cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

Tom :damnified: boosted

[?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
@christin@lsbt.me

Wer seinen eigenen Mailserver betreibt, kennt das Problem

Secure Your Server: acht Checks, ein Scan, für immer kostenlos

Ich betreibe neben vielen privaten Domains auch meinen eigenen Mailserver, da hängt viel an einer sauber konfigurierten Domain: DNS-Einträge exakt, TLS sauber, SSH gehärtet. Wer das prüfen will, trifft auf ein Dutzend Scanner, die fast alle dasselbe tun: sich einen einzigen Ausschnitt anschauen und ab einem gewissen Punkt ein Konto oder eine Kreditkarte verlangen. Deshalb gibt es jetzt Secure Your Server: acht Kategorien von DNS bis PGP in einem einzigen Scan, dazu ein echter Mail-Zustellungstest, für immer kostenlos, ohne Konto, ohne Tracking. Teste deine eigene Domain, bevor es jemand mit weniger guten Absichten tut.

chrislo.de/blog/2026-08-10-15-

[?]LWN.net » 🌐
@lwn@fedi.lwn.net

[?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
@nemo@mas.to

Signal is testing “Signal Login,” an optional way to register without a phone number—reportedly requiring a one-time payment 💳📱. The fee would act as a barrier against spam/abuse and help support Signal’s mission 🙌. AboutSignal: aboutsignal.com/news/signal-lo

    [?]adb » 🌐
    @adbenitez@mastodon.de

    am I the only one annoyed by so frequent updates???

    I am already pissed off one can not disable automatic download of updates, one can disable the updates app completely, but I would prefer to manually check for updates and review available update before downloading not to completely disable updates

    then after applying updates it takes ages "optimizing apps" see this screenshot, only 8 optimized apps out of 35 and it has taken 19 minutes already and in the meantime the phone is very slow and overheated :(

      [?]Kyle Rankin » 🌐
      @kyle@mastodon.kylerank.in

      So I've read the news about the HuggingFace / OpenAI incident over the past few weeks, but this Black Hat talk where OpenAI folks talk about agent collaboration and what happened inside is wild.

      youtube.com/watch?v=87DyyMV0kC

        Tim Hergert boosted

        [?]Tom Sellers » 🌐
        @TomSellers@infosec.exchange

        A request for InfoSec nerds, IT peoples, and security product buyers in general:

        If you have a vendor that sells ANYTHING that claims to be a security control, enables security, is "hardened", or tries to trade on "security" in any way and they don't have trivial-to-find security contact information please hound the absolute hell out of them until they do or they fire you as a customer.

        Maybe point them to securitytxt.org/ so they can setup /.well-known/security.txt.

        This would have been a fun game at the Blackhat vendor hall. Check each one and if you find a vendor w/o it then you could have just stood around chanting taunts at them.

          [?]LWN.net » 🌐
          @lwn@fedi.lwn.net

          [?]mle✨ » 🌐
          @mle@infosec.exchange

          RE: infosec.exchange/@mle/11701998

          As of ~yesterday, a leak warning has appeared on Cl0p's site for 42 alleged victims of this campaign. Total estimated amount of data stolen across all orgs reaches roughly 23TB and appears to include data like CAD files, databases and backups, engineering drawings, and various other documents.

          Their total estimate of value for the data seems a bit...off, though, considering one org's valuation is listed at over 2 trillion dollars. Without that outlier, the rest of their estimate for company revenue comes to roughly $192 billion. It's in their best interest to provide estimates on the high side, though, so that's an important consideration.

          [?]mle✨ » 🌐
          @mle@infosec.exchange

          New from me: analysis of a June extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.

          Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.

          Read more: censys.com/blog/cl0p-targets-w

              [?]LWN.net » 🌐
              @lwn@fedi.lwn.net

              Michael boosted

              [?]Ben Hardill » 🌐
              @ben@bluetoot.hardill.me.uk

              Anybody know anything about TuranSec?

              A CVE has been raised against a project I'm involved with by them, but I'm currently +95% sure it's a false positive.

              Are they considered a trusted source?

