cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
RE: https://infosec.exchange/@mttaggart/116830015225440372
This is a really important read for understanding both what's under the hood with LLMs, but also why it is impossible to secure any #LLM.
In the thread, I posted a couple of extra links to experts explaining that last sentence better than I can. But read the article Taggart linked first.
Nora Tindall boostedThis is a masterful demonstration of the unsecurable nature of LLMs, and how prompt injection by dedicated humans who know how to write will always win.
This dumb password rule is from Ubisoft.
Only tells you the rules after submitting and clicking a link to a pop
up window.
https://dumbpasswordrules.com/sites/ubisoft/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
The doom of cyber security is not about companies get breached by AI.
But, if the one who should be protected (the citizen) no longer own the rights of their own in digital world , and being watched 24 hours 7 days.
In that age, infosec is no longer about "protecting people", but it shifted to "protecting interest".
This dumb password rule is from Ancestry.
Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter or special character
- Must not be a well known or common password
https://dumbpasswordrules.com/sites/ancestry/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from URSSAF (French employers tax collection service).
When setting a new password:
Password must be exactly 8 characters, at least 1 letter, at least 1 number, but no special characters.
https://dumbpasswordrules.com/sites/urssaf-french-employers-tax-collection-service/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Pole-Emploi.
Password must contain at least one letter, one number and one character from `&-_@*%=.,;:!?` only.
It rejected passwords generated by pass, while accepting `p@ssw0rd!`...
They also block pasting on the password confirmation field,
forcing you to manually type your 32-letters-long generated passwo...
https://dumbpasswordrules.com/sites/pole-emploi/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇
This dumb password rule is from Onleihe.
Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords
https://dumbpasswordrules.com/sites/onleihe/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.
(I don’t recall who wrote these words or where I originally saw them. I only made the graphic.)
This dumb password rule is from Sears.
"cAsE sensitive, no spaces, ! or ?
8 characters min - 1 letter, 1 number
Can't repeat same character more than 3 times in a row
Cannot be or contain your username or email address"
https://dumbpasswordrules.com/sites/sears/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Premera Blue Cross.
Password must contain 8-30 characters, including one letter and one number.
"Special characters allowed" seems to mean a very small handful of choices you can only find through trial and error `-_'.@`
https://dumbpasswordrules.com/sites/premera-blue-cross/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
So, the AI company that sent the detection images to me at my domain internaluser dot com thanked me for the heads up, and advised they had fixed the issue.
And by fixed the issue, what they mean is - they still send me daily notifications to internaluser dot com about detections at this random facility, but now they just send the link to the review the image rather than the image itself.
It's great that they want to keep me apprised of the happenings at this place, but I'm not sure I need to factor into the RACI at all tbh.
i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.
The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.
And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D
I wrote up this cursed discovery with more details:
https://mike-sheward.medium.com/deleteduser-com-a-15-pii-magnet-c4396eb21061
Ok, if you are particularly sensitive to the effects of irony, I suggest you take a seat before reading further.
In what is perhaps the most perfect encapsulation of everything that this experiment has shown so far, last night, deleted-user.com received over 400 emails from the same organization.
This was an EU based tech firm.
The purpose of those emails? They were from the company's legal team, advising users of updated terms and conditions, and the first update was:
"Data protection: we added language explaining how we handle personal data under the GDPR"
This dumb password rule is from Hetzner.
- 8 or more characters
- At least one uppercase and one lowercase letter
- At least one number or special character
Okay, fair enough, but after putting in a password with some special characters this message appears:
- Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...
https://dumbpasswordrules.com/sites/hetzner/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
@moses_izumi @ltning @ju @cwebber @opensourceopenmind
Security isn't, never was, and never will be a product.
I'm glad I don't know what the #infosec industry is like these days.
Even the new name makes me break out in hives: "cyber security"
It reeks of Dunning-Kruger and hollywoodified idiocy.
This dumb password rule is from ICAgile.
Observed on November 17, 2020:
Password must contain:
- 8-15 total characters
- At least one lowercase letter
- At least one uppercase letter
- At least one number
- At least one special character (e.g., !#$%^*)
They don't seem to have a public registration form. You receive a registration link...
https://dumbpasswordrules.com/sites/icagile/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AOK (German Health Insurance).
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one number and one special character
- Special characters are: !...
https://dumbpasswordrules.com/sites/aok-german-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Telekom/T-Systems MyWorkplace.
Telekom's MyWorkplace is a Single Sign On / login hub for their
Open Telekom Cloud which is basically an Amazon AWS clone. It's
rather new and especially for business customers. Especially
because it is for business customers, there's absolutely no reason
to limit a password to 16 characters. Eve...
https://dumbpasswordrules.com/sites/telekomt-systems-myworkplace/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from SAS Eurobonus.
The best thing about rules, is that you can multiple different ones!
Like SAS that allows you to have a long password at least when signing
up, but you'll be sorry if you want to change your password later on.
https://dumbpasswordrules.com/sites/sas-eurobonus/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from HSA Bank.
- Must be minimum 12 characters
- Must not be one of user's past 5 passwords
- Must contain uppercase and lowercase letters
- Must contain a number
- Must not be the same as user's account number or login/username
But also...
