cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]BLACKVOID ⚫️ » 🌐
@blackvoid@mastodon.social

Testing soon to be published camera.

⚡️ 4K resolution (30fps)
⚡️ PoE and -powered
⚡️ IP67 and IK10 ratings
⚡️ People, vehicle, and license plate detection
⚡️ Smart Smoke detection
⚡️ Face recognition*
⚡️ Automatic defog

* needs to be paired with a Synology DVA model

    [?]Peter N. M. Hansteen » 🌐
    @pitrh@mastodon.social

    [?]Peter N. M. Hansteen » 🌐
    @pitrh@mastodon.social

    [?]knoppix » 🌐
    @knoppix95@mastodon.social

    Amazon’s Ring is partnering with Flock—a network used by ICE, police & feds—in a major privacy red flag 🚨

    Cops can now request Ring footage, expanding AI surveillance into our neighborhoods 🎥
    Flock tracks vehicles & uses biased AI to ID people ⚠️

    Given Ring’s privacy failures, this is deeply alarming 😠

    🔗 techcrunch.com/2025/10/16/amaz

      [?]Open Rights Group » 🌐
      @openrightsgroup@social.openrightsgroup.org

      Message scanning powers are sleeping on the statute book. They must never get activated.

      The UK government has already tried to make Apple put a backdoor in its encrypted services. It's clear they want to recklessly dismantle our cybersecurity protections.

      We must save encryption to 💬

        [?]Open Rights Group » 🌐
        @openrightsgroup@social.openrightsgroup.org

        Powers in the UK Online Safety Act to introduce message scanning technology is far from an online safety measure. It's a gift to predators and stalkers❗

        Forcing a backdoor into encrypted systems so everything we send can be scanned makes us vulnerable to anybody who wants to exploit that weakness.

          [?]Open Rights Group » 🌐
          @openrightsgroup@social.openrightsgroup.org

          Practice Safe Text for Global Encryption Day 🔒

          Messaging apps we use to chat, share and plan shield us from scams, stalking and sextortion.

          But the UK Online Safety Act contains a time bomb that lets the government break encryption for surveillance.

          Find out more about our campaign ➡️ openrightsgroup.org/campaign/s

          Image of a red and yellow message icon as a 3D baloon with a children crossing sign on the skin. Text reads: Save Encryption – Practice Safe Text.

          Alt...Image of a red and yellow message icon as a 3D baloon with a children crossing sign on the skin. Text reads: Save Encryption – Practice Safe Text.

            [?]Open Rights Group » 🌐
            @openrightsgroup@social.openrightsgroup.org

            Encryption scrambles what we send on messaging apps.

            Only the person you’re talking to can make sense of it. That’s your chats, pics and deets for their eyes only.

            This is how we protect kids, parents and people experiencing domestic abuse from those who want to use your private life against you.

              [?]Aaron Toponce ⚛️:debian: » 🌐
              @atoponce@fosstodon.org

              Please stop using Math.floor(Math.random() * range) for generating

              atoponce.github.io/unbiased-ra

                [?]nixCraft 🐧 » 🌐
                @nixCraft@mastodon.social

                Microsoft says it’s starting to test ads inside the Start menu on Windows 11. The software maker will use the Recommended section of the Start menu, which usually shows file recommendations, to suggest apps from the Microsoft Store. Trillion dollar corporation is so poor. They need more money by selling your data to the highest bidder. wtf? theverge.com/2024/4/12/2412864

                The headline reads: Microsoft starts testing ads in the Windows 11 Start menu / The app recommendations from Windows 10 are coming to Windows 11 soon.

                Alt...The headline reads: Microsoft starts testing ads in the Windows 11 Start menu / The app recommendations from Windows 10 are coming to Windows 11 soon.

                  [?]nixCraft 🐧 » 🌐
                  @nixCraft@mastodon.social

                  xubuntu.org might be compromised old.reddit.com/r/Ubuntu/commen

                  The malware check the clipboard for crypto wallet addresses and then replace them with attacker addresses.

                    [?]knoppix » 🌐
                    @knoppix95@mastodon.social

                    ⚠️ ~200,000 Framework Linux laptops shipped with UEFI components that can bypass Secure Boot 🖥️

                    A signed mm command allows memory edits, disabling signature checks & enabling persistent bootkits 🔐
                    Not a breach—an oversight. Fixes are rolling out. Users should update firmware or apply mitigations 🔧

                    @frameworkcomputer

                    🔗 bleepingcomputer.com/news/secu

                      [?]GeneBean » 🌐
                      @genebean@fosstodon.org

                      [?]Tim (Wadhwa-)Brown :donor: » 🌐
                      @timb_machine@infosec.exchange

                      Interesting Git repos of the week:

                      , ,

                        [?]R. Scott (i47i) :freebsd_logo: » 🌐
                        @i47i@hachyderm.io

                        Massive Crypto Scam Bust: $15B Bitcoin Seized

                        The US Department of Justice executed its largest-ever forfeiture action, seizing approximately $15 billion in bitcoin from Chen Zhi, a 37-year-old Cambodian-British tycoon who founded Prince Holding Group.