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                [?]Peter N. M. Hansteen » 🌐
                @pitrh@mastodon.social

                [?]ARGVMI~1.PIF » 🌐
                @argv_minus_one@mastodon.sdf.org

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                An LLM agent attempts to compromise a project on GitHub

                lwn.net/Articles/1087162/

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  [?]Peter N. M. Hansteen » 🌐
                  @pitrh@mastodon.social

                  [?]ARGVMI~1.PIF » 🌐
                  @argv_minus_one@mastodon.sdf.org

                  @paco

                  The mouse is the only one I would *tolerate* being wireless. The others are way too much of a risk. Especially the keyboard.

                  That said, wireless mice sometimes lose signal/battery and that's annoying, so I generally use wired everything.

                    [?]LWN.net » 🌐
                    @lwn@fedi.lwn.net

                    SQLite Critical CVEs or LLM Slop? (JFrog blog)

                    lwn.net/Articles/1086936/

                      [?]LWN.net » 🌐
                      @lwn@fedi.lwn.net

                      [?]GamingOnLinux 🐧🎮 » 🌐
                      @gamingonlinux@mastodon.social

                      [?]LWN.net » 🌐
                      @lwn@fedi.lwn.net

                      [?] » 🌐
                      @grahamperrin@mastodon.bsd.cafe

                      FreeBSD Security in Production: Vulnerability Response and Operational Best Practices

                      klarasystems.com/webinars/free

                      ― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.

                      2026-09-02 15:00 UTC

                      timee.io/e/freebsd-security-20

                      @allanjude

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        Chewie boosted

                        [?]Jan Vlug » 🌐
                        @janvlug@mastodon.social

                        US prosecutors charge Atlanta man after phone wipes itself during airport search

                        "The case centers on ... use of GrapheneOS, an open-source operating system that works on Google Pixel phones and lets users enter a passcode to a device clean."

                        "The wipe is now central to the case. Prosecutors are treating it as an intentional act to destroy evidence..."

                        techspot.com/news/113236-us-pr

                          [?]LWN.net » 🌐
                          @lwn@fedi.lwn.net

                          [?]Wen » 🌐
                          @Wen@mastodon.scot

                          [?]Python Software Foundation » 🌐
                          @ThePSF@fosstodon.org

                          The PSF is hiring a Security Developer! Help triage vulnerabilities in CPython, fight malware/supply-chain attacks on PyPI, and build tools to keep the ecosystem safe for millions of users 🐍🔒 This is a global, remote, 1 year term role, with the possibility of renewal.

                          Apply today:
                          pythonsoftwarefoundation.apply

                            [?]LWN.net » 🌐
                            @lwn@fedi.lwn.net

                            [?]Peter N. M. Hansteen » 🌐
                            @pitrh@mastodon.social

                            [?]nixCraft 🐧 » 🌐
                            @nixCraft@mastodon.social

                            Google now support account recovery with AI and your face. What could possibly go wrong? Google having my face is not just bad enough but chances are high that selfie video may not work in edge cases or network down etc.

                            blog.google/innovation-and-ai/

                            The tweet from Google offical account reads:

Forgot your password? Lost your phone? Can’t get into your account? 

You can now use a selfie video to log into your Google Account. 

The new feature is easy to use and lets you sign in — even if you forget your password or don’t have your usual phone or laptop — with a quick selfie.

There is a short video showing how to use a selfie video to log into your Google Account and link to https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/

                            Alt...The tweet from Google offical account reads: Forgot your password? Lost your phone? Can’t get into your account? You can now use a selfie video to log into your Google Account. The new feature is easy to use and lets you sign in — even if you forget your password or don’t have your usual phone or laptop — with a quick selfie. There is a short video showing how to use a selfie video to log into your Google Account and link to https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              6 ★ 2 ↺
                              Mike Sheward boosted

                              [?]Sam » 🌐
                              @sam@cablespaghetti.dev

                              Fediverse, I have a rant I need to get off my chest. Groups in Google Workspace is a security nightmare and has been for years! Why has Google STILL not fixed the glaring problems!?

                              I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.

                              This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.

                              Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.

                              Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...


                              Screenshot of the default Google Group settings for team mode

                              Alt...Screenshot of the default Google Group settings for team mode

                              Screenshot of the default Google Group settings for public mode

                              Alt...Screenshot of the default Google Group settings for public mode