nexa
By thread
nexa@server-nexa.polito.it
By month
Messages by month
- ----- 2026 -----
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2025 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2024 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2023 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2022 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2021 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2020 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2019 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2018 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2017 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2016 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2015 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2014 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2013 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2012 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2011 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2010 -----
- December
- November
- October
- September
- August
- July
- June
- May
- April
- March
- February
- January
- ----- 2009 -----
- December
- November
- October
- September
- August
- July
- June
- May
March 2020
- 68 participants
- 304 messages
Qualche volontario?
by Stefano Quintarelli
Buongiorno a tutti,
Come sapete il ministero dell'istruzione sta coordinando dei contributi da
parte di privati per consentire alle scuole di proseguire la didattica on-line.
accanto alla fornitura di servizi e tecnologie da parte delle scuole ci
sarà una community (peer to peer) di supporto per i docenti.
ad assistere questa community docenti ci saranno dei volontari.
Uno dei temi cui i docenti sono interessati è la privacy .
se qualcuno fosse disponibile a dare una mano rispondendo in un forum a
domande dei docenti in merito agli aspetti di privacy della didattica
on-line , è pregato di segnalarmelo.
grazie per ogni contributo.
Ciao, s.
March 2, 2020
128° Mercoledì di Nexa | 11 Marzo 2020
by Nexa Media
Nexa Center for Internet and Society Newsletter
Se non visualizzi correttamente questo messaggio clicca qui
<https://nexa.polito.it/mercoledi-128>
NEXA
128° Mercoledì di Nexa
Mercoledì 11 marzo 2020, ore 18.00 - 20.00
Politecnico di Torino
http://nexa.polito.it/mercoledi-128 <https://nexa.polito.it/mercoledi-128>
Volti artificiali
Speaker
Prof. Massimo Leone (Università degli Studi di Torino)
This event will be webcast live: https://nexa.polito.it/nexa-hangout-on-air
Dal punto di vista semiotico, un *volto puramente artificiale* non può
sussistere. Ogni artefatto riconoscibile come volto, infatti, deve
dipendere direttamente o indirettamente da *volti biologicamente
esistenti*. Sin dalle *raffigurazioni preistoriche*, gli esseri umani
utilizzano tecniche e tecnologie svariate per *rappresentare volti
biologicamente esistenti*, ma anche per *evocarne d’inesistenti*. Questi
ultimi tuttavia devono necessariamente scaturire da una *scomposizione*
e da una *ricomposizione combinatoria* dei primi. Analogamente,
l’emergere di *volti “nella natura”*, attestata sin dall’antichità, si è
rivelato essere il risultato pareidolico di *meccanismi neurofisiologici
e percettivi profondi*, legati all’evoluzione della specie umana e della
sua capacità di riconoscere volti.
Lo sviluppo della tecnica e della tecnologia non ha affatto eliminato
l’*intenzionalità umana* nella rappresentazione e nella lettura del
volto ma ne ha spostato e occultato la fonte. Da un lato, con lo
sviluppo delle *reti neurali antagoniste*, scaturisce il mito di
macchine capaci di generare automaticamente e senza intervenzione umana
immagini di volti; dall’altro, con lo sviluppo delle *reti neurali
convoluzionali*, si diffonde la retorica di macchine in grado di
scorgere e identificare volti senza l’ausilio di operatori umani.
L’intervento si prefigge di analizzare queste concezioni
dell’*intelligenza artificiale* soffermandosi su due casi di studio che
riguardano le *immagini facciali*. Da un lato, un *caso di studio
estetico* riguardante la *raffigurazione di volti*: la retorica digitale
relativa agli *algoritmi di “abbellimento” facciale* (in particolare,
l’applicazione cinese per smartphone “Meitu”); dall’altro lato, un *caso
di studio giuridico* riguardante la *lettura di volti*: il dibattito
legale sul carattere testimoniale del *riconoscimento facciale automatico*.
BIOGRAFIE - e informazioni supplementari
[mercoledì128]
*Massimo LEONE* è Professore Ordinario di Filosofia della Comunicazione,
Semiotica della Cultura e Semiotica dell’Immagine presso il Dipartimento
di Filosofia e Scienze dell’Educazione dell’Università di Torino,
Vice-Direttore per la Ricerca presso lo stesso Dipartimento, e
Professore Ordinario a tempo parziale di Semiotica presso il
Dipartimento di Lingua e Letteratura Cinese dell’Università di Shanghai.
È PI del progetto ERC Consolidator FACETS (2019-2024): “Face Aesthetics
in Contemporary E-Technological Societies”.
*Letture consigliate e link utili:*
* Celentino, Joseph Clarke. 2016. “Face-to-Face With Facial
Recognition Evidence: Admissibility Under the Post-Crawford
Confrontation Clause”, 1317-53. /Michigan Law Review/, 114, 7.
* Greti, Iulia Ivana. 2016. “Face and the Dynamics of Its
Construction: A Relational and Multilayered Perspective”, 106-125.
/Symbolic Interaction/, 39, 1 (February 2016).
