cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
boostedWer seinen eigenen Mailserver betreibt, kennt das Problem
Ich betreibe neben vielen privaten Domains auch meinen eigenen Mailserver, da hängt viel an einer sauber konfigurierten Domain: DNS-Einträge exakt, TLS sauber, SSH gehärtet. Wer das prüfen will, trifft auf ein Dutzend Scanner, die fast alle dasselbe tun: sich einen einzigen Ausschnitt anschauen und ab einem gewissen Punkt ein Konto oder eine Kreditkarte verlangen. Deshalb gibt es jetzt Secure Your Server: acht Kategorien von DNS bis PGP in einem einzigen Scan, dazu ein echter Mail-Zustellungstest, für immer kostenlos, ohne Konto, ohne Tracking. Teste deine eigene Domain, bevor es jemand mit weniger guten Absichten tut.
#chrislo #digitaleunabhängigkeit #itsicherheit #cybersecurity #infosec #opensource #selfhosting #datenschutz #dsgvo #digitalesouveränität #security #vereine
boostedSignal is testing “Signal Login,” an optional way to register without a phone number—reportedly requiring a one-time payment 💳📱. The fee would act as a barrier against spam/abuse and help support Signal’s mission 🙌. AboutSignal: https://aboutsignal.com/news/signal-login-registration-without-a-phone-number/ #Signal #Privacy #Security #Messaging
am I the only one annoyed by so frequent #GrapheneOS updates???
I am already pissed off one can not disable automatic download of updates, one can disable the updates app completely, but I would prefer to manually check for updates and review available update before downloading not to completely disable updates
then after applying updates it takes ages "optimizing apps" see this screenshot, only 8 optimized apps out of 35 and it has taken 19 minutes already and in the meantime the phone is very slow and overheated :(
#android #degoogled #degoogle #privacy #security #opensource
So I've read the news about the HuggingFace / OpenAI incident over the past few weeks, but this Black Hat talk where OpenAI folks talk about agent collaboration and what happened inside is wild.
A request for InfoSec nerds, IT peoples, and security product buyers in general:
If you have a vendor that sells ANYTHING that claims to be a security control, enables security, is "hardened", or tries to trade on "security" in any way and they don't have trivial-to-find security contact information please hound the absolute hell out of them until they do or they fire you as a customer.
Maybe point them to https://securitytxt.org/ so they can setup /.well-known/security.txt.
This would have been a fun game at the Blackhat vendor hall. Check each one and if you find a vendor w/o it then you could have just stood around chanting taunts at them.
RE: https://infosec.exchange/@mle/117019987473999160
As of ~yesterday, a leak warning has appeared on Cl0p's site for 42 alleged victims of this campaign. Total estimated amount of data stolen across all orgs reaches roughly 23TB and appears to include data like CAD files, databases and backups, engineering drawings, and various other documents.
Their total estimate of value for the data seems a bit...off, though, considering one org's valuation is listed at over 2 trillion dollars. Without that outlier, the rest of their estimate for company revenue comes to roughly $192 billion. It's in their best interest to provide estimates on the high side, though, so that's an important consideration.
#security #ransomware #extortion #cl0p
New from me: analysis of a June #Cl0p extortion campaign. In a departure from their previous targeting, the data stolen in this campaign may be a bit different than what they've taken in the past. The campaign targeted PTC's Windchill and FlexPLM products, product lifecycle management tools used in manufacturing and industrial engineering.
Rather than financial, HR, or customer data, the compromised data in this case may include things like supply chain details, product designs and schematics, and other intellectual property. This is particularly notable given the adoption of Windchill across the energy, electronics, medical device tech, and defense sectors.
Dead Software Walking: The ongoing evolution of relayd(8) and httpd(8) https://undeadly.org/cgi?action=article;sid=20260805083816 #openbsd #relayd #httpd #development #webserver #loadbalancing #security #cryptography #modernsoftware #freesoftware #libresoftware
Call for testing: OpenBSD vmm(4)/vmd(8) fd-ification https://www.undeadly.org/cgi?action=article;sid=20260804054218 #openbsd #vmm #vmd #virtualization #virtualmachines #testing #newcode #development #security #freesoftware #libresoftware
Arch Linux AUR hit with another wave of malware https://www.gamingonlinux.com/2026/08/arch-linux-aur-hit-with-another-wave-of-malware/
FreeBSD Security in Production: Vulnerability Response and Operational Best Practices
https://klarasystems.com/webinars/freebsd-security-production-vulnerability-response-best-practices/
― join Klara’s Allan Jude and FreeBSD Security Officer Gordon Tetlow for a technical discussion on securing production FreeBSD systems.
2026-09-02 15:00 UTC
US prosecutors charge Atlanta man after #GrapheneOS phone wipes itself during airport search
"The case centers on ... use of GrapheneOS, an open-source operating system that works on Google Pixel phones and lets users enter a passcode to #wipe a device clean."
"The wipe is now central to the case. Prosecutors are treating it as an intentional act to destroy evidence..."
https://www.techspot.com/news/113236-us-prosecutors-charge-atlanta-man-after-grapheneos-phone.html
Will the English government ever learn or is Blairism deep in their souls?
Private Equity and the NHS.
#PrivateEquity #NHS #England #Health #Security #Privacy #Exploitation #ProfitTaking #ShortSighted #NoLessonsLearnt
The PSF is hiring a Security Developer! Help triage vulnerabilities in CPython, fight malware/supply-chain attacks on PyPI, and build tools to keep the #Python ecosystem safe for millions of users 🐍🔒 This is a global, remote, 1 year term role, with the possibility of renewal. #Security
Apply today:
https://pythonsoftwarefoundation.applytojob.com/apply/ei03ut60y4/Security-Developer
httpd(8) gains support for custom HTTP headers https://www.undeadly.org/cgi?action=article;sid=20260725103657 #openbsd #httpd #customheaders #securityheaders #webserver #security #libresoftware #freesoftware
Google now support account recovery with AI and your face. What could possibly go wrong? Google having my face is not just bad enough but chances are high that selfie video may not work in edge cases or network down etc.
https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/
I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.
This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.
Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.
Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...