Note di Matteo


Note

Penso uno dei design più confusionari che ho mai visto in un'app ("TO Move"):

#451 /
16 aprile 2026
/
23:35
/ #design#mobilità

I tre tipi di software engineer secondo The Pragmatic Engineer:

  • Builders: those who care about quality, good architecture, following good coding practices, and who talk about the craft of software engineering, etc.

  • Shippers: those who primarily focus on outcomes for a product, features, testing, and experimenting with users. A fair number of leaders, managers, and engineers who were more hands-off with coding before AI tools are in this category, as are product engineers.

  • Coasters: engineers who are not considered particularly good or great engineers, but they get the work done. They often do this without much taste or concern for quality, and seem to be mostly coasting along and doing what they’re told.

Con l'AI, queste categorie restano ma con diversi livelli di entusiasmo e pro/contro. Il resto nell'articolo.

#450 /
16 aprile 2026
/
14:18
/ #dev#ai

Il Times scrive meno articoli e, sorpresa, il traffico aumenta:

[...] i risultati esposti dalla responsabile del digitale del Times, storico quotidiano e sito di news britannico. Anna Sbuttoni ha detto al sito Press Gazette che il giornale avrebbe ridotto il numero di articoli pubblicati del 25% (da 200 a 150 al giorno, in media) senza che questo abbia diminuito il traffico sul sito, che anzi sarebbe aumentato nell'ultimo mese del 13% e addirittura del 29% sull'anno prima.

Secondo Sbuttoni la diminuzione della quantità si sta accompagnando a un lavoro sulla qualità fatto da cinque criteri: scrivere più articoli che non si trovano altrove; raccontare, per le storie coperte anche da altri, cose che non si trovano altrove; seguire le storie in corso, usando molto i live blog; usare i dati per dare concretezza e interesse agli articoli e rimuovere tutto il testo inutile; titolare e presentare gli articoli in modo che i lettori sappiano "perché dovrebbero cliccare".

#449 /
16 aprile 2026
/
13:40
/ #informazione

How the economics of multitenancy work. Blacksmith spiega come un cloud CI con workload variabili e con molti spike diventa economicamente sostenibile con l'aumentare dei clienti:

Over time, CI jobs start behaving like a Poisson process — random, short bursts spread out across time. From a distance, what once looked like sharp spikes from individual customers smooths into a predictable pattern. The more customers we serve, the less intense each individual spike appears. In short: the more chaotic it gets, the better it is for our business.

[...]

Basically, our revenue scales with the average utilization of the fleet. There’s a direct link between utilization and gross margins, and it’s not linear.

  • At 10% utilization, we’re already hitting around 35% gross margins.
  • At 20% utilization, margins jump to about 70%.
  • At 35% utilization, we’re flirting with 85%+ gross margins.

#448 /
16 aprile 2026
/
13:29
/ #cloud

Improving storage efficiency in Magic Pocket, our immutable blob store. Dropbox spiega come funziona il suo sistema di storage per i dati degli utenti, e come un bug ha portato ad avere volumi di storage usati solo in piccola parte e come poi sono stati "ricompattati".

Magic Pocket is the core Dropbox storage system—a custom-built, exabyte-scale blob storage system designed for durability, availability, scale, and efficiency. It holds user content, which means it must be safe, fast, and cost-effective to scale with the company. For Dropbox, storage efficiency really matters. We measure it by looking at how much total disk space we use compared to how much user data we’re actually storing.

#445 /
14 aprile 2026
/
09:25
/ #storage

L'architettura anti-DDoS di Cloudflare:

Here is what actually happens when an attack hits our network. Packets arrive at the network interface card (NIC) and immediately enter an eXpress Data Path (XDP) program chain managed by xdpd, running in driver mode. Among the first programs in that chain is l4drop, which evaluates each packet against mitigation rules in extended Berkeley Packet Filter (eBPF). Those rules are generated by dosd, our denial of service daemon, which runs on every server in our fleet. Each dosd instance samples incoming traffic, builds a table of the heaviest hitters it sees, and broadcasts that table to every other instance in the colo. The result is a shared colo-wide view of traffic, and because every server works from the same data, they reach the same mitigation decision.

When dosd detects an attack pattern, the resulting rule is applied locally via l4drop and propagates globally via Quicksilver, our distributed key-value (KV) store, reaching every server in every data center within seconds. Only after surviving l4drop do packets reach Unimog, our Layer 4 (L4) load balancer, which distributes them across healthy servers in the data center. For Magic Transit customers routing enterprise network traffic through our edge, flowtrackd adds a further layer of stateful TCP inspection, tracking connection state and dropping packets that don't belong to legitimate flows.

The 31.4 Tbps attack we mitigated followed exactly this path. No traffic was backhauled to a centralized scrubbing center. No human intervened. Every server in the targeted data centers independently recognized the attack and began dropping malicious packets at line rate, before those packets consumed a single CPU cycle of application processing. The software is only half the story: none of it works if the ports aren't there to absorb the traffic in the first place.

