cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
@nemo@mas.to

Verified Apps (Privacy Guides) is an app‑signing certificate hash viewer/verifier that checks installed apps or APKs against a crowdsourced DB. MIT • Last update 2026-06-13. Learn more: github.com/privacyguides/verif 🔐📱

apt.izzysoft.de/fdroid/index/a

    Chewie boosted

    [?]Freezenet » 🌐
    @freezenet@noc.social

    Your Question: Will Bill C-34 Affect Mastodon?

    One of the questions we got is whether or not Mastodon is affected by Bill C-34. We'll make an attempt to answer that today.

    freezenet.ca/your-question-wil

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      sqrt(-1) boosted

      [?]GrapheneOS » 🌐
      @GrapheneOS@grapheneos.social

      GrapheneOS version 2026061800 released:

      grapheneos.org/releases#202606

      See the linked release notes for a summary of the improvements over the previous release.

      Forum discussion thread:

      discuss.grapheneos.org/d/36568

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]Sem Schilder :t_blink: » 🌐
        @xvilo@mastodon.org.uk

        Do we make 2FA mandatory for everyone? Kinda want to do this

          [?]LWN.net » 🌐
          @lwn@fedi.lwn.net

          Everything security at PyCon US 2026

          lwn.net/Articles/1078361/

            [?]Python Software Foundation » 🌐
            @ThePSF@fosstodon.org

            Did you miss this year? 🐍🛡️ Here's a summary of everything security at @pycon US 2026, including the new security talk track, an update from PSF security engineers, and notes from the OSS maintainer security open space.

            pyfound.blogspot.com/2026/06/e

              [?]LWN.net » 🌐
              @lwn@fedi.lwn.net

              [?]GrapheneOS » 🌐
              @GrapheneOS@grapheneos.social

              GrapheneOS version 2026061600 released:

              grapheneos.org/releases#202606

              See the linked release notes for a summary of the improvements over the previous release.

              Forum discussion thread:

              discuss.grapheneos.org/d/36483

                [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                @bobdahacker@infosec.exchange

                ✈️ New Blog Post: Your Boarding Pass Is a Skeleton Key. Frontier Airlines Doesn't Care.

                Frontier's mobile API returns full passport numbers, home addresses, children's DOB, credit card details, and KTNs for any booking. The only auth? A PNR and last name. Printed on every boarding pass.

                Reported March 3rd. 105 days later, still live. They fixed the least important vuln and ghosted me on the rest. They also updated the website code and somehow made the leaks worse.

                Full writeup: bobdahacker.com/blog/frontier-

                  Tim Hergert boosted

                  [?]Pete Orrall [Pete/Pete] » 🌐
                  @peteorrall@mastodon.bsd.cafe

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  [?]Emeritus Prof. Christopher May » 🌐
                  @ChrisMayLA6@mastodon.me.uk

                  I'm with Frances Ryan, there is a false distinction drawn by our political class between threats to security that emanate from the global system & those that stem from how UK society is organised.

                  The argument that we necessarily need to choose between military expenditure & welfare spending (wilfully) misunderstands the *real* threats to the UK population.

                  Rather we should see the UK's 'security' as including the plight of the population.


                  theguardian.com/commentisfree/

                  Threats to a nation do not always come from enemies across an ocean. Often, the danger is closer to home: the way an economy and society are rigged against a populace that increasingly feels divided, alienated and without the means to live a decent life. And the bad actors, both in the UK and abroad, who are willing to stoke real grievances for their own distorted ends. This is not the kind of safety that will be gained with drones and missiles – think social housing, healthcare and education instead – but it is no less integral to Britain’s wellbeing.

                  Alt...Threats to a nation do not always come from enemies across an ocean. Often, the danger is closer to home: the way an economy and society are rigged against a populace that increasingly feels divided, alienated and without the means to live a decent life. And the bad actors, both in the UK and abroad, who are willing to stoke real grievances for their own distorted ends. This is not the kind of safety that will be gained with drones and missiles – think social housing, healthcare and education instead – but it is no less integral to Britain’s wellbeing.

                    [?]Mysk🇨🇦🇩🇪 » 🌐
                    @mysk@mastodon.social

                    Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps.

                    Mullvad is aware of this issue. It is described in this blog:

                    mullvad.net/en/help/why-wiregu

                    You can download Loupe here:
                    apps.apple.com/app/id6766152470

                    Proton VPN tunnel internal IP as shown in the Settings app

                    Alt...Proton VPN tunnel internal IP as shown in the Settings app

                    Proton VPN tunnel internal IP as shown in Loupe

                    Alt...Proton VPN tunnel internal IP as shown in Loupe

                    Mullvad VPN tunnel internal IPs as shown in the Settings app

                    Alt...Mullvad VPN tunnel internal IPs as shown in the Settings app

                    Mullvad VPN tunnel internal IPs as shown in Loupe

                    Alt...Mullvad VPN tunnel internal IPs as shown in Loupe

                      [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
                      @bobdahacker@infosec.exchange

                      ⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.

                      Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.