* Leone, Massimo. 2019. “The Semiotics of the Face in Digital Dating:
A Research Direction”, 18-40. /Digital Age in Semiotics and
Communication/, special issue on “Digital Sex and Dating”, 2.
South-East European Center for Semiotic Studies (Sofia: New
Bulgarian University); DOI:
http://ojs.nbu.bg/ojs/index.php/DASC/article/view/247.
* Leone, Massimo. 2020. “Digital Cosmetics: A Semiotic Study on the
Chinese and Global Meaning of the Face in Image Processing Apps”,
forthcoming. /Social Semiotics/; draft available at this link
<https://www.academia.edu/41978669/2020_-_Digital_Cosmetics_A_Semiotic_Study…>.
* Nawara, John. 2011. “Note, Machine Learning: Face Recognition
Technology Evidence in Criminal Trials”, 604-607. /U. Louisville L.
Rev./ 49.
Che cosa sono il Centro Nexa e i cicli di incontri “Mercoledì di Nexa” e
“Nexa Lunch Seminar”
<https://www.facebook.com/nexa.center/> <https://twitter.com/nexacenter>
<https://www.youtube.com/user/NexaCenter>
#nexawednesday <https://twitter.com/search?q=%23nexawednesday&src=typd>
Il Centro Nexa su Internet & Società del Politecnico di Torino
(Dipartimento di Automatica e Informatica) dal 2006 è un centro di
ricerca indipendente e interdisciplinare che, in collaborazione con
l'Università di Torino, studia Internet (e più in generale le Tecnologie
digitali) e i suoi rapporti con la società. Maggiori informazioni
all'indirizzo: http://nexa.polito.it/about.
Durante i “*Mercoledì di Nexa*”, che si tengono *ogni 2° mercoledì del
mese* alle *ore 18 in punto*, il Centro Nexa su Internet e Società apre
le sue porte non solo agli esperti e a tutti coloro i quali lavorano con
Internet, ma anche a semplici appassionati e cittadini. Il ciclo di
incontri intende approfondire, con un linguaggio preciso ma accessibile,
i temi legati alla Rete: motori di ricerca, Creative Commons, social
networks, open source/software libero, neutralità della rete, libertà di
espressione, privacy, file sharing, big e open data, smart cities e
molto altro.
Al centro di quasi tutti gli incontri un ospite pronto a dialogare con i
direttori del Centro Nexa, il Prof. Juan Carlos De Martin del
Politecnico di Torino e il Prof. Marco Ricolfi dell'Università di
Torino, nonché lo staff e i Fellows del Centro Nexa.
Maggiori informazioni sui Mercoledì di Nexa, incluso un elenco di tutti
i “Mercoledì” passati, sono disponibili all'indirizzo:
http://nexa.polito.it/mercoledi.
Si segnala inoltre che dal maggio 2012 *ogni 4° mercoledì* del mese
*dalle ore 13 alle ore 14* il Centro Nexa organizza anche i "*Nexa Lunch
Seminar*". Una lista di tutti i “Lunch Seminar” passati è disponibile
all'indirizzo: http://nexa.polito.it/lunch-seminars.
See our events calendar <http://nexa.polito.it/events> if you're curious
about future luncheons, discussions, lectures, and conferences not
listed in this email. Our events are free and open to the public, unless
otherwise noted.
Responsabile Comunicazione Centro Nexa su Internet & Società: *Anita
Botta*, tel: +39 011 090 7219, Mob: +39 347 131 3903,
anita.botta(a)polito.it <mailto:anita.botta@polito.it>.
Maggiori informazioni sui Mercoledì di Nexa e i Nexa Lunch Seminar, sono
disponibili all'indirizzo: http://nexa.polito.it/events. Weekly Events
Newsletter. Sign up <http://nexa.polito.it/mailing-lists> to receive
this newsletter if this email was forwarded to you. To manage your
subscription preferences, please click here
<https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa>.
Connect & get involved: Jobs, internships, and more
<http://nexa.polito.it/get-involved>.
March 2, 2020
Why the Success of The New York Times May Be Bad News for Journalism - The New York Times
by J.C. DE MARTIN
Why the Success of The New York Times May Be Bad News for Journalism
In his debut, our new media columnist says The Times has become like Facebook or Google — a digital behemoth crowding out the competition.
https://www.nytimes.com/2020/03/01/business/media/ben-smith-journalism-news…
(Sent from my wireless device; please excuse brevity and typos (if any))
March 2, 2020
Re: [nexa] We found 6 critical PayPal vulnerabilities – and PayPal punished us for it
by Giacomo Tesio
Scusate ho dimenticato il link.
Eccolo:
https://cybernews.com/security/we-found-6-critical-paypal-vulnerabilities-a…
Giacomo
On Friday, 28 February 2020, Davide Carboni <dcarboni(a)gmail.com> wrote:
> Qual è la fonte di questo interessante articolo?
