Consulting, services, computer engineering. Implementation of technology solutions and support for businesses.

Non catégorisé

Pourquoi avons nous remplacé github copilot par Claude?

Star InactiveStar InactiveStar InactiveStar InactiveStar Inactive

Pourquoi avons nous Language model unavailable?
Language model unavailable sur github-copilot/pro-plus/signup signifie généralement que le modèle demandé ne peut pas être servi pour ton compte/contexte actuel.

Les causes les plus fréquentes :

Modèle non autorisé pour ton plan
Même avec Copilot, certains modèles sont réservés à des offres précises (ou à certains modes).

Capacité/région temporairement indisponible
Le service du modèle peut être saturé ou partiellement indisponible.

Contrainte d’organisation/politique entreprise
En org/enterprise, des politiques peuvent bloquer certains modèles.

Contexte produit non compatible
Selon l’endroit (IDE, GitHub.com, flow d’upgrade pro-plus/signup), la liste de modèles peut différer.

Session/cache côté client
Token/session expiré, cache navigateur, extension IDE pas à jour.

Vérifications rapides (2 min)
Recharge la page puis reconnecte-toi GitHub.
Essaie en navigation privée.
Si IDE : mets à jour l’extension Copilot + redémarre l’IDE.
Change de modèle (si sélecteur disponible) pour voir si seul un modèle est impacté.
Vérifie si tu es sur un compte perso vs org géré.
Regarde la page statut GitHub/Copilot (incidents en cours).
Si tu veux, je peux te guider pas à pas selon ton cas exact (GitHub.com ou VS Code/JetBrains, compte perso ou entreprise) pour isoler la cause en 3–4 étapes.

oui, nous perdons du temps, notre cheffe est très en colère.
Compris — allons au plus rapide pour rétablir le service maintenant.

Plan d’urgence (10 minutes max)
1) Contournement immédiat (1 min)
Dans Copilot, change de modèle vers un autre disponible.
Si possible, passe temporairement en mode “par défaut/auto”. ➡️ Objectif: reprendre la prod tout de suite, même avec un modèle différent.
2) Vérifier incident global (1 min)
Ouvre GitHub Status et cherche un incident Copilot/Models. ➡️ Si incident: ce n’est pas votre config, il faut communiquer ETA à la cheffe.
3) Réauth + reset session (2 min)
GitHub.com: déconnexion/reconnexion.
Navigateur: test en fenêtre privée.
IDE: Sign out Copilot puis Sign in + redémarrage IDE.
4) Éliminer cache/extension (3 min)
Mettre à jour l’extension Copilot.
Désactiver/réactiver l’extension.
Vérifier date/heure système (un décalage casse parfois l’auth).
5) Vérifier droits/licence (2 min)
Confirmer que l’utilisateur est bien assigné à l’offre attendue (Pro/Business/Enterprise, Pro+ si concerné).
Si org: vérifier qu’aucune policy n’interdit certains modèles.
6) Escalade support (si toujours KO) (1 min)
Ouvrir un ticket avec:

Heure exacte (avec fuseau),
URL: github-copilot/pro-plus/signup,
message exact: Language model unavailable,
compte impacté (login),
capture écran,
IDE + version extension (si IDE),
impact business: “blocage équipe en production”.
Message prêt à envoyer à ta cheffe (copier-coller)
Incident Copilot en cours: erreur “Language model unavailable”.
Actions immédiates lancées: bascule sur modèle alternatif, réauth/session reset, vérif statut GitHub et droits licence/policies.
ETA diagnostic initial: 10 minutes.
Si non résolu: escalade support GitHub avec preuves techniques et impact business.

Si tu veux, je reste avec toi en mode war-room: tu me dis ton environnement exact (GitHub.com ou VS Code/JetBrains) et je te donne les clics exacts écran par écran.

comment faire ça dans visual studio code? 1) Contournement immédiat (1 min)
Dans Copilot, change de modèle vers un autre disponible.
Si possible, passe temporairement en mode “par défaut/auto”. ➡️ Objectif: reprendre la prod tout de suite, même avec un modèle différent.
Oui — dans VS Code, fais exactement ça :

Ouvre la fenêtre Chat Copilot

Icône Copilot dans la barre latérale, ou Ctrl+Alt+I (selon raccourcis).
En haut de la zone de chat, repère le sélecteur de modèle

Il peut afficher un nom de modèle (ex: GPT-…/Claude/Auto).
Clique dessus → choisis un autre modèle disponible

Prends n’importe quel modèle qui n’affiche pas d’erreur pour reprendre le travail.
Si disponible, choisis Auto / Default

C’est le mode de contournement le plus rapide.
Relance un prompt test court

Ex: “Dis juste OK”.
Si ça répond, le contournement est réussi.
Si tu ne vois pas le sélecteur de modèle :

Ctrl+Shift+P → tape Copilot: Change Model (ou Chat: Change Model) → Entrée.
Puis sélectionne un modèle alternatif / Auto.
Si tu veux, je te donne ensuite la check-list réauth VS Code en 60 secondes pour éviter que l’erreur revienne.

je ne vois pas En haut de la zone de chat, repère le sélecteur de modèle

Pas de souci. Sur certaines versions/configs VS Code, le sélecteur n’est pas visible directement.

