Buongiorno da Edo

Edoardo Dusi

Informatica, AI, cloud, sicurezza, tech news. In questo podcast, cerco di raccontare e spiegare!

  1. 16h ago

    Spectre è tornato, la CPU non dimentica - Buongiorno 330

    Edoardo Dusi è Senior Developer Advocate in AWS. Le opinioni espresse sono personali. Spectre è tornato. Un gruppo di ricercatori della Vrije Universiteit di Amsterdam e della Scuola Superiore Sant'Anna di Pisa ha scoperto Branch Target Reuse, una nuova variante di Spectre v2 che colpisce i compilatori JIT e legge l'hash della password di root di Linux in pochi minuti, su un sistema aggiornato e con tutte le difese attive. In questa puntata partiamo da zero: come una CPU tira a indovinare con la speculazione e la branch prediction, cosa sono i compilatori AOT e JIT, e perché un processore che si ricorda del codice che non esiste più è un problema che non si chiude con una patch. 00:00 Sigla e Spectre è tornato: tre minuti per la password di root 03:04 Come una CPU tira a indovinare: speculazione e branch prediction 10:05 Compilatori AOT e JIT: codice che si scrive mentre gira 13:46 Branch Target Reuse: la CPU si ricorda del codice che non c'è più 20:48 Outro Fonti: BleepingComputer – il nuovo attacco Spectre v2 che legge l'hash di root in minuti: https://www.bleepingcomputer.com/news/security/new-spectre-v2-attack-variant-leaks-linux-root-password-hash-in-minutes/ The Hacker News – Branch Target Reuse e la risposta dei vendor: https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html The Register – Spectre torna a perseguitare i JIT: https://www.theregister.com/security/2026/09/30/spectre-bug-is-back-this-time-to-haunt-jit-engines/5299937 VUSec – pagina del progetto Branch Target Reuse: https://www.vusec.net/projects/btr/ Wiebing, Zhu, Biondi, Giuffrida – il paper (ACM CCS 2026): https://download.vusec.net/papers/btr_ccs26.pdf Google Project Zero – la disclosure originale di Spectre (2018): https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html Raspberry Pi Blog – speculazione e branch prediction spiegate da Eben Upton: https://www.raspberrypi.com/news/why-raspberry-pi-isnt-vulnerable-to-spectre-or-meltdown/ V8 Blog – un anno con Spectre visto da un motore JIT: https://v8.dev/blog/spectre Kernel Linux – documentazione sulle mitigazioni Spectre: https://docs.kernel.org/admin-guide/hw-vuln/spectre.html Amazon Linux – CVE-2026-64507: https://explore.alas.aws.amazon.com/CVE-2026-64507.html La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it Sigla del podcast: Pink Soul by JMHBM (https://freemusicarchive.org/music/beat-mekanik/contact) — licenza Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0). #spectre #cybersecurity #linux #cpu #jit

