cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

Wen boosted

[?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
@MissConstrue@mefi.social

RE: infosec.exchange/@mttaggart/11

This is a really important read for understanding both what's under the hood with LLMs, but also why it is impossible to secure any .

In the thread, I posted a couple of extra links to experts explaining that last sentence better than I can. But read the article Taggart linked first.

Nora Tindall boosted

[?]Taggart :ifin: » 🌐
@mttaggart@infosec.exchange

This is a masterful demonstration of the unsecurable nature of LLMs, and how prompt injection by dedicated humans who know how to write will always win.

role-confusion.github.io/

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Ubisoft.

    Only tells you the rules after submitting and clicking a link to a pop
    up window.

    dumbpasswordrules.com/sites/ub

      [?]Alyx [Any pronouns :nonbinary_flag:] » 🌐
      @x_cli@infosec.exchange

      Secure Boot is really going great.

      Can it drop dead already?

      Ominous error pop-up. It reads:
Error Details
Unable to download updates
Device 362301da643102b9f38477387e2193e57abaa590
[UEFI dbx] does not currently allow updates: Not enough efivarfs space, requested 38,7 kB and got 18,9 kB

      Alt...Ominous error pop-up. It reads: Error Details Unable to download updates Device 362301da643102b9f38477387e2193e57abaa590 [UEFI dbx] does not currently allow updates: Not enough efivarfs space, requested 38,7 kB and got 18,9 kB

        [?]AmmarSpaces » 🌐
        @AmmarSpaces@infosec.exchange

        The doom of cyber security is not about companies get breached by AI.

        But, if the one who should be protected (the citizen) no longer own the rights of their own in digital world , and being watched 24 hours 7 days.

        In that age, infosec is no longer about "protecting people", but it shifted to "protecting interest".

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Ancestry.

          Password:
          - Must be at least 8 characters long
          - Must contain at least 1 number
          - Must contain at least 1 letter or special character
          - Must not be a well known or common password

          dumbpasswordrules.com/sites/an

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from URSSAF (French employers tax collection service).

            When setting a new password:
            Password must be exactly 8 characters, at least 1 letter, at least 1 number, but no special characters.

            dumbpasswordrules.com/sites/ur

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Pole-Emploi.

              Password must contain at least one letter, one number and one character from `&-_@*%=.,;:!?` only.
              It rejected passwords generated by pass, while accepting `p@ssw0rd!`...
              They also block pasting on the password confirmation field,
              forcing you to manually type your 32-letters-long generated passwo...

              dumbpasswordrules.com/sites/po

                [?]Mysk🇨🇦🇩🇪 » 🌐
                @mysk@mastodon.social

                🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇

                Alt...Demo showing how a command replaces the binaries of Signal, Brave, and Slack

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Onleihe.

                  Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords

                  dumbpasswordrules.com/sites/on

                    [?]Mark Wyner Won’t Comply :vm: » 🌐
                    @markwyner@mas.to

                    It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.

                    (I don’t recall who wrote these words or where I originally saw them. I only made the graphic.)

                    Illustration of some eyes looking straight at you followed by text that reads “I need privacy, not because my actions are questionable. But because your judgment and intentions are.”

                    Alt...Illustration of some eyes looking straight at you followed by text that reads “I need privacy, not because my actions are questionable. But because your judgment and intentions are.”

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Sears.

                      "cAsE sensitive, no spaces, ! or ?
                      8 characters min - 1 letter, 1 number
                      Can't repeat same character more than 3 times in a row
                      Cannot be or contain your username or email address"

                      dumbpasswordrules.com/sites/se

                        [?]signifier of eschaton » 🌐
                        @lw@mastodon.bsd.cafe

                        looking for a database of DNS IOCs, e.g. "if a client queries for domain <X>, it's probably compromised by <Y>". does this exist?

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from Premera Blue Cross.

                          Password must contain 8-30 characters, including one letter and one number.
                          "Special characters allowed" seems to mean a very small handful of choices you can only find through trial and error `-_'.@`

                          dumbpasswordrules.com/sites/pr

                            [?]Mike Sheward » 🌐
                            @SecureOwl@infosec.exchange

                            So, the AI company that sent the detection images to me at my domain internaluser dot com thanked me for the heads up, and advised they had fixed the issue.

                            And by fixed the issue, what they mean is - they still send me daily notifications to internaluser dot com about detections at this random facility, but now they just send the link to the review the image rather than the image itself.

                            It's great that they want to keep me apprised of the happenings at this place, but I'm not sure I need to factor into the RACI at all tbh.

                              [?]Mike Sheward » 🌐
                              @SecureOwl@infosec.exchange

                              i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

                              The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

                              And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

                                [?]Mike Sheward » 🌐
                                @SecureOwl@infosec.exchange

                                [?]Mike Sheward » 🌐
                                @SecureOwl@infosec.exchange

                                Ok, if you are particularly sensitive to the effects of irony, I suggest you take a seat before reading further.

