cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Peter N. M. Hansteen »
@pitrh@mastodon.social

[?]Mark Stosberg »
@markstos@urbanists.social

I'm not sure what's worse: If German American Bank is actually promoting three different look-alike domains and thinks that's good for security or if one or two or more of these are fake and German American Bank hasn't noticed and gotten them taken down yet.

It's like they are training their customers: "If it has German American anywhere in the name and the graphics look the same, assume it's safe!" 🤦‍♂️

Screenshot of search results where germanamerican.com germanamericanonline.com and germanamericabchome.com all appear to be German American Bank.

Alt...Screenshot of search results where germanamerican.com germanamericanonline.com and germanamericabchome.com all appear to be German American Bank.

    [?]Peter N. M. Hansteen »
    @pitrh@mastodon.social

    In one month (2025-09-25), there will be a "Network management with the OpenBSD Packet Filter Toolset" tutorial events.eurobsdcon.org/2025/tal at in To register: 2025.eurobsdcon.org/registrati

      [?]Paco Hope wishes ill for JK Rowling »
      @paco@infosec.exchange

      Every network is standards and regulatory compliant until it gets punched in the face.

      philvenables.com/post/everyone

        [?]Brandon Mitchell »
        @bmitch@fosstodon.org

        If you've ever typoed ghcr to ghrc, particularly with a "docker login" or any automation that performs a login to the container registry, I'm seeing a strong indication that your GitHub credentials have been leaked to a malicious actor.

        bmitch.net/blog/2025-08-22-ghr

          [?]Stefan :veritrek: »
          @stefan@social.stefanberger.net

          This is why you should not hard-code credentials in your source code, but use env. vars or credential managers.

          Looks like someone sent me a mail via a python script. The script had an issue which let the mail content to be the script itself, which contains a token.

          (Or this is phishing wanting me to try the token)

            [?]9x0rg »
            @9x0rg@mamot.fr

            Merci @siosm !

            **OpenSSH client side key management for better privacy and security**

            tim.siosm.fr/blog/2023/01/13/o

              [?]Adrianna Tan »
              @skinnylatte@hachyderm.io

              Chewie boosted

              [?]Jake in the desert »
              @jake4480@c.im

              If you're using Chrome, don't use VPN extensions like FreeVPN.One unless you don't mind it taking screenshots of every website you visit. (Use VPNs like Mullvad or Proton)

              cyberinsider.com/chrome-vpn-ex

                [?]Peter N. M. Hansteen »
                @pitrh@mastodon.social

                [?]Paul Kater - Antifa »
                @paulk@writing.exchange

                Apparently there was a security leak at Paypal, so suggestion to change your password FAST and slap MFA on it if you don't have it yet.
                Do note: passwords can't be longer than 20 characters and a hyphen is not allowed.
                Hello security...

                Boosts appreciated.

                References:

                cybernews.com/security/paypal-

                tomsguide.com/computing/online

                  [?]woollypigs »
                  @woollypigs@sudomakecake.com

                  I just spent waaayyy too long trying to figure out how to change the password for a user in linux and couldn't understand why the <beep> it didn't work, I kept getting an error.

                  To then finally see that I had typed the username wrong ....

                    [?]Em :official_verified: »
                    @Em0nM4stodon@infosec.exchange

                    New Privacy Guides article 🔐✨
                    by me:

                    If you want to keep your password manager local-only, KeePassXC is a great solution!

                    It's free,
                    Open-source,
                    Easy to install and use,
                    Doesn't require an account,
                    Works on Linux, macOS, and Windows,
                    And the team is here! 👉@keepassxc

                    Here's how to set it up with a YubiKey: privacyguides.org/articles/202

                      omg! ubuntu boosted

                      [?]omg! ubuntu »
                      @omgubuntu@floss.social

                      I don't imagine many Linux users would trust a billy-no-name 'free' VPN extension, but friends and family might be less savvy to the dangers - dangers the researchers at Koi Security show are real for 100k users of this Chrome add-on.

                      omgubuntu.co.uk/2025/08/free-v

                        🗳

                        [?]knoppix »
                        @knoppix95@mastodon.social

                        📊 Poll of the Day
                        Past polls got great engagement — let’s go even bigger this time! 🚀

                        This is Mastodon, so we know the audience is a bit more techie... let’s see how that reflects in the results! 👀

                        Which OS are you using right now? 💻
                        (Feel free to reply with why you use it too 👇)

                        Vote + Boost 🔁 = ❤️

                        🪟 Windows:3
                        🍏 iOS, iPadOS, macOS:6
                        🐧 Linux:29
                        🤖 Android:11

                          [?]knoppix »
                          @knoppix95@mastodon.social

                          Apple: spaceship 🛸
                          Microsoft: glass tower 🏢
                          Linux: basement... still runs the internet 🐧😎

                          Root access > real estate.