- Cannot be longer than 20 characters
https://dumbpasswordrules.com/sites/hsa-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Singapore Airlines.
`/[0-9]{6}/`
https://dumbpasswordrules.com/sites/singapore-airlines/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Getin Bank.
The new password should contain at least 10 and a maximum of 20 characters.
The password must contain at least one upper case letter, one lower case
letter and one number. The password cannot contain non-ASCII Polish alphabet
characters, special characters `&<'"` or spaces.
https://dumbpasswordrules.com/sites/getin-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Buddy of mine is in pretty dire straits. He’s got decades in #infosec but he went through a nasty divorce and then got laid off twice in 18 months and the psychological and financial toll has been immense. He’s been looking for work for well over a year now and has gotten no bites.
If anyone is looking for a CISO/infosec manager/security team architect let me know. He’s served in those kind of roles for huge orgs, small orgs, and everything in between.
This dumb password rule is from Ameli.fr (French national health insurance).
This was very painful to find a password that works with this one and that I can actually remember (I ended-up using my bank-account number because everything else failed). It took me maybe one hour and I thought I would become crazy (and yes, the session expires frequently while you are actually...
https://dumbpasswordrules.com/sites/ameli-fr-french-national-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
strncpy() has been removed from the #Linux kernel. All former callers have +been migrated to safer alternatives. strncpy() is major source of bugs. The replacements are listed now.
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3746ccbb0a97bed3c06ccde6b880013b1dddc1
FYI, this is starting from Linux kernel v7.2 but it was the need of the hour.
This dumb password rule is from Irodoricomics.
A website to buy english-localized doujins. The password must be between 4 and 20 characters long
https://dumbpasswordrules.com/sites/irodoricomics/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from NetworkRail Open Data Feeds.
Does require special characters but limits password length to 20.
https://dumbpasswordrules.com/sites/networkrail-open-data-feeds/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Replit.
Forces to use minimum 8 characters in the password and it must contain at least one uppercase.
https://dumbpasswordrules.com/sites/replit/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Lenovo.
- **Between 8 and 20 characters, not more.**
- 1 alphabetic letter
- 1 number (0-9)
- **1 symbol ($!#&)**
https://dumbpasswordrules.com/sites/lenovo/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
reminder that "fortibleed" is not a vuln. no CVE. no patch. nothing fucking "bled."
it's a russian-speaking crew firing 1.16 billion creds from old breaches and infostealer logs at every fortigate dumb enough to have its mgmt interface sitting on the public internet. ~50% of internet-facing boxes. half of you.
and before anyone cries "but my password was 28 characters with symbols": it didn't get cracked. it was already chilling in an infostealer dump in plaintext. great entropy, shame about the malware on your sales guy's laptop.
the -bleed suffix is marketing. the real CVE is CVE-2026-YOUREANIDIOT: "admin panel pointed at 0.0.0.0/0, password recycled from a 2022 breach, MFA considered but never enabled."
rotate the creds, yank the mgmt interface off the internet, force MFA, and maybe stop letting threat intel firms name your incidents like they're naming a fucking Marvel villain.
This dumb password rule is from California Department of Motor Vehicles.
They also prohibit pasting into the password field by using a JavaScript
`alert()` whenever you right-click or press the `Ctrl` button, so
you can't use a password manager.
https://dumbpasswordrules.com/sites/california-department-of-motor-vehicles/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ancestry.
Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter or special character
- Must not be a well known or common password
https://dumbpasswordrules.com/sites/ancestry/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from ANZ Bank.
Your password needs to be between 8 and 16 characters long - no special characters allowed.
https://dumbpasswordrules.com/sites/anz-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Daybreak Games.
Max password length is 15 characters
The only special characters that can be used are !"#$%
https://dumbpasswordrules.com/sites/daybreak-games/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
I'm sure this has done the rounds but I am catching up with things after being offline for a few days.
tl;dr: FIFA's RBAC controls implemented client side inc. streaming controls and live scores portals
> It wasn't just read access. The Streaming Management panel had full controls. Start, stop, schedule. For every match. Every camera angle.
> "Update Live Stats" with a rich text editor, match time, match score fields, and an "Edit and Publish" button
Dang.
This dumb password rule is from Credit Agricole.
* Login is a predefined 11 digits long identifier that you can not change
* Password is a 6 digits long identifier that you need to input using your mouse
https://dumbpasswordrules.com/sites/credit-agricole/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
NEW by me:
One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.
Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.
Data leaks followed.
#NovoNordisk #FulcrumSec #TheUSERS007 #hackandleak #extortion #AI #databreach #infosec #cybersecurity
@campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe
So Commodore is introducing a smart phone.
https://www.youtube.com/watch?v=ixD_fqrnA_c
I was excited at first but then the description. Personally, as a Cybersecurity person, you can not tell me it has privacy while including WhatsApp and Google Maps. Sorry Commodore, I'm going to pass on this item. Best of luck though, seriously.
✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.
Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.
Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.
Full writeup: https://bobdahacker.com/blog/frontier-airlines-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FrontierAirlines #Security #CyberSecurity #Privacy #Aviation #PCIDSS #DataExposure