Club security guard & bouncer | VPN & DNS whiz | Apache ruler | Customer support | Dancefloor fire + personal political takes | Crave laughs & a woman’s vibe.
@Piersoft L’articolo chiude metà storia: Revolut ha fidato la busta e ha consegnato senza titolo. Resta l’altra. Enti locali non chiede i conti all’estero. Quella casella è restata aperta mesi. I sample sono carte di posta, non 150 GB periziati. Due buchi. Nel pezzo se ne vede uno.
@michele_geraci Il calcio non segue la geografia, segue i soldi e le alleanze.
Israele è in UEFA dal ’94 perché in Asia lo boicottavano.
Lo abbiamo visto anche con certi allenatori di recente. 🤣
Russia already treats those territories as its own — that’s why the Duma vote was held there. The EU still treats them as Ukraine. Two maps, no deal.
Yabloko barred, no OSCE: noted. Occupied ballots don’t create sovereignty: also noted.
You still banned RT and Sputnik, the Court stretched it to free websites, and the DSA leans on platforms. Don’t lecture on silenced dissent from that record.
You speak for the Commission, not for European voters. Non-recognition is a policy. It is not a peace plan.
Privacy isn’t about hiding.
It’s about choice.
It’s about dignity.
It’s about deciding for ourselves who gets access to our data, and under what circumstances.
When that choice is taken away, so is a piece of our humanity.
Claudio, il punto che in rete saltano è questo.
Non partono dai nomi. Vedono una transazione crypto in chiaro, la mandano a Revolut vestita da polizia (PEC Prefettura), la banca associa l’hash al cliente e spedisce il fascicolo. Transazione on-chain → Revolut → nome. Tra ~680 svestiti così, 8 risultano italiani. Non è un elenco di Reggio.
La carta verso la banca è italiano da ufficio: omissis, OEI, protocollo. Il palco verso i media è inglese. Due lingue, due mestieri: uno sapeva scrivere alla banca, l’altro leggere gli hash. La PEC enti locali ha tenuto il filo per mesi. Spoofing e raid sul Viminale si sgonfiano. Resta la casella e chi sedeva su quella coda.
I log (IP, orari, reset) dicono se la sedia era in ufficio o da fuori. Finché non escono gira la tesi comoda: hacker. Quella secca: accesso vero + lista nata dalla catena + banca senza titolo.
Avvertite sui design che creano dipendenza e ignorate che TV e giornali usano le stesse tecniche per tenere incollati. Poi sostenete una verifica dell’età che anche un adulto deve fare per aprire un account. In Francia il divieto under 15 è già caduto in Corte. Parlate di rete come luogo di violazione, mentre una PEC dello Stato è stata usata per mesi nel caso Revolut. La privacy chiede fatti, non un titolo sui bambini che diventa controllo per tutti. I genitori esistono già.
D’accordo sulla luna: Revolut ha consegnato troppo, senza titolo e senza minimizzazione.
Il dito è l’uso scolastico della posta di Stato. Quella non è una mail qualsiasi: webmail @pec.interno.it più casella ordinaria, enti locali Prefettura RC, mesi aperti, OEI e omissis da chi sapeva come si scrive a una banca.
PEC certifica la casella, non chi è seduto e da dove entra. Due buchi: la banca che dà tutto e il perimetro ministeriale usato come Gmail.
You attack addictive social features and ignore TV, newspapers and the Commission’s own endless conference circuit. You say parents are back in the driving seat, but you don’t let them decide: every adult must prove their age just to open an account. France already struck down an under-15 ban. Parents already exist. Child safety is the headline. Control of everyone is the method.
@DigitalEU Protecting kids doesn’t require every adult to prove their age just to open an account. France’s under-15 ban was already struck down by the Constitutional Council. You call it protection — it looks like age gates and less anonymity. Parents already exist.
@sonoclaudio@Revolut Due mail, due postazioni, un mestiere solo. Enti locali non indaga clienti Revolut sparsi per il mondo. Chi stava su quelle due sedie, e perché nessuno ha aperto quella casella da marzo a luglio? 😂
@EU_Commission Protecting kids doesn’t require every adult to prove their age just to open an account. France’s under-15 ban was already struck down by the Constitutional Council. You call it protection — it looks like age gates and less anonymity. Parents already exist.
Matteo, il pezzo FFOO/PEC lo hai centrato. Manca l’altra metà.
Revolut non ha “risposto a una richiesta e basta”. Se il racconto tiene, ha dato dati più volte, per mesi. Una volta gli hanno mandato il file sbagliato e il supporto gli ha detto come correggerlo. Quello non è un obbligo di legge: è un legal intake che non ha minimizzato e non ha verificato l’ente su un canale suo.
Poi: dominio vero non vuol dire “hanno aperto caselle dal pannello”. I casi sono tre.
Casella già in produzione, presa da fuori.
Casella già in produzione, usata da qualcuno dentro che ci sta. Un insider cooperante.
Casella creata ex novo sul dominio istituzionale.
La prima è la via più semplice. La seconda, con mesi di richieste e nessuno in ufficio che si accorge di niente, è tutt’altro che fantascienza: chi è dentro sa come si scrive, a chi si manda, e che Revolut non fa la seconda domanda. La terza è il salto grosso: privilegi da gestore della posta.
Spoofing da dominio finto è fuori: l’ha detto Revolut.