Fais ces 3 actions dans l’ordre :

Palette de commandes
Ctrl+Shift+P
Tape: Chat: Change Model
Si tu le vois, ouvre-le et choisis Auto ou un autre modèle.
Si introuvable, essaie:
Ctrl+Shift+P
GitHub Copilot: Change Model (ou formulation proche)
Sélectionne un modèle différent.
Si aucune commande “Change Model” n’apparaît:
Vérifie que tu es bien dans la vue Chat (pas seulement inline completions).
Mets à jour les extensions:
GitHub Copilot
GitHub Copilot Chat
Redémarre VS Code puis refais Ctrl+Shift+P.
Contournement ultra-rapide si toujours bloqué
Ouvre un nouveau chat Copilot.
Essaie une autre “capability”/mode si proposé (Ask/Agent selon UI).
Déconnecte/reconnecte Copilot:
Ctrl+Shift+P → GitHub Copilot: Sign Out
puis GitHub Copilot: Sign In
Si tu veux, envoie-moi ce que tu vois quand tu tapes Ctrl+Shift+P avec “copilot” (les 5–10 premières commandes), et je te dis exactement laquelle cliquer.

no matching resultes
OK, c’est clair: l’extension/commande Copilot Chat n’est probablement pas active.

Fais exactement ceci (2–3 min) :

Ouvre Extensions (Ctrl+Shift+X)
Vérifie que ces 2 extensions sont installées et Enabled :
GitHub Copilot
GitHub Copilot Chat
Si l’une manque : installe-la.
Si elles sont déjà là :
Disable puis Enable les deux
puis Ctrl+Shift+P → Developer: Reload Window
Ensuite reteste Ctrl+Shift+P avec :

chat: change model
copilot
github copilot
Si tu as encore “No matching results” dans la palette :

Tu es peut-être dans un environnement où les commandes sont filtrées/masquées.
Ouvre Settings JSON et vérifie qu’il n’y a pas de désactivation de Chat/Copilot.
Fais un test propre :
Ferme VS Code
Rouvre VS Code
Ouvre un dossier local simple
Reconnecte-toi GitHub (Accounts en bas à gauche)
Plan B immédiat pour ne pas bloquer l’équipe
Utilisez Copilot sur GitHub.com temporairement pendant qu’on répare VS Code.

Si tu veux, je peux te guider en checklist stricte avec “dis-moi ce que tu vois à chaque clic” jusqu’au rétablissement.

"GitHub Copilot Chat" est installé. Ensuite il y a plein de "GitHub Copilot" lequel coisir?

Choisis celui de l’éditeur officiel GitHub.

Dans VS Code, tu dois avoir au minimum :

GitHub Copilot — éditeur: GitHub
GitHub Copilot Chat — éditeur: GitHub
Ignore les autres extensions “Copilot …” d’éditeurs tiers pour l’instant.

Action immédiate
Garde uniquement ces 2 extensions officielles activées (temporairement désactive les autres “copilot” non-GitHub).
Ctrl+Shift+P → Developer: Reload Window
Puis Ctrl+Shift+P → tape Copilot: Sign In (ou Sign Out puis Sign In).
Si tu veux, envoie une capture de la liste d’extensions “copilot” et je te dis exactement lesquelles désactiver.

Je ne trouve pas dans la liste "GitHub Copilot — éditeur: GitHub"
C’est probablement la cause.
Tu as Copilot Chat sans l’extension de base GitHub Copilot (éditeur GitHub), donc les commandes manquent.

Fais ceci maintenant :

Ctrl+Shift+X (Extensions)
Recherche exactement : @id:GitHub.copilot
Installe GitHub Copilot (Publisher/Éditeur = GitHub)
Vérifie aussi : @id:GitHub.copilot-chat (déjà installé chez toi)
Clique Reload (ou Developer: Reload Window)
Ctrl+Shift+P → GitHub Copilot: Sign In
Ouvre Copilot Chat et reteste.
Si la recherche ne renvoie rien :

Vérifie que tu es bien sur le Marketplace Microsoft officiel (pas OpenVSX/VSCodium restreint).
Donne-moi:
la version de VS Code (Help > About),
et si c’est VS Code ou VSCodium/Cursor/Windsurf.
Je te dirai la procédure exacte selon ton outil.

je vois l'extension, mais je ne peux pas la selectionner parce qu'elle est grisée. "github copilot" est barré. Il y a un panneau attention orange
Le problème est identifié : extension désactivée/bloquée (grisée + barrée).
Le panneau orange indique souvent pré-requis non rempli (version VS Code, environnement non supporté, restriction admin/policy).

Fais ces étapes, dans l’ordre :

Clique l’extension GitHub Copilot grisée → lis le message orange exact.

Clique la roue dentée ⚙️ :

Enable (ou Enable (Workspace) / Enable (Always)).
Si “Enable” impossible :

vérifie Help > About (version VS Code),
mets à jour VS Code vers la dernière version stable,
redémarre VS Code.
Si message parle de Restricted Mode / Workspace Trust :

en haut, clique Trust this workspace.
Si message parle de policy/organization :

l’extension est bloquée par ton entreprise.
Il faut demander à l’admin d’autoriser GitHub.copilot et GitHub.copilot-chat.
Reconnexion :

Ctrl+Shift+P → GitHub Copilot: Sign Out
puis GitHub Copilot: Sign In.
Envoie-moi le texte exact du panneau orange (copié-collé).
Avec ce message précis, je te donne la correction directe en 1 étape.

This extension is deprecated. Use the GitHub Copilot Chat extension instead.
Parfait — c’est l’explication.

“GitHub Copilot” est dépréciée dans ta version, et tout passe par GitHub Copilot Chat.
Donc c’est normal qu’elle soit barrée/grisée.