                      Full writeup: bobdahacker.com/blog/fifa-hack

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                        @gamingonlinux@mastodon.social

                        [?]LWN.net » 🌐
                        @lwn@fedi.lwn.net

                        BrianKrebs boosted

                        [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                        @gamingonlinux@mastodon.social

                        [?]Peter N. M. Hansteen » 🌐
                        @pitrh@mastodon.social

                        sus boosted

                        [?]Freezenet » 🌐
                        @freezenet@noc.social

                        Government Rolling Age Verification and Online Harms into One Giant Mess

                        Reports suggest that the Canadian government is introducing a bill that would combine online harms and age verification legislation.

                        freezenet.ca/government-rollin

                          Tim Hergert boosted

                          [?]Metin Seven » 🌐
                          @metin@graphics.social

                          Meme, showing a continuous circle of data breach messages from corporations…

Ahaha you're not gonna believe this but we had a bit of a data breach.

Your data is probably for sale online now.

That means someone could easily impersonate you.

Going forward we're gonna need more of your data to make sure its you.

                          Alt...Meme, showing a continuous circle of data breach messages from corporations… Ahaha you're not gonna believe this but we had a bit of a data breach. Your data is probably for sale online now. That means someone could easily impersonate you. Going forward we're gonna need more of your data to make sure its you.

                            [?]LWN.net » 🌐
                            @lwn@fedi.lwn.net

                            [?]Miron 🇪🇺 » 🌐
                            @hmiron@fosstodon.org

                            Dealing with passkeys is kind of hassle for me. Does it get better after a while?

                            I’m asking because I started selfhosting PocketID and it ONLY has passkeys, no passwords and I have to decide if I keep it or not.

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              Larson: Are insecure code completions a vulnerability?

                              lwn.net/Articles/1077413/

                                [?]Tim Mak » 🌐
                                @timkmak@journa.host

                                The Arsenal, the sister publication of The Counteroffensive, conducted an with U.S. Senator Ruben Gallego at the Black Sea Forum about and how they can be supported now and after the war. Watch it at the link! counteroffensive.news/p/war-th

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [$] Eliminating long-lived credentials with trusted publishing

                                  Trusted publishing is an authentication mechanism that relies on short-lived credentials to reduce the risk of supply-chain attacks. At the 2026 Open Source Summit North America, M [...]

                                  lwn.net/Articles/1076205/

                                    [?]LWN.net » 🌐
                                    @lwn@fedi.lwn.net

                                    [?]Aaron Toponce ⚛️:debian: » 🌐
                                    @atoponce@fosstodon.org

                                    I think I've mentioned this before, but I'm toying around with adding keyboard patterns in my password generator.

                                    The algorithm:

                                    1. Pick a random key.
                                    2. Identify adjacent keys horizontally and vertically.
                                    3. Pick a random adjacent key.
                                    4. Repeat until entropy target is reached.

                                    72-bit examples:

                                    Colemak: 098(){]|}+}[{]\\]|}|}[{{:YU8u
                                    Dvorak: 5$#$p>EJkXKJkUpyp>#2#>pYF
                                    QWERTY: XZxcxzxZXSXsde3>?.?:?>?:"[}+
                                    Workman: _+-0["['I"['iO>oEnFuENfNyn

                                      [?]mc.fly [he/him] » 🌐
                                      @mcfly@milliways.social

                                      Do i have someone in my peer group that could give a 4 hrs workshop on target Information Gathering at a company? Ideally based on Kali linux or alike.

                                        [?]LWN.net » 🌐
                                        @lwn@fedi.lwn.net

                                        [?]heise online » 🌐
                                        @heiseonline@social.heise.de

                                        Schweizer Rüstungsunternehmen RUAG zahlt Lösegeld an Cybergang

                                        Nachdem die Cybergang Akira bei der RUAG-Tochter Mecanex USA Daten abgezogen hat, hat RUAG ein Lösegeld gezahlt.

                                        heise.de/news/Schweizer-Ruestu

                                          Wen boosted

                                          [?]Mark » 🌐
                                          @paka@mastodon.scot

                                          UK: Palantir break clause

                                          Cross party committee of MPs has just officially recommended that the government trigger the break clause in 's contract.

                                          The report states ...

                                          [1/2]

                                            WTL boosted

                                            [?]Mysk🇨🇦🇩🇪 » 🌐
                                            @mysk@mastodon.social

                                            Introducing Loupe, our latest privacy app for iOS. Discover what apps can learn about you just by reading data your iPhone already exposes, such as your languages, installed apps, device sensors, and much much more

                                            Loupe is free, private, and open source. Give it a try 👇

                                            apps.apple.com/app/id6766152470

                                            Link to source code:

                                            github.com/mysk-research/loupe

                                            Banner for Loupe

                                            Alt...Banner for Loupe

                                              [?]LWN.net » 🌐
                                              @lwn@fedi.lwn.net

                                              [?]LWN.net » 🌐
                                              @lwn@fedi.lwn.net

                                              One step forward, two steps back on CA age bill (EFF Deeplinks Blog)

                                              lwn.net/Articles/1076377/

                                                [?]LWN.net » 🌐
                                                @lwn@fedi.lwn.net

                                                [?]Exquisite.social » 🌐
                                                @exquisite@exquisite.social

                                                Mastodon Update :flan_hacker:

                                                We have completed the update to Mastodon v4.5.11 which contains some security fixes. Protecting our community is paramount to us - so we'd rather not wait until the wee little hours.

                                                  [?]LWN.net » 🌐
                                                  @lwn@fedi.lwn.net

                                                  Back to top - More...