                                In what is perhaps the most perfect encapsulation of everything that this experiment has shown so far, last night, deleted-user.com received over 400 emails from the same organization.

                                This was an EU based tech firm.

                                The purpose of those emails? They were from the company's legal team, advising users of updated terms and conditions, and the first update was:

                                "Data protection: we added language explaining how we handle personal data under the GDPR"

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Hetzner.

                                  - 8 or more characters
                                  - At least one uppercase and one lowercase letter
                                  - At least one number or special character

                                  Okay, fair enough, but after putting in a password with some special characters this message appears:
                                  - Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...

                                  dumbpasswordrules.com/sites/he

                                    [?]R.L. Dane :Debian: :OpenBSD: :FreeBSD: 🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                    @rl_dane@polymaths.social

                                    @moses_izumi @ltning @ju @cwebber @opensourceopenmind

                                    Security isn't, never was, and never will be a product.

                                    I'm glad I don't know what the #infosec industry is like these days.

                                    Even the new name makes me break out in hives: "cyber security"

                                    It reeks of Dunning-Kruger and hollywoodified idiocy.

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from ICAgile.

                                      Observed on November 17, 2020:

                                      Password must contain:
                                      - 8-15 total characters
                                      - At least one lowercase letter
                                      - At least one uppercase letter
                                      - At least one number
                                      - At least one special character (e.g., !#$%^*)

                                      They don't seem to have a public registration form. You receive a registration link...

                                      dumbpasswordrules.com/sites/ic

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from AOK (German Health Insurance).

                                        This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
                                        The password rules are:
                                        - Length between 8 and 14 characters
                                        - At least one letter, one number and one special character
                                        - Special characters are: !...

                                        dumbpasswordrules.com/sites/ao

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from Telekom/T-Systems MyWorkplace.

                                          Telekom's MyWorkplace is a Single Sign On / login hub for their
                                          Open Telekom Cloud which is basically an Amazon AWS clone. It's
                                          rather new and especially for business customers. Especially
                                          because it is for business customers, there's absolutely no reason
                                          to limit a password to 16 characters. Eve...

                                          dumbpasswordrules.com/sites/te

                                            [?]Tinker ☀️ » 🌐
                                            @tinker@infosec.exchange

                                            WarGames came out over forty years ago.

                                              [?]Tinker ☀️ » 🌐
                                              @tinker@infosec.exchange

                                              The movie Hackers came out over thirty years ago.

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from SAS Eurobonus.

                                                The best thing about rules, is that you can multiple different ones!
                                                Like SAS that allows you to have a long password at least when signing
                                                up, but you'll be sorry if you want to change your password later on.

                                                dumbpasswordrules.com/sites/sa

                                                  [?]Ge0rG [he/him] » 🌐
                                                  @ge0rg@chaos.social

                                                  From the "Pivot to woodworking" department

                                                  Venn diagram:
left: forest ranger
right: devops engineer
middle: looking for bugs in logs

                                                  Alt...Venn diagram: left: forest ranger right: devops engineer middle: looking for bugs in logs

                                                    [?]Tinker ☀️ » 🌐
                                                    @tinker@infosec.exchange

                                                    Mr. Robot came out over ten years ago.

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from HSA Bank.

                                                      - Must be minimum 12 characters
                                                      - Must not be one of user's past 5 passwords
                                                      - Must contain uppercase and lowercase letters
                                                      - Must contain a number
                                                      - Must not be the same as user's account number or login/username

                                                      But also...
                                                      - Cannot be longer than 20 characters

                                                      dumbpasswordrules.com/sites/hs

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Getin Bank.

                                                        The new password should contain at least 10 and a maximum of 20 characters.
                                                        The password must contain at least one upper case letter, one lower case
                                                        letter and one number. The password cannot contain non-ASCII Polish alphabet
                                                        characters, special characters `&<'"` or spaces.

                                                        dumbpasswordrules.com/sites/ge

                                                          Hedders boosted

                                                          [?]rk: it’s hyphen-minus actually » 🌐
                                                          @rk@mastodon.well.com

                                                          Buddy of mine is in pretty dire straits. He’s got decades in but he went through a nasty divorce and then got laid off twice in 18 months and the psychological and financial toll has been immense. He’s been looking for work for well over a year now and has gotten no bites.

                                                          If anyone is looking for a CISO/infosec manager/security team architect let me know. He’s served in those kind of roles for huge orgs, small orgs, and everything in between.

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from Ameli.fr (French national health insurance).

                                                            This was very painful to find a password that works with this one and that I can actually remember (I ended-up using my bank-account number because everything else failed). It took me maybe one hour and I thought I would become crazy (and yes, the session expires frequently while you are actually...

                                                            dumbpasswordrules.com/sites/am

                                                              [?]nixCraft 🐧 » 🌐
                                                              @nixCraft@mastodon.social

                                                              strncpy() has been removed from the kernel. All former callers have +been migrated to safer alternatives. strncpy() is major source of bugs. The replacements are listed now.
                                                              git.kernel.org/pub/scm/linux/k
                                                              FYI, this is starting from Linux kernel v7.2 but it was the need of the hour.