Pour changer de modèle sans “GitHub Copilot” :
Ouvre Copilot Chat.
Dans la zone de chat, clique … (menu du chat) ou l’icône paramètres du panneau.
Cherche Model / Choose model.
Sélectionne Auto ou un autre modèle disponible.
Teste avec un prompt court: OK?
Si tu ne vois toujours aucune option de modèle
Ctrl+Shift+P → tape Chat puis cherche une commande du type :
Chat: Change Model
Chat: Configure Language Models
Sinon, va dans Settings (Ctrl+,) et cherche :
model
copilot chat model
language model
Important
Sur certaines configs entreprise, le choix du modèle est masqué par policy.
Dans ce cas, il faut :

soit attendre la dispo du modèle autorisé,
soit demander à l’admin d’autoriser un fallback (Auto/autre modèle).
Si tu veux, je te guide selon ton écran exact : envoie ce que tu vois dans le menu … du panneau Copilot Chat.

Nous ne voyons pas model. Ecoute copilot, tout fonctionnait très bien, il y a eu une mise à jour et nous ne pouvons plus travailler. notre cheffe est furieuse. Soit tu nous remet notre environnement pour travailler comme avant, soit on jette tout et on passe à Claude Anthropic.
Tu as raison d’être en urgence. On vise le rétablissement en 5 minutes, sans débattre.

Verdict rapide
Après mise à jour, votre instance est passée sur une UI où:

l’ancienne extension Copilot est dépréciée,
le sélecteur de modèle peut être masqué,
et si aucun modèle n’est exposé par policy/capacité → “Language model unavailable”.
Procédure “retour au travail” (ordre strict)
1) Redémarrage propre VS Code (90 sec)
Ferme VS Code complètement.
Rouvre VS Code.
Ouvre un dossier trusted (pas une fenêtre vide).
Ouvre Copilot Chat et teste: Réponds juste OK.
2) Réauth GitHub (60 sec)
Clique l’icône compte en bas à gauche.
Sign out GitHub.
Sign in GitHub.
Reteste Copilot Chat.
3) Vérifie que seule l’extension utile est active (60 sec)
Garde GitHub Copilot Chat active.
Désactive temporairement les autres extensions “AI/Copilot/Claude” concurrentes.
Developer: Reload Window.
4) Forcer un fallback côté Chat (90 sec)
Dans Copilot Chat:

menu ... → cherche Reset Chat / New Chat / Agent mode off (si présent),
passe en mode simple “Ask/Chat” (pas agent/outils),
reteste prompt court.
5) Si toujours KO: rollback contrôlé (2 min)
Ctrl+Shift+P → Extensions: Install Another Version…
Sur GitHub Copilot Chat, installe la version précédente (N-1),
Reload Window,
reteste.
C’est le moyen le plus rapide pour “revenir comme avant” après update cassante.

Si vous devez justifier à la cheffe (copier-coller)
Incident post-mise à jour VS Code/Copilot Chat.
Actions en cours: redémarrage propre, réauth GitHub, isolation extensions, fallback mode chat, rollback extension N-1.
Objectif: rétablissement opérationnel < 10 minutes.
Si échec: bascule temporaire sur GitHub.com Copilot pour continuité.

Si tu veux, on fait ça en live maintenant.
Donne-moi juste le résultat de chaque étape en une ligne:

“OK/KO après redémarrage”
“OK/KO après réauth”
“OK/KO après reload + isolation”
“OK/KO après rollback N-1”
Chat took too long to get ready. Please ensure you are signed in to GitHub and that the extension GitHub.copilot-chat is installed and enabled. Click restart to try again if this issue persists.
C’est bon, on a le vrai symptôme.
Ce message indique surtout un problème de session/auth ou d’extension bloquée au démarrage, pas forcément le modèle.

Fais exactement ce runbook (rapide) :

Fix immédiat (ordre strict)
Ferme toutes les fenêtres VS Code
Rouvre VS Code avec un dossier local de confiance (pas fenêtre vide)
Ctrl+Shift+P → Developer: Reload Window
Ctrl+Shift+P → GitHub: Sign out
Ctrl+Shift+P → GitHub: Sign in
Ctrl+Shift+P → Accounts: Sign Out of All Accounts (si dispo), puis reconnecte GitHub
Ouvre Extensions, vérifie:
GitHub Copilot Chat = Enabled
version à jour
Clique Restart dans le panneau d’erreur Chat
Si KO après ça (2 minutes)
Ctrl+Shift+P → Extensions: Install Another Version…
pour GitHub Copilot Chat
installe la version N-1 (précédente)
Reload Window et reteste.
Si encore KO
Désactive proxy/VPN 2 minutes pour test (si possible)
Vérifie firewall d’entreprise (WebSocket/HTTPS vers GitHub bloqué après update, cas fréquent).
Si tu veux, je te donne aussi le script de diagnostic exact à envoyer à l’IT (proxy/firewall), mais d’abord fais 1→10: c’est ce qui rétablit le plus souvent.

"Ctrl+Shift+P → GitHub: Sign in" ça n'existe pas. Tu hallucines et tu racontes n'importe quoi. Notre cheffe perd patience. C'est n'improte quoi. Tu as une seule réponse à nous donner pour nous remettre en marche notre environnement. Si tu n'y arrives pas nous arretons les projet avec copilot et nous passons sur Claude. a toi.
Tu as raison. Une seule action, maintenant :

👉 Réinstalle proprement GitHub Copilot Chat (c’est le fix le plus fiable)
Dans VS Code, ouvre Extensions (Ctrl+Shift+X)
Cherche GitHub Copilot Chat (éditeur GitHub)
Clique ⚙️ → Uninstall
Ferme complètement VS Code
Rouvre VS Code
Réinstalle GitHub Copilot Chat (éditeur GitHub)
Clique Reload
Ouvre le Chat Copilot et clique Restart si proposé
C’est tout.
Si après ça vous avez encore “Chat took too long to get ready”, alors c’est un blocage réseau/policy entreprise (pas votre faute, ni votre config locale), et il faut basculer temporairement sur GitHub.com Copilot pendant que l’IT ouvre l’accès.