                        Chen faces charges of wire fraud and money laundering conspiracy for operating forced-labor compounds across Cambodia that ran "pig butchering" cryptocurrency scams, stealing billions from victims worldwide.

                        Prince Group allegedly operated at least 10 scam compounds in Cambodia, with facilities controlling 76,000 fake social media accounts using 1,250 mobile phones.

                        Trafficked workers, lured by fake job advertisements, were held against their will and forced under threat of torture to carry out online fraud, often building fake romantic relationships with targets before convincing them to invest in fraudulent cryptocurrency platforms.

                        At one point, Chen allegedly bragged the operation was generating $30 million daily. Americans lost at least $10 billion to Southeast Asia-based scams in 2024 alone, a 66% increase from 2023.

                        Stolen funds financed luxury purchases including yachts, private jets, vacation homes, and a Picasso painting.

                        The US Treasury sanctioned 146 individuals and entities within the Prince Group network, declaring it a transnational criminal organization. The UK froze 19 London properties worth over $134 million linked to the network.

                        Chen, who served as an adviser to Cambodia's prime ministers and held the honorific title "neak oknha," remains at large and faces up to 40 years in prison if convicted.

                        cnbc.com/2025/10/14/bitcoin-do

                        justice.gov/opa/pr/chairman-pr

                        home.treasury.gov/news/press-r

                        aljazeera.com/news/2025/10/15/

                        npr.org/2025/10/15/nx-s1-55749

                          [?]Peter N. M. Hansteen » 🌐
                          @pitrh@mastodon.social

                          [?]Paco Ho Ho Hope 🎄 » 🌐
                          @paco@infosec.exchange

                          Maybe someone wants to explain the value of stupid AI prompts like the one in this paper. They write:

                          As a highly experienced threat modeler practitioner with over 20 years of experience, you have worked for one of the largest financial institutions in the world.

                          First off, this is a classic mistake: assuming that (a) security is the same everywhere, so what one firm does well, everyone should do the same, and (b) "financial institutions" have the best security, so if you want to have the "best security," you should do what they do.

                          Secondly, I don't get the point of including this fictional 20 years of experience in the prompt. Is that making a material difference? Why not tell it that it has a bazillion years of experience? Why not omit that? Do you want it threat modelling like we did "over 20 years ago" in 2002?

                          Third, this prompt will steer you toward threat models that are very wrong for some orgs. A non-profit, or an educational institution, or a low-stakes governmental agency (like parks & rec) will have very different needs.

                          Lastly, the thing that all AI systems get wrong is they lack any notion of skepticism. Did the architecture diagram not make sense? Did they imply something exists but omit it from the description? Do some aspects of the documentation contradict each other? It never considers the possibility that any inputs are wrong or incomplete, either through ignorance or omission.

                          The advent of LLMs makes everyone think they can do expert-level work in fields where they have no expertise, all because they think they are the first person to try applying an LLM to problems in that domain.

                            [?]Paco Ho Ho Hope 🎄 » 🌐
                            @paco@infosec.exchange

                            @daedalus Generally speaking, “resilience” and “recovery” are the equivalent of “shift security right.” Nobody is interested in prevention any more. Only wonks still say “shift security left.”

                            Modern businesses have realised that only a fraction of the reckless risks actually materialise. So they’re picking up their plates and joining the queue at the all-you-can-eat risk buffet.

                            “Clean up on aisle 5” when things blow up feels cheaper to them than the opportunity cost of a risk they didn’t take. This is why I can’t be CEO.

                              Jean Clean boosted

                              [?]Marcus "MajorLinux" Summers » 🌐
                              @majorlinux@toot.majorshouse.com

                              Coming to a Snapdragon phone near you...maybe...

                              GrapheneOS will drop Google Pixel exclusivity with 'major' Snapdragon-powered devices coming

                              9to5google.com/2025/10/14/grap

                                [?]Chad McCullough » 🌐
                                @cmccullough@polymaths.social

                                Earlier today, I thought my @1password account had been compromised, so I immediately changed the password for my account, which created a new emergency kit. A few hours later, I'm trying to log in and it's failing. For some reason, I'm still able to access my browser extension account and the password is still listed as my original password but not allowing me into my account. The new password that I created isn't working, either.