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Irodoricomics.

                                                                A website to buy english-localized doujins. The password must be between 4 and 20 characters long

                                                                dumbpasswordrules.com/sites/ir

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from NetworkRail Open Data Feeds.

                                                                  Does require special characters but limits password length to 20.

                                                                  dumbpasswordrules.com/sites/ne

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Replit.

                                                                    Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                                                                    dumbpasswordrules.com/sites/re

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Lenovo.

                                                                      - **Between 8 and 20 characters, not more.**
                                                                      - 1 alphabetic letter
                                                                      - 1 number (0-9)
                                                                      - **1 symbol ($!#&)**

                                                                      dumbpasswordrules.com/sites/le

                                                                        Chewie boosted

                                                                        [?]k3ym𖺀 » 🌐
                                                                        @k3ym0@infosec.exchange

                                                                        reminder that "fortibleed" is not a vuln. no CVE. no patch. nothing fucking "bled."

                                                                        it's a russian-speaking crew firing 1.16 billion creds from old breaches and infostealer logs at every fortigate dumb enough to have its mgmt interface sitting on the public internet. ~50% of internet-facing boxes. half of you.

                                                                        and before anyone cries "but my password was 28 characters with symbols": it didn't get cracked. it was already chilling in an infostealer dump in plaintext. great entropy, shame about the malware on your sales guy's laptop.

                                                                        the -bleed suffix is marketing. the real CVE is CVE-2026-YOUREANIDIOT: "admin panel pointed at 0.0.0.0/0, password recycled from a 2022 breach, MFA considered but never enabled."

                                                                        rotate the creds, yank the mgmt interface off the internet, force MFA, and maybe stop letting threat intel firms name your incidents like they're naming a fucking Marvel villain.

                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from California Department of Motor Vehicles.

                                                                          They also prohibit pasting into the password field by using a JavaScript
                                                                          `alert()` whenever you right-click or press the `Ctrl` button, so
                                                                          you can't use a password manager.

                                                                          dumbpasswordrules.com/sites/ca

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Ancestry.

                                                                            Password:
                                                                            - Must be at least 8 characters long
                                                                            - Must contain at least 1 number
                                                                            - Must contain at least 1 letter or special character
                                                                            - Must not be a well known or common password

                                                                            dumbpasswordrules.com/sites/an

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from ANZ Bank.

                                                                              Your password needs to be between 8 and 16 characters long - no special characters allowed.

                                                                              dumbpasswordrules.com/sites/an

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from Daybreak Games.

                                                                                Max password length is 15 characters

                                                                                The only special characters that can be used are !"#$%

                                                                                dumbpasswordrules.com/sites/da

                                                                                  [?]Neil Craig [He/Him] » 🌐
                                                                                  @tdp_org@mastodon.social

                                                                                  I'm sure this has done the rounds but I am catching up with things after being offline for a few days.

                                                                                  tl;dr: FIFA's RBAC controls implemented client side inc. streaming controls and live scores portals

                                                                                  > It wasn't just read access. The Streaming Management panel had full controls. Start, stop, schedule. For every match. Every camera angle.

                                                                                  > "Update Live Stats" with a rich text editor, match time, match score fields, and an "Edit and Publish" button

                                                                                  Dang.

                                                                                  bobdahacker.com/blog/fifa-hack

                                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                                    @dumbpasswordrules@infosec.exchange

                                                                                    This dumb password rule is from Credit Agricole.

                                                                                    * Login is a predefined 11 digits long identifier that you can not change
                                                                                    * Password is a 6 digits long identifier that you need to input using your mouse

                                                                                    dumbpasswordrules.com/sites/cr

                                                                                      [?]Dissent Doe :cupofcoffee: [She/Her] » 🌐
                                                                                      @PogoWasRight@infosec.exchange

                                                                                      NEW by me:

                                                                                      One threat actor demanded $50 million from Novo Nordisk. Another one demanded $25 million. Neither got paid.

                                                                                      Two different groups tried to extort Novo Nordisk at around the same time. Novo Nordisk strung them both along, and then went dark.

                                                                                      Data leaks followed.

                                                                                      databreaches.net/2026/06/16/on

                                                                                      @campuscodi @euroinfosec @jgreig @lorenzofb @ajvicens @amvinfe

                                                                                        [?]C64Whiz » 🌐
                                                                                        @c64whiz@oldbytes.space

                                                                                        So Commodore is introducing a smart phone.

                                                                                        youtube.com/watch?v=ixD_fqrnA_c

                                                                                        I was excited at first but then the description. Personally, as a Cybersecurity person, you can not tell me it has privacy while including WhatsApp and Google Maps. Sorry Commodore, I'm going to pass on this item. Best of luck though, seriously.

                                                                                          [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                                                                                          @bobdahacker@infosec.exchange

                                                                                          ✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.

                                                                                          Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.

                                                                                          Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.

                                                                                          Full writeup: bobdahacker.com/blog/frontier-

                                                                                            Back to top - More...