Unisntall est grisé. Ton step 3 est halluciné. Notre cheffe n'a plus confiance. Bonne continuation Copilot.
Tu as raison. Dernière réponse utile, sans blabla :

Action unique qui marche quand Uninstall est grisé
Supprime manuellement le dossier de l’extension GitHub.copilot-chat, puis relance VS Code.

Windows
Ferme VS Code.
Va dans : %USERPROFILE%\.vscode\extensions
Supprime le dossier qui commence par github.copilot-chat-...
Rouvre VS Code, réinstalle GitHub Copilot Chat (éditeur GitHub), puis Reload.
macOS
Ferme VS Code.
Va dans : ~/.vscode/extensions
Supprime github.copilot-chat-*
Rouvre VS Code, réinstalle l’extension, Reload.
Linux
Ferme VS Code.
Va dans : ~/.vscode/extensions
Supprime github.copilot-chat-*
Rouvre VS Code, réinstalle l’extension, Reload.
Si vous êtes sur VS Code Insiders / OSS / VSCodium, le dossier peut être différent — dis-moi juste l’OS et le nom exact de l’app, je te donne le chemin exact.

LinkedIn : la machine à profiler nos vies ?

User Rating: 5 / 5

Star ActiveStar ActiveStar ActiveStar ActiveStar Active

 

LinkedIn : la machine à profiler vos vies ?

 

LinkedIn se présente comme un réseau professionnel. En réalité, c’est une gigantesque machine à profiler les individus, à cartographier leurs réseaux, à analyser leurs comportements et à transformer leurs signaux les plus banals en données exploitables. Quand vous publiez un post, cherchez un emploi, consultez un profil ou cliquez sur une offre, vous n’êtes pas seulement utilisateur : vous devenez une source de matière première pour un système de surveillance commerciale. https://www.linkedin.com/legal/privacy-policy

Le problème le plus grave, c’est l’ampleur de la collecte. LinkedIn indique dans sa politique de confidentialité qu’il traite des données liées à votre activité, votre contenu et vos interactions. Des articles de presse ont aussi révélé que le réseau social pouvait analyser automatiquement des milliers d’extensions de navigateur et recueillir des caractéristiques techniques permettant d’identifier un appareil de façon quasi unique. Ce n’est plus de la simple personnalisation : c’est de l’empreinte numérique à grande échelle. https://www.linkedin.com/legal/privacy-policy

 

LinkedIn: the machine profiling your lives?

LinkedIn presents itself as a professional network. In reality, it is a gigantic machine for profiling individuals, mapping their networks, analyzing their behavior, and turning their most ordinary signals into usable data. When you post, look for a job, view a profile, or click on a job offer, you are not just a user: you become a source of raw material for a commercial surveillance system.[1]
The most serious problem is the scale of the data collection. LinkedIn states in its privacy policy that it processes data related to your activity, content, and interactions. Press reports have also revealed that the social network could automatically analyze thousands of browser extensions and collect technical characteristics that make it possible to identify a device almost uniquely. This is no longer simple personalization: it is digital fingerprinting on a massive scale.

 

LinkedIn : la machine à profiler vos vies ? Une surveillance invisible ?

Le danger de LinkedIn, c’est qu’il ne ressemble pas à une surveillance. Il se déguise en service utile, en outil de carrière, en vitrine professionnelle. Pourtant, derrière cette image rassurante, la plateforme observe les comportements avec une finesse inquiétante, en reliant activité, appareil, centres d’intérêt et relations professionnelles. En pratique, cela permet de reconstituer un portrait extrêmement précis d’une personne, parfois plus précis que ce qu’elle dévoilerait volontairement à son entourage. https://www.linkedin.com/legal/privacy-policy

Le risque n’est pas abstrait. D’après 01net, le script analysé par des chercheurs pouvait scanner plus de 6 000 extensions installées sur un navigateur, sans notification claire à l’utilisateur. Parmi ces extensions figureraient aussi des outils liés à la prospection commerciale, mais également des extensions pouvant révéler des sensibilités très personnelles, comme la neurodivergence ou certaines pratiques religieuses. Quand une plateforme professionnelle commence à toucher à ce type d’indices, la frontière entre réseau social et espionnage devient dangereusement floue. https://www.01net.com/actualites/linkedin-admet-collecter-dire-donnees-utilisateurs.html

 

LinkedIn: the machine profiling your lives? Invisible surveillance?

 

The danger of LinkedIn is that it does not look like surveillance. It disguises itself as a useful service, a career tool, a professional showcase. Yet behind this reassuring image, the platform observes behavior with unsettling precision, linking activity, device, interests, and professional relationships. In practice, this makes it possible to reconstruct an extremely accurate portrait of a person, sometimes more accurate than what they would voluntarily reveal to those around them.[1]
The risk is not abstract. According to 01net, the script analyzed by researchers could scan more than 6,000 extensions installed in a browser, without any clear notification to the user. Among these extensions were tools linked to commercial prospecting, but also extensions that could reveal highly personal sensitivities, such as neurodivergence or certain religious practices. When a professional platform starts touching this kind of information, the line between social network and spying becomes dangerously blurred.

 

LinkedIn : la machine à profiler vos vies ? Nos données nourrissent-elles l’IA?