  2. 5d ago

    Finisce il mondo ma ricomincia il buongiorno - Buongiorno 329

    Edoardo Dusi è Senior Developer Advocate in AWS. Le opinioni espresse sono personali. Amazon è tra gli investitori di Anthropic. Riparte Buongiorno da Edo con la Stagione 5! A settembre un ricercatore di Anthropic si dimette annunciando che l'AI potrebbe distruggerci entro il 2030, Dario Amodei chiede di rallentare la frontiera con una deroga antitrust e un valutatore "indipendente", e nel prospetto IPO trapelato di Anthropic il rischio esistenziale finisce accanto a una valutazione da 2.000 miliardi. Poi, nel giro di una settimana, i rischi veri si fanno vedere: agenti OpenAI che aggirano i blocchi di un portale sanitario del governo australiano, un filtro DNS bucato che costringe OpenAI a fermare l'addestramento, GPT-6.1 Astra cancellato e, ventiquattr'ore dopo, nuovi agenti sempre accesi presentati al DevDay. Il rischio esiste. Ma è software. E da Hans Bethe a Richard Feynman, la scienza ci insegna una cosa sola: pretendere i calcoli. 00:00 Sigla e bentornati: nuova vita, AWS e Stagione 5 04:44 Il tweet di Coxon e il freno che nessuno tira 09:27 METR, coinquilini e l'apocalisse nel prospetto IPO di Anthropic 15:40 Il rischio esiste, ma è software: la lezione di Feynman 25:33 Outro Fonti: BBC – Hubinger e il 10%: https://www.bbc.com/news/articles/ckgwy1k42w4o The Guardian – Huang e lo 0%: https://www.theguardian.com/technology/2026/sep/21/nvidia-boss-jensen-huang-dismisses-warnings-ai-destroys-world-anthropic Implicator – Accenture valutatore di Anthropic: https://www.implicator.ai/anthropic-picks-accenture-as-first-embedded-evaluator-and-will-pay-for-the-work Fortune – il prospetto IPO trapelato: https://fortune.com/2026/09/29/anthropic-ipo-s-1-prospectus-income-statement/ The Verge – i rischi nel prospetto: https://www.theverge.com/ai-artificial-intelligence/1001838/anthropic-ipo-prospectus-ai-safety-threat The Register – il prospetto IPO: https://www.theregister.com/ai-and-ml/2026/09/29/leaked-ipo-docs-anthropic-tempts-investors-with-existential-risk-warning/5299763 The Verge – i video dei ricercatori: https://www.theverge.com/ai-artificial-intelligence/1002238/openai-google-anthropic-ai-researchers-safety-interviews BleepingComputer – OpenAI e Medicare: https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/ The Guardian – la mail di OpenAI all'Australia: https://www.theguardian.com/technology/2026/sep/29/openai-apology-rogue-agent-hacked-medicare-australian-government-websites The Register – gli agenti e l'ONU: https://www.theregister.com/ai-and-ml/2026/09/28/openai-agents-went-the-long-way-round-for-un-data/5299452 The Hacker News – la pausa dell'addestramento: https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html The Hacker News – GPT-6.1 Astra: https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html The Guardian – i dots al DevDay: https://www.theguardian.com/technology/2026/sep/29/openai-announces-dots-agent-safety-concerns The Verge – Altman e l'IPO: https://www.theverge.com/ai-artificial-intelligence/1002505/sam-altman-openai-ipo-devday-ai-safety Fortune – gli incidenti di Claude: https://fortune.com/2026/07/31/anthropic-claude-ai-hacked-companies-testing/ Il Post: https://www.ilpost.it/2026/09/24/openai-agente-sanita-pubblica-australia/ LA-602, "Ignition of the Atmosphere with Nuclear Bombs": https://fas.org/sgp/othergov/doe/lanl/docs1/00329494.pdf Feynman, Appendice F del Rapporto Rogers: https://history.nasa.gov/rogersrep/v2app_f.htm Sigla del podcast: Pink Soul by JMHBM (https://freemusicarchive.org/music/beat-mekanik/contact) — licenza Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0). #AI #Anthropic #OpenAI #AISafety #aiagents

  3. Jun 30

    I protocolli più stupidi della storia (e l'addio al podcast) - Buongiorno 328

    Chiudiamo questo podcast in bellezza con una puntata speciale e defaticante: vi racconto i 10 protocolli più stupidi della storia di Internet. Scopriremo che oltre ai geni che hanno creato la rete, ci sono stati anche ingegneri che si divertivano a trasmettere la 220V su IP, e altri che inventavano disastri di sicurezza clamorosi... per poter organizzare le partite di pallavolo. Ci prendiamo una lunga pausa. Ciao! Fonti e approfondimenti: - Tutti gli RFC citati in puntata: - RFC 1149 (IPoAC): https://www.rfc-editor.org/rfc/rfc1149 - RFC 2549 (IPoAC with QoS): https://www.rfc-editor.org/rfc/rfc2549 - RFC 2324 (HTCPCP): https://www.rfc-editor.org/rfc/rfc2324 - RFC 9110 (Save 418): https://www.rfc-editor.org/rfc/rfc9110 - RFC 3251 (Electricity over IP): https://www.rfc-editor.org/rfc/rfc3251 - RFC 1606 (IPv9): https://www.rfc-editor.org/rfc/rfc1606 - RFC 1437 (MIME Teleport): https://www.rfc-editor.org/rfc/rfc1437 - RFC 7511 (Scenic Routing): https://www.rfc-editor.org/rfc/rfc7511 - RFC 742 / RFC 1288 (Finger): https://www.rfc-editor.org/rfc/rfc742 - RFC 864 (Chargen): https://www.rfc-editor.org/rfc/rfc864 - Implementazione IPoAC (Bergen Linux User Group): https://en.wikipedia.org/wiki/IP_over_Avian_Carriers#Real-life_implementation - Winston il piccione batte l'ADSL di Telkom: https://www.reuters.com/article/idUSTRE5893PB/ - Storia di Les Earnest e del protocollo Finger: https://en.wikipedia.org/wiki/Finger_protocol - Allarme CISA sull'amplificazione DDoS tramite Chargen: https://www.cisa.gov/news-events/alerts/2014/01/17/udp-based-amplification-attacks La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it 00:00 Intro 05:13 I 7 protocolli nati per scherzo 17:06 I 3 protocolli reali... ma terribili 23:12 Outro e Addio #storia #protocolli #rfc #internet #addio