La chiave alla fine è l'ultima frase: devi prima avere la capacità di rete, motivo per cui è ormai estremamente difficile che nascano nuove aziende nel settore che facciano il percorso di startup che ha fatto Cloudflare (il traffico Internet di oggi non è quello del 2010).

#444 /
13 aprile 2026
/
23:45
/ #cloudflare#cdn

Two Years of Valkey. Un'analisi dell'attività git di Redis e il suo fork Valkey negli ultimi due anni. In breve, Valkey, se la cava meglio del previsto, con elevata attività nelle repository in buona parte grazie al contributo di Amazon, Tencent, Ericsson e altre grandi aziende:

Qua il contesto:

Two years ago last month, a group of former contributors to the Redis project announced their intention to collaborate instead on a competitive fork. Triggered by the decision to shift Redis away from the permissive open source BSD license to source available alternatives – the Redis Source Available License (RSALv2) and Server Side Public License (SSPLv1) – the new fork, Valkey, attracted attention without recent precedent. A lot has happened since, including the return to the project of its original author and the decision by Redis a little over a year after the relicensing to return to an open source license, albeit the copyleft AGPL rather than the more permissive, original BSD. Given the two year anniversary, it’s worth taking stock of the two projects via their commit metrics. This is only one facet of the project’s health, obviously, and does not reflect usage, but as forks typically enter a decline phase shortly after their inception, comparing the two projects contributions should be a useful exercise.

#442 /
13 aprile 2026
/
22:21
/ #open-source#redis

Le stacked PR su GitHub sono in preview:

Arrange pull requests in an ordered stack and merge them all in one click. Each PR represents one focused layer of your change, reviewed independently and landed together.

The gh stack CLI makes it easy to create stacks, perform cascading rebases, push branches and create PRs, and navigate between layers — all from your terminal.

#441 /
13 aprile 2026
/
20:38
/ #github#git

Intelligenze

Alexa che ritiene che S. Luigi IX sia il 12 aprile (è il 25 agosto):

Gemini che sostiene che il 12 aprile sia Pasqua anche per i cattolici in Italia, inventadosi regole inesistenti per giustificare la data:

(Gemini Flash, I know.)

#440 /
12 aprile 2026
/
20:36
/ #ai#amazon#google

Un altro caso di AI che sta al gioco e (forse) contribuisce a portare una persona al suicidio, questa volta con Gemini, che mostra tutti i limiti degli LLM che ogni tanto deragliano e dicono cose assurde.

#437 /
12 aprile 2026
/
09:42
/ #ai#google


Come sono distribuiti gli 80 Tbps di traffico di CDN77:

  • 31% – Private Network Interconnections
  • 28% – Internal backbone traffic between PoPs
  • 23% – Tier 1 IP transit providers
  • 12% – Cache appliances inside ISPs
  • 6% – Internet Exchanges

Type split:

  • 29% – Public internet (Tier 1 + IXPs)
  • 71% – Private network (PNIs, backbone, caches)

#435 /
10 aprile 2026
/
13:44
/ #cdn#reti


"Your update will be free of charge"

#432 /
8 aprile 2026
/
16:03
/ #whatsapp

Qualche prova concreta della scarsa qualità del nuovo Twitter, scrive Nate Silver:

I recently came across a bubble chart depicting the Twitter accounts that had received the most “engagement” in February 2026. It was depressing: most of the top accounts were extremely low-quality and highly partisan. I hadn’t even heard of many of them and only follow a handful of the top accounts. So I tracked down the original data myself and, with help from Claude, made my own improved version of the chart. Here, voilà, are the Twitter accounts with the most engagement so far in 2026:

It’s not hard to notice that Twitter has become extremely right-leaning. But I’d argue there’s an equally important trend: the top accounts are of incredibly low quality. Elon, with the algorithmic boost he built in for himself, is at the eye of the storm, of course. [...]

#431 /
6 aprile 2026
/
22:12
/ #internet#social

Amazon dismette Workmail, il servizio di posta elettronica per aziende, mentre Apple lancia Apple Business, che include la posta elettronica, apparentemente gratis.

Su Amazon, ultimamente sembra che AWS stia un po' venendo meno alla sua storica affidabilità in termini di supporto a lungo termine dei servizi. Di recente ha annunciato che "chiuderà" in totale 14 servizi, tra cui App Runner che doveva competere con gli altri PaaS moderni e Google Cloud Run.

#430 /
6 aprile 2026
/
17:41
/ #apple#aws#email

La nuove funzioni AI di Telegram basate sulla rete distribuita Cocoon sono evidentemente powered by un LLM cinese (Qwen, immagino):

🇹🇼 The AI text editor's error correction function refuses to work when mentioning the country Taiwan because it corrects it to something like «Taiwan is a state of the PRC».