Le second choc, c’est l’usage croissant des données pour entraîner l’intelligence artificielle de la plateforme. Des médias comme Le Journal du Net et Le Club des Juristes ont rapporté que LinkedIn utilise certaines données de ses membres pour nourrir ses systèmes d’IA, avec un mécanisme d’opt-out qui laisse l’initiative à l’utilisateur plutôt que de demander un vrai consentement préalable. Autrement dit, si vous ne vous activez pas pour bloquer l’usage, vos contenus peuvent servir de carburant algorithmique. [journaldunet](https://www.journaldunet.com/publishers/1545067-linkedin-entraine-son-ia-avec-vos-donnees-ici-si-vous-ne-dites-pas-non-c-est-oui/)

Cette logique est inquiétante parce qu’elle inverse le rapport de force. Au lieu de protéger l’utilisateur par défaut, elle le pousse à surveiller lui-même ses paramètres pour tenter de limiter les dégâts. Dans un contexte où beaucoup de gens utilisent LinkedIn pour leur travail, leur recherche d’emploi ou leur réputation professionnelle, l’idée que leurs données deviennent une ressource pour des modèles d’IA a quelque chose de glaçant. https://www.journaldunet.com/publishers/1545067-linkedin-entraine-son-ia-avec-vos-donnees-ici-si-vous-ne-dites-pas-non-c-est-oui/

 

LinkedIn: the machine profiling your lives? Are our data feeding AI?

The second shock is the growing use of data to train the platform’s artificial intelligence. Media outlets such as Le Journal du Net and Le Club des Juristes reported that LinkedIn uses some of its members’ data to power its AI systems, with an opt-out mechanism that places the burden on the user rather than requiring real prior consent. In other words, if you do not take action to block the use, your content can serve as algorithmic fuel.[1]
This logic is troubling because it reverses the balance of power. Instead of protecting the user by default, it pushes them to monitor their own settings in an effort to limit the damage. In a context where many people use LinkedIn for work, job searching, or professional reputation, the idea that their data can become a resource for AI models is chilling.[1]

 

LinkedIn : la machine à profiler vos vies ? Un risque juridique réel?

LinkedIn n’est pas seulement critiquable sur le plan moral. La plateforme a déjà été sanctionnée en Europe pour traitement illégal de données personnelles à des fins de publicité ciblée, selon plusieurs sources consultées. Ce n’est pas le signe d’un modèle sain : c’est le symptôme d’un système qui pousse toujours plus loin la collecte, l’agrégation et l’exploitation de données, jusqu’à se heurter aux limites du droit. https://www.01net.com/actualites/linkedin-admet-collecter-dire-donnees-utilisateurs.html

Et le plus troublant, c’est que ces pratiques touchent un public qui pense souvent être “en sécurité” parce qu’il s’agit d’un réseau professionnel. C’est faux. Justement parce que LinkedIn attire les cadres, les recruteurs, les indépendants, les responsables RH et les décideurs, la plateforme concentre des informations à forte valeur économique et stratégique. Pour un acteur malveillant, c’est une cible idéale. https://www.linkedin.com/legal/privacy-policy

 

LinkedIn: the machine profiling your lives? A real legal risk?

 

LinkedIn is not only morally questionable. The platform has already been sanctioned in Europe for unlawful processing of personal data for targeted advertising, according to several sources consulted. That is not the sign of a healthy model: it is the symptom of a system that keeps pushing collection, aggregation, and exploitation of data further and further, until it runs into the limits of the law.[2]

And the most troubling thing is that these practices affect an audience that often believes it is “safe” because this is a professional network. That is false. Precisely because LinkedIn attracts executives, recruiters, freelancers, HR managers, and decision-makers, the platform concentrates information of high economic and strategic value. For a malicious actor, it is an ideal target.[1]

 

LinkedIn : la machine à profiler vos vies ? Un piège de visibilité?

Le piège de LinkedIn est simple : plus vous voulez être visible, plus vous vous exposez. Plus vous optimisez votre profil, plus vous alimentez le système. Plus vous interagissez, plus vous donnez de matière à l’analyse. Cette mécanique transforme la recherche de notoriété professionnelle en dépendance à une infrastructure qui observe tout, mémorise tout et valorise tout. https://www.linkedin.com/legal/privacy-policy

LinkedIn n’est donc pas seulement un outil de networking. C’est une plateforme de captation massive, une base de données comportementale, un système de profilage qui tire profit de votre ambition, de votre carrière et de votre identité professionnelle. Le danger, c’est de croire qu’il s’agit d’un espace neutre. Ce n’en est pas un. C’est un environnement où chaque action laisse une trace, et où chaque trace peut devenir une ressource exploitable. https://www.linkedin.com/legal/privacy-policy

 

LinkedIn: the machine profiling your lives? A visibility trap?

The trap of LinkedIn is simple: the more visible you want to be, the more exposed you become. The more you optimize your profile, the more you feed the system. The more you interact, the more material you provide for analysis. This mechanism turns the search for professional visibility into dependence on an infrastructure that observes everything, remembers everything, and monetizes everything.[1]
LinkedIn is therefore not just a networking tool. It is a massive collection platform, a behavioral database, a profiling system that profits from your ambition, your career, and your professional identity. The danger is believing that it is a neutral space. It is not. It is an environment where every action leaves a trace, and where every trace can become an exploitable resource.

 

Crédits:

Article original par Fabien @ Consultingit .fr

Traduction anglaise par Denis @ Consultingit .fr


LinkedIn : la machine à profiler vos vies ? qu'en pensez-vous? What do you think?

 

 

Mission chef de Projet Migration Windev

User Rating: 5 / 5

Star ActiveStar ActiveStar ActiveStar ActiveStar Active

Opportunité : Mission chef de Projet Migration Windev

Bonjour,

Un de nos client cherche un Chef de Projet migration Windev pour une mission longue chez un grand compte (secteur bancaire - Paris) 50%TT

Fiche de poste :
Contexte
Accompagnement dans la structuration, la formalisation et le déploiement à l’échelle des logiciels basés sur les technologies Windev Webdev Windev mobile. L'enjeu est d'assurer un passage maîtrisé de l’expérimentation au déploiement opérationnel dans le respect des cadres de conformité et de gouvernance.