> On Wed, 26 Feb 2020, 3:49 pm Giacomo Tesio, <giacomo(a)tesio.it> wrote:
>>
>> When our analysts discovered six vulnerabilities in PayPal – ranging
>> from dangerous exploits that can allow anyone to bypass their
>> two-factor authentication (2FA), to being able to send malicious code
>> through their SmartChat system – we were met with non-stop delays,
>> unresponsive staff, and lack of appreciation. Below, we go over each
>> vulnerability in detail and why we believe they’re so dangerous.
>>
>> When we pushed the HackerOne staff for clarification on these issues,
>> they removed points from our Reputation scores, relegating our
>> profiles to a suspicious, spammy level. This happened even when the
>> issue was eventually patched, although we received no bounty, credit,
>> or even a thanks. Instead, we got our Reputation scores (which start
>> out at 100) negatively impacted, leaving us worse off than if we’d
>> reported nothing at all.
>> [...]
>>
>> # PayPal’s reputation for dishonesty
>>
>> PayPal has been on the receiving end of criticism for not honoring its
>> own bug bounty program.
>>
>> Most ethical hackers will remember the 2013 case of Robert Kugler, the
>> 17-year old German student who was shafted out of a huge bounty after
>> he discovered a critical bug on PayPal’s site. Kugler notified PayPal
>> of the vulnerability on May 19, but apparently PayPal told him that
>> because he was under 18, he was ineligible for the Bug Bounty Program.
>>
>> But according to PayPal, the bug had already been discovered by
>> someone else, but they also admitted that the young hacker was just
>> too young.
>>
>> Another researcher earlier discovered that attempting to communicate
>> serious vulnerabilities in PayPal’s software led to long delays. At
>> the end, and frustrated, the researcher promises to never waste his
>> time with PayPal again.
>>
>> There’s also the case of another teenager, Joshua Rogers, also 17 at
>> the time, who said that he was able to easily bypass PayPal’s 2FA. He
>> went on to state, however, that PayPal didn’t respond after multiple
>> attempts at communicating the issue with them.
>>
>> PayPal acknowledged and downplayed the vulnerability, later patching
>> it, without offering any thanks to Rogers.
>>
>>
>> # The big problem with HackerOne
>>
>> HackerOne is often hailed as a godsend for ethical hackers, allowing
>> companies to get novel ways to patch up their tools, and allowing
>> hackers to get paid for finding those vulnerabilities.
>>
>> It’s certainly the most popular, especially since big names like
>> PayPal work exclusively with the platform. There have been issues with
>> HackerOne’s response, including the huge scandal involving Valve, when
>> a researcher was banned from HackerOne after trying to report a Steam
>> zero-day.
>>
>> However, its Triage system, which is often seen as an innovation,
>> actually has a serious problem. The way that HackerOne’s triage system
>> works is simple: instead of bothering the vendor (HackerOne’s
>> customer) with each reported vulnerability, they’ve set up a system
>> where HackerOne Security Analysts will quickly check and categorize
>> each reported issue and escalate or close the issues as needed. This
>> is similar to the triage system in hospitals.
>>
>> These Security Analysts are able to identify the problem, try to
>> replicate it, and communicate with the vendor to work on a fix.
>> However, there’s one big flaw here: these Security Analysts are also
>> active Bug Bounty Hackers.
>>
>> Essentially, these Security Analysts get first dibs on reported
>> vulnerabilities. They have full discretion on the type of severity of
>> the issue, and they have the power to escalate, delay or close the
>> issue.
>>
>> That presents a huge opportunity for them, if they act in bad faith.
>> Other criticisms have pointed out that Security Analysts can first
>> delay the reported vulnerability, report it themselves on a different
>> bug bounty platform, collect the bounty (without disclosing it of
>> course), and then closing the reported issue as Not Applicable, or
>> perhaps Duplicate.
>>
>> As such, the system is ripe for abuse, especially since Security
>> Analysts on HackerOne use generic usernames, meaning that there’s no
>> real way of knowing what they are doing on other bug bounty platforms.
>> ______
>>
>> Sono sempre a disagio di fronte alla locuzione "hacker etico".
>>
>> L'hacking è sempre una azione etica: un'etica basata sulla curiosità,
>> volta alla ricerca di conoscenza.
>>
>> Il fatto che si qualifichi come "etica" la collaborazione con i
>> responsabili di una falla di sicurezza nel ritardare la diffusione
>> dell'informazione è in parte sintomo ed in parte causa del pessimo
>> livello di sicurezza nell'informatica.
>>
>>
>> Se ogni falla di sicurezza venisse subito anonimamente diffusa sui
>> mass media, dopo un paio di fallimenti aziendali, avremmo software
>> molto più sicuro.
>>
>> Windows sarebbe il sistema operativo più sicuro del pianeta.
>> (o Microsoft non esisterebbe più...)
>>
>> Invece, abbiamo HackerOne.
>>
>>
>> Giacomo
>> _______________________________________________
>> nexa mailing list
>> nexa(a)server-nexa.polito.it
>> https://server-nexa.polito.it/cgi-bin/mailman/listinfo/nexa
>
March 1, 2020