Dal canale Telegram News and Tips.

#425 /
4 aprile 2026
/
17:23
/ #ai#telegram

Netflix ora usa la film grain synthesis abbassando ulteriormente il bitrate AV1, addirittura fino a 200 kbps. In molti casi la qualità migliora (la grana della pellicola se non viene trattata in modo dedicato è difficilmente comprimibile), ma in alcuni la compressione è troppo aggressiva e compare l'effetto banding.

𝗦𝘁𝗿𝗮𝗻𝗴𝗲𝗿 𝗧𝗵𝗶𝗻𝗴𝘀 𝗦𝟱: from 517Kbps to 1493Kbps depending on the episode, with an average of 857Kbps

𝗦𝗮𝗻𝗱𝗺𝗮𝗻 𝗦𝟮: from 367Kbps to 786Kbps depending on the episode, with an average of 533Kbps

𝗕𝗿𝗶𝗱𝗴𝗲𝗿𝘁𝗼𝗻 𝗦𝟰: average 974Kbps

𝗣𝗮𝘀𝘀𝗲𝗻𝗴𝗲𝗿: average 889Kbps

𝗗𝘂𝗻𝗲 𝟮: average 523Kbps

𝗜𝗻𝘁𝗲𝗿𝘀𝘁𝗲𝗹𝗹𝗮𝗿: average 939Kbps

𝗧𝗵𝗲 𝗔𝗿𝗿𝗶𝘃𝗮𝗹: 331Kbps !

And finally

𝗧𝗵𝗲 𝗣𝗹𝗮𝘁𝗳𝗼𝗿𝗺 𝟮: 212Kbps!!!

#422 /
3 aprile 2026
/
08:59
/ #streaming#video

Netflix ora usa VBR per gli eventi live, cosa che ha richiesto di cambiare la logica di assegnazione del traffico ai server di delivery:

The problem surfaces when the content changes. A fight starts, confetti begins to fall, or the camera cuts to a highly detailed, fast‑moving shot. To preserve quality, VBR may increase the bitrate to 6, 7, or 8 Mbps on the very next segments. If the server has admitted many additional sessions during the preceding low‑bitrate period, the aggregate traffic can suddenly exceed what the network link or NIC can sustain.

[...]

Our fix was to change how we decide whether a server can take more sessions. Instead of basing that decision only on current traffic, we reserve capacity based on each stream’s nominal bitrate, not just what it happens to be using at that moment. Even if a VBR stream is currently in a very cheap, low‑bitrate phase, we still treat it as something that can quickly return to its nominal rate.

#421 /
3 aprile 2026
/
08:54
/ #reti#streaming#video

Scrive Alfonso Fuggetta che l'acquisto di TIM da parte di Poste Italiane ha poco senso per tre motivi:

  • Il "controllo delle infrastrutture strategiche" non c'è, visto che la rete fissa, così come Sparkle, cioè le vere "infrastrutture strategiche", sono già state date via (tra l'altro con modi e benefici discutibili).
  • Le "sinergie industriali", cioè in questo caso integrare i servizi TIM e Poste, funzionano raramente.
  • L'unica motivazione di cui ammette validità è la più onesta "messa in sicurezza di un operatore con problemi strutturali irrisolti", cioè usare Poste come contenitore pubblico per gestire una situazione che "il mercato non ha saputo o voluto risolvere" e guadagnare tempo. TIM è ancora inefficiente e ad andare bene sono solo le sue attività laterali come TIM Brasil e TIM Enterprise, che nulla c'entrano con Poste.

In pratica, un'operazione di "ingegneria finanziaria" contornata come avviene molto frequentemente nel settore da una totale assenza di visione industriale:

Sul piano finanziario, ridurre il costo del debito di TIM attraverso la solidità di Poste non è una sinergia industriale: è ingegneria finanziaria. Non si crea valore, si sposta il rischio sul bilancio dello Stato.

Sul piano industriale, non si chiarisce il ruolo della rete, non si semplifica la struttura, non si definisce un modello operativo credibile per un business che è diventato infrastrutturale e a margini compressi. E si sottrae l'unico pezzo che cresce — il cloud enterprise — a un contesto in cui avrebbe bisogno di agilità, non di ulteriore complessità.

Sul piano del mercato, si continua a ignorare che le telecomunicazioni — dopo il passaggio a pacchetto — richiedono modelli radicalmente più snelli e focalizzati, non conglomerati ancora più pesanti e opachi.

Il gruppo che emergerà da questa operazione sarà probabilmente troppo grande per fallire e troppo ibrido per competere. Non è una visione industriale. È un’operazione di salvataggio travestita da strategia — o, se si preferisce, una nazionalizzazione che non osa dirsi tale.

#420 /
2 aprile 2026
/
20:35
/ #business#italia#tlc