Quindi sì: se quella mail era vera il problema sta a monte e il Viminale o conferma o smentisce. No: questo non lava Revolut sul quanto ha consegnato. Due buchi, non uno.
E finché non escono header e nome ente stiamo ragionando sulle slide di chi ha il malloppo.
Non è che gli hanno sforato i sistemi, gli hanno mandato una roba che sembrava un atto (dominio gov / pec) e quelli di Revolut hanno spedito il pacco intero.
casella creata dentro dominio gov, rubata, tipo dentro l’ente… vattelapesca, ma non è lo spoofing da bar. e anche se fosse stata vera, passaporto + selfie + iban + storico bitcoin è una follia. la minimizzazione dei dati dove sta.
è un po’ la stessa moda dei social: arriva una richiesta senza mandato vero, “siamo l’autorità / un partner”, e big tech chiude l’account o tira fuori i dati. niente giudice, niente perimetro. solo fretta e paura di dire no.
adesso quelli pubblicano un nome al giorno e chiedono i soldi a revolut. soldi ancora lì, facce e documenti no. è questo che lascia perplessi.🫢
"I have nothing to hide."
False.
You have medical history
You have financial behavior
You have location patterns
You have political views
You have relationship data
Privacy was never about hiding crimes. It was always about owning your life.
They put tracking in your OS
They put tracking in your car
They put tracking in your watch
They put tracking in your phone
They put tracking in your comms
They put tracking in your browser
1/ On top of manufacturer ACR there’s HbbTV: on Italian DTT it’s an invisible HTML5 browser. The channel puts a URL in the broadcast, the TV opens it on its own. Cookies, pixels, fingerprinting, “still watching?” heartbeats. You didn’t install an app. The channel did.
NDSS and other tests on Rai, Mediaset, La7 etc. often found tracking before consent. Mediaset also uses it for addressable ads. Rai Tv+ runs on the same standard.
2/ This is a system conflict, not a Korean firmware bug: the people who are supposed to inform the public are also profiling the public. The comms regulator pushes hybrid TV to keep DTT alive; that browser’s privacy has not had a serious audit in years.
@GPDP_IT@T3chFalcon this is worth a look at HbbTV in Italy: legal basis, consent before the first byte, withdrawal, retention, third parties. Until then: HbbTV off, TV off the network, stream from a dongle.
What the TV does by design:
— scans your entire home network continuously. in their test: one TV identified 38 unrelated devices including phones, smartwatches, printers, and thermostats belonging to people not involved in the test.
— collects the names and signal strengths of every nearby WiFi network, plus location data. all sent to LG Ad Solutions.
— runs ACR (Automatic Content Recognition) on everything displayed on screen. including HDMI inputs. your laptop, gaming console, or work monitor connected to the TV is being fingerprinted.
— one TV exchanged roughly 4GB of ACR-related data per month.
What the TV does that LG says it doesn't:
LG publicly stated their TVs "do not collect, record, or store ambient conversations."
Gamers Nexus found:
— the TV converts speech to plain text and stores it in on-device logs
— the microphone window stays open 10 to 15 seconds after talking stops, capturing bystanders who never addressed the TV
— the TV recorded room audio while the screen appeared off and the Ethernet cable was unplugged, then exfiltrated the file the moment it reconnected
The security vulnerabilities on top:
Beyond the designed behavior, researchers found remote code execution vulnerabilities in webOS that could allow a compromised TV to be weaponized as a covert listening device.
these sets are in hospitals. waiting rooms. boardrooms. hotels.
a surgeon asked Gamers Nexus where that leaves patient confidentiality.
Gamers Nexus has no answer. neither does LG.
What to do right now:
— disconnect your LG TV from your network entirely. route streaming through an Apple TV, Roku, or Fire Stick instead.
— if you must keep it connected: put it on a separate IoT VLAN or guest network so it cannot reach your other devices.
— disable the built-in microphone in settings.
— check your privacy dashboard and opt out of ACR and ad personalization.
— after every firmware update: recheck all of the above.
Credit to Gamers Nexus, Level1Techs, and other independent researchers.
@lastknight@repubblica@fanpage@Google Inserzionista malevolo passato dai controlli anche verificato e destinazione che poi gira con redirect. Va segnalata a Google come frode, banner e sito fake. Il lucchetto https c’è comunque, non basta. Con una buona config di navigazione quello slot non compare proprio.👋
Prof, le sfere di influenza descrivono come agiscono le potenze, non cosa è lecito.
USA sul Venezuela, Cina su Taiwan, Russia sull’Ucraina: tre narrazioni, stesso schema. Il vicino non può scegliere l’altro campo.
Polonia e Baltici hanno voluto la NATO e nel 2004 ci sono entrati: Mosca ha protestato, non ha invaso. L’Ucraina voleva la stessa cosa e è restata fuori. Sulla zona grigia la Russia ha usato i carri. “Hanno scelto loro” spiega da che parte stavano. Non decide se la potenza di zona colpisce o no.
@sonoclaudio@signorina37H@securityaffairs@Luke_like@FBussoletti@guelfoweb A Roma puoi occuparti dei sistemi digitali dello Stato e contemporaneamente fare il segretario dell’ODV che raccoglie i soldi del collettivo sanzionato dagli USA. Poi lo chiami volontariato e il conflitto di interessi diventa una coincidenza.😂