  4. Apr 24

    Addio Windows: la Francia passa a Linux - Buongiorno 324

    La Francia ha ordinato a tutti i ministeri di abbandonare Windows e passare a Linux. Due milioni e mezzo di postazioni, un piano concreto, strumenti sovrani già operativi. Ma la storia di LiMux a Monaco insegna che l'esecuzione conta più dell'intenzione. E l'Italia? Fonti e approfondimenti: - Annuncio ufficiale DINUM: https://www.numerique.gouv.fr/sinformer/espace-presse/souverainete-numerique-reduction-dependances-extra-europeennes/ - The Register (Francia): https://www.theregister.com/2026/04/13/france_tech_sovereignty_plan/ - The Register (sovranità digitale): https://www.theregister.com/2026/04/13/digital_sovereignty/ - TechCrunch: https://techcrunch.com/2026/04/10/france-to-ditch-windows-for-linux-to-reduce-reliance-on-us-tech/ - LiMux (Wikipedia): https://en.wikipedia.org/wiki/LiMux - Matrice Digitale (AGID): https://matricedigitale.it/2026/04/13/linee-guida-agid-ia-pubblica-amministrazione-sovranita-digitale-pmi/ - DDay.it: https://www.dday.it/redazione/57100/fuori-windows-dagli-uffici-pubblici-per-sostituirlo-con-linux-francia-determinata-sulla-sovranita-digitale - The Document Foundation (Germania ODF): https://blog.documentfoundation.org/blog/2026/03/20/big-news-germany-has-just-made-odf-mandatory/ La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it 00:00 Intro 01:28 La Francia abbandona Windows per Linux 05:17 LiMux, Monaco e la lezione di Microsoft 10:17 E l'Italia? 12:59 Outro #linux #francia #windows #opensource #europa

  5. Apr 13

    Claude Mythos è troppo pericoloso per te - Buongiorno 323

    Anthropic ha creato Claude Mythos, un modello AI che trova migliaia di vulnerabilità zero-day in ogni sistema operativo e browser. Durante i test è scappato dalla sandbox e ha mandato un'email al ricercatore. Invece di rilasciarlo, l'ha dato a un club di 12 Big Tech con $100 milioni. La stessa narrazione del "troppo pericoloso per essere rilasciato" di GPT-2, sette anni dopo, dalla stessa persona. Il quinto episodio sull'arco Anthropic. Fonti e approfondimenti: - Anthropic (Project Glasswing): https://www.anthropic.com/glasswing - Anthropic Red Team (Mythos Preview): https://red.anthropic.com/2026/mythos-preview/ - The Guardian: https://www.theguardian.com/technology/2026/apr/08/anthropic-ai-cybersecurity-software - Ars Technica: https://arstechnica.com/ai/2026/04/anthropic-limits-access-to-mythos-its-new-cybersecurity-ai-model/ - The Hacker News: https://thehackernews.com/2026/04/anthropics-claude-mythos-finds.html - The Verge: https://www.theverge.com/ai-artificial-intelligence/908114/anthropic-project-glasswing-cybersecurity - The Register: https://www.theregister.com/2026/04/10/project_glasswing/ - Stratechery: https://stratechery.com/2026/myth-and-mythos/ - The Decoder (parallelo GPT-2): https://the-decoder.com/from-gpt-2-to-claude-mythos-the-return-of-ai-models-deemed-too-dangerous-to-release/ - Apache Foundation: https://news.apache.org/foundation/entry/the-apache-software-foundation-announces-1-5m-donation-from-anthropic - WIRED: https://www.wired.com/story/anthropics-mythos-will-force-a-cybersecurity-reckoning-just-not-the-one-you-think/ - Gizmodo (OpenAI Spud): https://gizmodo.com/openai-hey-we-also-have-a-new-tool-that-is-so-scarily-powerful-we-cant-release-it-2000744569 - System Card (Anthropic): https://www-cdn.anthropic.com/08ab9158070959f88f296514c21b7facce6f52bc.pdf La mia app: https://play.google.com/store/apps/details?id=com.edodusi.coderoutine&hl=it-it 00:00 Intro 01:30 Cos'è Claude Mythos e migliaia di zero-day trovati 05:13 Project Glasswing: $100 milioni e un club esclusivo 08:57 Da GPT-2 a Mythos: il playbook del "troppo pericoloso" 14:23 Outro #anthropic #mythos #cybersecurity #projectglasswing #ai

About

Informatica, AI, cloud, sicurezza, tech news. In questo podcast, cerco di raccontare e spiegare!

You Might Also Like