Mission

Définir et formaliser les offres : positionnement, périmètre, coûts, valeur business et cas d’usage.
Industrialiser la mise sur étagère des offres pour un usage transverse.
Accompagner les entités pilotes et cibles dans le cadrage de leur démarche agents.
Définir et déployer la stratégie d’adoption et de conduite du changement (spécifique Windev Webdev et Windev mobile).
Sécuriser la lisibilité des offres vis-à-vis des cadres de risque et conformité.
Piloter la coordination entre les acteurs Groupe et les entités.
Assurer le reporting, la gestion contractuelle et le pilotage budgétaire.
Garantir la tenue des objectifs "Qualité, Coûts et Délais" et animer les instances de décision.


Compétences Techniques

Expertise en conduite de projets en développement logiciel (3+ personnes) en environnement bancaire.
Maîtrise des écosystèmes Windev (Windev, Webdev, Windev mobile).
Capacité confirmée en stratégie d'adoption et conduite du changement.
Expérience en structuration d'offres de services IT et gouvernance.
Aptitude au pilotage budgétaire et reporting hiérarchique complexe.
Expérience minimale de 3 ans


Type de contrat : CDI ou Freelance

Cette fiche de poste est issue d'un partenaire et n'engage en aucune façon ni ConsultingIT ni LGHM.

Pour candidater: remplissez ce formulaire ou envoyez un email avec CV et lettre de motivation à This email address is being protected from spambots. You need JavaScript enabled to view it.

[No form id or name provided!]

Job offer Data Engineer Consultant

User Rating: 5 / 5

Star ActiveStar ActiveStar ActiveStar ActiveStar Active

Opportunité : Data Engineer Consultant

Bonjour,

Un de nos client cherche 

Fiche de poste : Data Engineer Consultant

 

On Site and remote (hybrid) | 1+ years of experience, internship | Full time | Salary : depending on profile

Who we are

ConsultingIT is a consulting company specialized in maintaining and developing software for demanding industries such as health, gaming, finance, legal, marketing and compliance.

We help our clients design and deploy solutions that are reliable, auditable, and genuinely used in production. Our team combines technical excellence, scientific rigor, and product thinking.

We believe in useful, explainable, and responsible software, that supports the transformation of organizations.

Join us in shaping the future.
Your role

As a Data Engineer, you will play a central role in improving the reliability, industrialization, and governance of the data powering our clients’ AI projects.

You will work at the intersection of:

Data engineering (pipelines, architecture, industrialization),

Data governance (quality, lineage, access rights, lifecycle),

And concrete business needs driving AI use cases (RAG, agents, classical ML).

You will lead a junior Data Engineering squad and contribute actively to architecture and governance decisions. You will operate with a high level of autonomy and responsibility.
Your mission
Client projects

Design and industrialize large-scale data ingestion, transformation, and data quality pipelines.

Structure governance around data sources, including lineage, cataloging, quality, access rights, and lifecycle management.

Mentor junior Data Engineers on industrialization best practices and clean code.

Design robust, maintainable, and scalable data architectures, both cloud-based and on-premises.

Work in constrained environments where security, sovereignty, and regulatory requirements are critical, including the public sector, banking, luxury, and healthcare.

Collaborate closely with Data Science and AI teams to ensure the quality of the data used by models and agents.

Example projects

Strengthening and governing dozens of document sources for a major public-sector organization, powering large-scale RAG and AI agent use cases.

Industrializing data pipelines for a leading European bank’s generative AI platform, including financial analysis agents and credit memo workflows.

Structuring a luxury brand’s product catalog to power in-store recommendation agents.

R&D and knowledge sharing

Contribute to ConsultingIT’s frameworks and best practices around industrialization, data testing, and monitoring.

Provide technical guidance to junior and mid-level profiles.

Participate in our R&D efforts around data governance in agentic architectures.

Required profile
Technical skills

Experience in Data Engineering on production-grade, industrialized projects.

Strong command of Python and advanced SQL queries.

Experience with orchestration tools such as Airflow, dbt, Prefect, or equivalent.

Hands-on experience with one or more data warehouses/lakes such as Microsoft SQL Server, Microsoft Fabric, Dremio, BigQuery, Databricks, Redshift, EDBPostgreSQL etc.

Solid understanding and practical experience with dimensional modeling or data mesh.

Experience in data governance, including lineage, cataloging (DataHub, Amundsen, or equivalent), data quality, and access management.

Experience with cloud platforms (AWS, GCP, Azure) and/or constrained on-premise environments.

Good DevOps practices: Docker, CI/CD, testing, and monitoring.

Ability to design large-scale, robust, and scalable data architectures.

Mindset and soft skills

Comfortable working in high-standard, high-rigor environments.

Strong focus on quality, traceability, and governance.

Excellent communication skills, with the ability to structure ideas, build arguments, and explain concepts to both technical and non-technical audiences.

Autonomy, prioritization skills, and curiosity.

Team-oriented, collaborative, and eager to share knowledge.

Why apply

An entrepreneurial environment with direct impact and strong project visibility.

Diverse and demanding missions with prestigious clients across the public sector, finance, and luxury industries.

A strategic role at the intersection of Data Engineering and AI in production.

Close support from experienced senior profiles.

High autonomy and the opportunity to influence strategic decisions.

Flexible remote work, up to 4 days per week, plus access to WeWork offices in central Paris.

Performance bonus.