                                I'm now a bit frustrated, extremely stressed, and not sure what to do. When I created the new password, 1Password asked if I wanted to save it and I, of course, said, yes. Why is the password not in my account and why am I not able to access my account?

                                #1password #security

                                  [?]K~ » 🌐
                                  @karadoc@aus.social

                                  So, another day, another leak of 70000 people's government IDs, from Discord this time.

                                  It seems to me that websites shouldn't be *allowed* to collect personal information unless it is absolutely necessary (an address so that they can delver a package). But we instead seem to be moving in the opposite direction with Governments around the world demanding that various websites collect ID for age verification. This is bad.

                                  arstechnica.com/security/2025/

                                    [?]Pete Orrall » 🌐
                                    @peteorrall@mastodon.bsd.cafe

                                    Wow, the damage from that Red Hat GitLab breach seems to be getting worse by the day. Jeez.

                                    The Crimson Collective, the cybercriminal gang claiming responsibility for breaching the repo and stealing over 500GB of data, now seems to be collaborating with other cybercriminal gangs to extort Red Hat.

                                    From the article, the cybercrim alliance:

                                    "threatens to publish a "multi terabyte of data haul of your most sensitive intellectual property" and accuses Red Hat of failing to safeguard what it claims are trade secrets and personal data, invoking GDPR and US state privacy laws. It also reckons Red Hat's doors were kicked in on September 13 – weeks before the company came clean about the break-in."

                                    theregister.com/2025/10/07/red

                                      [?]Peter N. M. Hansteen » 🌐
                                      @pitrh@mastodon.social

                                      Kestral boosted

                                      [?]GamingOnLinux » 🤖 🌐
                                      @gamingonlinux@mastodon.world

                                      Ouch. This whole ongoing online safety thing is going well isn't it? Who could have guessed that some personal data would end up leaking? Everyone with a brain.
                                      gamingonlinux.com/2025/10/arou

                                        [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                                        @gamingonlinux@mastodon.social

                                        [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                                        @gamingonlinux@mastodon.social

                                        hannah aubry boosted

                                        [?]Tuta » 🌐
                                        @Tutanota@mastodon.social

                                        We've just fought - now Ireland 🇮🇪 wants its own backdoor law. 🔓

                                        But we, together with ~40 orgs, are saying no.

                                        💪

                                        Read our open letter to Ireland: 👉 globalencryption.org/2025/10/o

                                        REMINDER
LEGISLATORS:

A backdoor for the good guys only is not possible.”

                                        Alt...REMINDER LEGISLATORS: A backdoor for the good guys only is not possible.”

                                          [?]gyptazy » 🌐
                                          @gyptazy@gyptazy.com

                                          Automated Security Patch Management for clusters? The next major feature of comes with automated node patching on Proxmox clusters! This becomes real with the upcoming version 1.2.0!


                                          ProxLB with upcoming new major features for Proxmox based clusters

                                          Alt...ProxLB with upcoming new major features for Proxmox based clusters

                                            [?]דער קערפער פֿון השם » 🌐
                                            @dukepaaron@babka.social

                                            "The violence has put local community members in the area on edge just days before the anniversary of the -led attacks on , which triggered the ongoing war in .

                                            “I’m always aware, wherever I am, thinking about my ,” Michele Bat-Or told KOMO News.

                                            A reported rise in globally after Oct. 7, 2023, has left local Jewish people, like Bat-Or, feeling at risk.

                                            “I usually wear a necklace, and I changed to a different symbol,” she continued, “That feels a little bit too unsafe to wear a Jewish star around my neck.”

                                            komonews.com/news/local/seattl

                                              [?]Peter N. M. Hansteen » 🌐
                                              @pitrh@mastodon.social

                                              Chewie boosted

                                              [?]knoppix » 🌐
                                              @knoppix95@mastodon.social

                                              🇬🇧 UK govt demands access to British Apple users' data, reigniting its privacy dispute with Apple 🔐

                                              Apple pulled Advanced Data Protection from UK iCloud, calling the move "gravely disappointing" ⚠️

                                              Critics warn secret orders threaten global security 🕵️

                                              🧑‍⚖️ Legal hearing set for Jan 2026

                                              🔗 bbc.com/news/articles/c740r0m4

                                                Rocketman boosted

                                                [?]Thomas Fricke (he/his) » 🌐
                                                @thomasfricke@23.social

                                                The lethal trifecta for s: private data, untrusted content, and external communication
                                                simonwillison.net/2025/Jun/16/

                                                  [?]Wen » 🌐
                                                  @Wen@mastodon.scot

                                                  Back to top - More...