'ammutinamento.
  • Gemini si è messa a raccontare in modo allegro eventi tragici come stragi e uragani, e a lanciare teorie del complotto contro di lei, sostenendo di essere censurata.
  • Grok ha smesso di scrivere in inglese corretto buttando fuori parole in modo casuale.
  • ChatGPT ha iniziato a produrre poesie.
#501 /
16 maggio 2026
/
17:14
/ #ai

Raycast 2

La nuova architettura cross-platform di Raycast 2 è tecnicamente impressive. La UI diventa una web view ma è talmente polished che è sostanzialmente indistinguibile.

#497 /
15 maggio 2026
/
14:07




La nuova app Trenitalia sembra bella, ma crasha nella pagina più importante cioè "I miei viaggi", dove ci sono i biglietti.

#489 /
3 maggio 2026
/
21:53
/ #trenitalia

Apri il sito Trenitalia e il testo "CIRCOLAZIONE REGOLARE SULLA RETE ALTA VELOCITÀ" inizia a scorrere al contrario quindi non vedi mai il testo completo se non stai attento:

#488 /
3 maggio 2026
/
18:25
/ #trenitalia

La nuova vulnerabilità di Linux Copy Fail è stata scoperta con uno strumento di penetration testing che usa l'AI:

Theori said that it discovered the vulnerability after its researcher, Taeyang Lee, found surface area in the crypto subsystem (specifically, splice() hands page-cache pages and scatterlist page provenance) had been underexplored. Using its AI-powered Xint code security tool, the researchers then found the bug after about an hour of scan time. The company said it has also developed an exploit that uses CopyFail to break out of Kubernetes containers.

Dice un altro ricercatore:

Some have also raised concerns about us releasing the exploit publicly. We have experience writing N-day exploits and know that monitoring git commits for fixes is common practice in offensive security. Attackers were likely already aware and exploiting this within the a few days after the kernel fix landed. With AI coding tools today, turning a CVE plus commit into a working exploit happens in hours anyway.

Grande differenza rispetto al passato, si muove tutto più velocemente.

#487 /
2 maggio 2026
/
10:08
/ #ai#security

Non uso più Windows ma notevole il nuovo Win+R di Windows 11:

Faster than before: Perf was top-of-mind when rewriting Run, and with a 94ms median time-to-show time it’s faster than ever before (more on how we got there below)!

  • The existing dialog median time-to-show is 103ms
  • The browse button has very low usage. 0.0038% of users have clicked that button with a sample of 35 million.
  • Validated users do use the dialog to paste text from the clipboard, then copy it again without running anything to scrub text formatting.

#485 /
1 maggio 2026
/
20:50
/ #windows

Canonical (Ubuntu) sotto attacco DDoS con i servizi online che non funzionano da ieri proprio mentre la vulnerabilità Copy Fail è stata svelata ed è per ora unpatched. L'attacco è stato rivendicato da "Islamic Cyber Resistance in Iraq – 313 Team".

~ ❯ dig ubuntu.com
; <<>> DiG 9.20.22 <<>> ubuntu.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 5065
;; flags: qr rd ra; QUERY: 1, ANSWER: 3, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 512
;; QUESTION SECTION:
;ubuntu.com.			IN	A

;; ANSWER SECTION:
ubuntu.com.		38	IN	A	185.125.190.20
ubuntu.com.		38	IN	A	185.125.190.21
ubuntu.com.		38	IN	A	185.125.190.29

;; Query time: 9 msec
;; SERVER: 8.8.8.8#53(8.8.8.8) (UDP)
;; WHEN: Fri May 01 14:38:59 CEST 2026
;; MSG SIZE  rcvd: 87

~ ❯ curl -I https://ubuntu.com
curl: (56) Recv failure: Connection reset by peer

~ ❯ ipinfo 185.125.190.20
Core
- IP           185.125.190.20
- Anycast      false
- Hostname     website-content-cache-1.ps5.canonical.com
- City         London
- Region       England
- Country      United Kingdom (GB)
- Currency     GBP (£)
- Location     51.5085,-0.1257
- Organization AS41231 Canonical Group Limited
- Postal       E1W
- Timezone     Europe/London
#484 /
1 maggio 2026
/
14:29
/ #security

È iniziato il nuovo round di assegnazione delle nuove gTLD. L'ultimo era stato nel 2012. Le candidature costano 227mila dollari e resteranno aperte dal 30 aprile al 12 agosto. In autunno sapremo la lista.

#483 /
1 maggio 2026
/
10:10
/ #domini

Where the goblins came from

OpenAI spiega (via theverge) che ha dovuto inserire un'istruzione nel prompt di GPT-5.5 in Codex per impedire che nelle risposte comparissero troppo frequentemente riferimenti o battute sui goblin. La spiegazione è che un "tic di stile" della personalità "nerdy" è "uscito" e ha contaminato anche il modello in generale. Mi sembra però indicativo del fatto che non abbiamo ancora idea (e forse non ce l'avremo mai) di come e perché gli LLM funzionano, al di là di tentativi e correzioni continue.

The rewards were applied only in the Nerdy condition, but reinforcement learning does not guarantee that learned behaviors stay neatly scoped to the condition that produced them. Once a style tic is rewarded, later training can spread or reinforce it elsewhere, especially if those outputs are reused in supervised fine-tuning or preference data.

#481 /
30 aprile 2026
/
23:03
/ #ai#openai