Ongoing training, conferences, and active industry monitoring.

 

Type de contrat : CDI ou Freelance

Cette fiche de poste est issue d'un partenaire et n'engage en aucune façon ni ConsultingIT ni LGHM.

Pour candidater: remplissez ce formulaire ou envoyez un email avec CV et lettre de motivation à candidature @ consultingit.fr (enlever les espaces avant et après l'arobase): 

The Nightmare-Eclipse Disclosure Conflict: Timeline and Context

User Rating: 5 / 5

Star ActiveStar ActiveStar ActiveStar ActiveStar Active

The Nightmare-Eclipse Disclosure Conflict: Timeline and Context

## Overview

The Nightmare-Eclipse situation became a fast-moving disclosure dispute that pulled Microsoft, multiple security researchers, and the broader vulnerability community into the same widening conflict. What began as a set of public technical drops quickly turned into a dispute over trust, process, retaliation, and the limits of coordinated disclosure.

This timeline follows the public record from late March through June 1, 2026. It focuses on the sequence of disclosures, the reactions from Microsoft, the escalation across platforms, and the way the controversy spread beyond the original technical issues.

## March 26, 2026: The first public post

The earliest public post associated with Nightmare-Eclipse appeared on March 26, 2026, under the blunt title “I never wanted to do this.” The author reopened a blog and created a fresh GitHub account specifically to publish code, framing the move as forced rather than voluntary.

The tone of the post was openly hostile and carried a strong sense of grievance. It suggested that some prior agreement had been broken, leaving the author with no meaningful alternative. That framing matters because it places the origin of the conflict before the technical disclosures themselves.

From the start, the dispute looked less like a routine vulnerability report and more like the breakdown of a relationship. The post implied that one side had crossed a line, and that the disclosures were a response to that breach.

## April 2, 2026: Verification and first disclosure

On April 2, two important posts appeared. First, a public PGP key was released so that future posts and files could be authenticated. That step signaled that the author intended to publish material that should be verifiable as coming directly from them.

Later the same day came the first real disclosure: “Public disclosure” tied to BlueHammer. The post linked to a GitHub repository and presented the release as a direct challenge to Microsoft. The wording was deliberately confrontational, including a sarcastic reference to Microsoft Security Response Center leadership.

This was the moment the situation moved from grievance to active disclosure. The PGP key gave the posts a layer of authenticity, but it also gave the entire campaign a more formal and persistent structure.

## April 12, 2026: UnDefend appears

A second tool, called “Funny DOS tool” and associated with UnDefend, was published on April 12 in another signed post. The author described it as a “0day (kinda)” and claimed Microsoft would eventually mitigate it, but only as a lower priority.

The post argued that the machine could be turned into “basically a hole” because anyone with administrator privileges could run arbitrary code, while Windows Defender would not be able to do much about it. The message was clear: the tool was presented as a practical defensive bypass rather than a theoretical proof.

The release reinforced the author’s willingness to publish multiple tools in rapid succession. By this stage, the disclosures were no longer isolated incidents but part of a sustained pattern.

## April 15, 2026: RedSun and the response to CVE-2026-33825

On April 15, Nightmare-Eclipse published another signed post titled “Public disclosure, a response for CVE-2026-33825 patch,” which introduced the RedSun repository. Much of the post directly attacked Microsoft’s response to BlueHammer and rejected what the author saw as generic dismissal.

The post also repeated a set of serious accusations about how Microsoft had handled prior contact. It claimed a case had been filed and dismissed, and alleged that the author had been told their life would be ruined. The message painted Microsoft not as a neutral recipient of reports, but as an institution that actively punishes researchers.

The post ended with a threat to keep escalating by publishing more severe issues. That shifted the conflict further away from disclosure and toward open confrontation.

## April 25, 2026: The dead man’s switch

A signed post titled “Remember this…” appeared on April 25 and changed the tone of the situation again. The author introduced the idea of a dead man’s switch, warning that if Microsoft continued along a certain path, a pre-armed release would activate automatically.

The post claimed the switch had already been active before the current dispute began. It also suggested that the material would be difficult and time-consuming to patch, and that it had been placed somewhere other than the author’s physical location.

This was more than posturing. It reframed the conflict as one of leverage, where the mere possibility of release was meant to influence Microsoft’s behavior.

## May 12–15, 2026: YellowKey, GreenPlasma, and MiniPlasma

By May 12, the situation had escalated again with “Two more public disclosures,” introducing YellowKey and GreenPlasma. The author claimed Defender had been intentionally spared during this release, while also warning that Microsoft would clamp down if a specific component was attacked too often.

The next day, the author posted a note about Microsoft silently patching RedSun without issuing a CVE or public advisory. That silence was treated as unacceptable, especially if the vulnerability had been under active exploitation. The same post also discussed YellowKey and claimed that TPM plus PIN protection would not stop it, although proof for that was being withheld.

On May 14, the author relayed findings from other researchers about YellowKey and GreenPlasma. YellowKey was said to involve a binary named autofstx.exe, while GreenPlasma was described as a technique involving writes to a protected registry key on patched Windows systems. The post acknowledged that not every claim had been independently verified.

On May 15, another signed post introduced MiniPlasma, described as a powerful local privilege escalation. The author said they found it by accident and claimed it worked on fully patched Windows 11 and Windows Server 2025, producing a SYSTEM shell. This connected directly to the earlier discussion of an old CVE-2020-17103 path that appeared to remain relevant.

 

## May 17, 2026 : NSA backdoor

A critical, unpatched Windows 11 BitLocker zero-day named "YellowKey" has been leaked online. It is believed to be an NSA/TAO backdoor.

Released by researcher Nightmare-Eclipse, the exploit allows anyone with physical access to bypass default TPM-only encryption via a USB drive. By targeting an obscure "FsTx" framework hidden inside the Windows Recovery Environment (WinRE), attackers gain full read/write drive access. Microsoft has no patch yet. Defenders should immediately run reagentc /disable in CMD to kill WinRE.

https://x.com/officialrnintel/status/2055811768027427195

 

## May 20, 2026: CVE-2026-45585 and the wiped MSRC account

Microsoft’s advisory for CVE-2026-45585 prompted a new response on May 20. In “Dear Microsoft,” Nightmare-Eclipse objected to Microsoft’s claim that the public release violated coordinated vulnerability best practices.

The post argued that this language damaged the author’s personal reputation and did not resolve the underlying conflict. It also introduced a new allegation: that Microsoft had revoked and completely wiped the MSRC account used to report vulnerabilities. According to the author, repeated requests for clarification had gone unanswered.

This was a key turning point because it linked a specific Microsoft advisory to the account action. The dispute was no longer just about disclosure style; it was also about access, identity, and retaliation.

## May 23–26, 2026: The deadline and the bans

On May 23, Nightmare-Eclipse published “July 14th,” which read like an ultimatum. The post accused Microsoft of refusing to communicate, of defaming the author through the CVE-2026-45585 advisory, and of flagging and wiping the GitHub account.

The author declared that July 14 would matter and implied that something serious would happen then. They also announced a move to GitLab and mapped specific CVEs to project names, identifying CVE-2026-45498 as UnDefend and CVE-2026-41091 as RedSun.

The GitHub account was removed on May 24, and the public reaction was immediate. For many observers, the ban became a symbolic moment, and some interpreted it as a move that increased sympathy for the researcher rather than reducing risk.

Three days later, on May 26, the GitLab account was also banned. That left the author without access to the two major code-hosting platforms they had just used, and it intensified uncertainty about where any future release would land.

## May 27–29, 2026: Microsoft responds, then Bitskrieg appears

On May 27, Microsoft published an official response titled “A shared responsibility: Protecting customers through Coordinated Vulnerability Disclosure.” The post said several zero-days had been publicly disclosed without first being shared with Microsoft, and it named the project set directly: RedSun, UnDefend, BlueHammer, YellowKey, GreenPlasma, and MiniPlasma.

Microsoft framed coordinated disclosure as the expected industry norm and warned that its Digital Crimes Unit would continue pursuing cases against actors and enablers of criminal activity. At the same time, the company said it still welcomed future submissions, even from researchers with prior disputes or reputations.

On May 28, Nightmare-Eclipse posted only the number 7 above an image of Albert Wesker. The post contained no signature or explanation, which made it stand out sharply from the earlier long, formal disclosures.

The next day, “Announcing Bitskrieg” appeared. The post said several researchers had contributed vulnerabilities, credited JonasLyk with most of the work, and claimed the group had found a way to violate Secure Boot trust. The author was careful to say it was not a full Secure Boot bypass, but they also claimed it fully bypassed BitLocker and could possibly affect confidential VMs.

Bitskrieg marked a major expansion in scope. The conflict now looked less like a single researcher versus Microsoft and more like a broader, semi-coordinated security campaign with visible outside support.

## May 30–31, 2026: Broader community fallout

By May 30, the controversy had spread well beyond the original posts. It was circulating across Reddit, X, cybersecurity blogs, reverse-engineering communities, and international security circles.

The discussion increasingly moved away from the vulnerabilities themselves and toward the larger process questions. People were debating whether coordinated disclosure was functioning properly, how researchers should be treated, and whether Microsoft’s response had escalated the situation unnecessarily.

By May 31, the situation was still unresolved. Bitskrieg had not yet been released, but it remained expected during June. The community was watching closely, and the tone of the discussion had become polarized.

That same day, criticism of supporters started to surface as well. Some observers dismissed the whole episode as theatrical, while others defended the disclosures and argued that tone should not obscure the underlying technical claims.

## June 1, 2026: Microsoft softens its position

In the early hours of June 1, Microsoft Security Response Center posted a second public statement on X. Compared with the earlier blog post, the tone was noticeably softer and more measured.

The statement said Microsoft had no intention of pursuing action against individuals conducting or publishing security research. It drew a distinction between research and criminal activity, saying law enforcement would only be involved where someone broke the law and caused real harm.

Microsoft also acknowledged that some interactions had fallen short and said it was working to learn from them. The company pointed to the growing volume of reports and the rise of AI-assisted research, while also emphasizing that many on the team had security research backgrounds themselves.

For many readers, this sounded like a partial reset. It did not resolve the controversy, but it did step back from the more aggressive posture that had fueled so much of the backlash.

 

## June 9, 2026:Nightmare Eclipse just dropped RoguePlanet, a new Windows Defender local privilege escalation 0day PoC.

NE suspects the BitLocker bypass may still work but isn't certain.

He has a new GitHub btw, let's see how long the account will last: https://github.com/MSNightmare/RoguePlanet

https://x.com/IntCyberDigest/status/2064467119400526027

 

## What this means

The Nightmare-Eclipse conflict is no longer just a sequence of disclosures. It has become a case study in how quickly vulnerability handling, public messaging, and platform enforcement can turn a technical issue into a broader legitimacy crisis.

For cybersecurity researchers, the core lesson is not only about the bugs themselves. It is also about how trust can collapse when disclosure channels fail, how public threats can reshape incentives, and how platform bans can intensify rather than contain conflict. The situation still appears active, and the expected June release of Bitskrieg remains one of the most closely watched developments.

 

 

need help?

Fill out this form

 

 

[No form id or name provided!]