                          Pic source: reddit.com/r/linuxmemes/commen

                          📸👇

                          Three images showing the headquarters of major operating systems. The top left shows Apple's massive circular "spaceship" HQ labeled "iOS". Top right shows Microsoft's sleek modern building labeled "Windows". Bottom image shows a man standing in a modest home office setup, labeled "Linux", humorously suggesting Linux has no official headquarters.

                          Alt...Three images showing the headquarters of major operating systems. The top left shows Apple's massive circular "spaceship" HQ labeled "iOS". Top right shows Microsoft's sleek modern building labeled "Windows". Bottom image shows a man standing in a modest home office setup, labeled "Linux", humorously suggesting Linux has no official headquarters.

                            [?]Open Rights Group »
                            @openrightsgroup@social.openrightsgroup.org

                            "While the UK may have dropped its demands for Apple to backdoor all of its users across the globe, UK users may still be banned from benefiting from [Advanced Data Protection] encryption."

                            "And if Apple does restore ADP to UK users, there will be serious questions of trust."

                            🗣️ ORG's @jim.

                            news.sky.com/story/uk-drops-ap

                              [?]Peter N. M. Hansteen »
                              @pitrh@mastodon.social

                              [?]Ricardo Martín :bsdhead: »
                              @ricardo@mastodon.bsd.cafe

                              [?]Wen »
                              @Wen@mastodon.scot

                              UK has backed down on demand to access US Apple user data, spy chief says

                              What a surprise! But they have still reduced data security for users in the UK.One correction - this applies to all UK customers and not just new ones.

                              theguardian.com/technology/202

                              From the article, text reads ‘In February, Apple responded by withdrawing the option for its new British customers to enable advance data protection options, saying it was "deeply disappointed" and would never build a backdoor into any of its products.
That meant, uniquely, many UK customers were unable to benefit from end-to-end encryption of services, including the iCloud Drive, photos, notes or reminders, making them more vulnerable to data breaches.
Gabbard said: "Over the past few months, I've been working closely with our partners in the UK, alongside President Trump and Vice-President Vance, to ensure Americans' private data remains private and our constitutional rights and civil liberties are protected."
It is not clear whether the technical capability notice requiring the data access would be withdrawn altogether or altered. It could in theory be limited to allowing access to the data only of UK citizens, although experts cautioned that could be technologically unrealistic. It also raises the danger that other foreign governments could still find a way to use the backdoor.
Neither is it clear whether Apple will be able to offer new UK customers access to its highest levels of data protection again.’

                              Alt...From the article, text reads ‘In February, Apple responded by withdrawing the option for its new British customers to enable advance data protection options, saying it was "deeply disappointed" and would never build a backdoor into any of its products. That meant, uniquely, many UK customers were unable to benefit from end-to-end encryption of services, including the iCloud Drive, photos, notes or reminders, making them more vulnerable to data breaches. Gabbard said: "Over the past few months, I've been working closely with our partners in the UK, alongside President Trump and Vice-President Vance, to ensure Americans' private data remains private and our constitutional rights and civil liberties are protected." It is not clear whether the technical capability notice requiring the data access would be withdrawn altogether or altered. It could in theory be limited to allowing access to the data only of UK citizens, although experts cautioned that could be technologically unrealistic. It also raises the danger that other foreign governments could still find a way to use the backdoor. Neither is it clear whether Apple will be able to offer new UK customers access to its highest levels of data protection again.’

                                [?]Open Rights Group »
                                @openrightsgroup@social.openrightsgroup.org

                                The UK has pulled its order to put a backdoor into Apple's encrypted services.

                                BUT "powers to attack encryption are still on the law books, and pose a serious risk to user security and protection against criminal abuse of our data."

                                🗣️ @jim, ORG Exec Director.

                                bbc.co.uk/news/articles/cdj2m3

                                  [?]Sijmen Mulder 🧑‍💻 »
                                  @sjmulder@bsd.network

                                  What if you could combine the ease of QR codes with the power of curl|bash? Now you can!

                                  codeberg.org/sjmulder/sh-handl

                                    [?]Ukraine News » 🤖
                                    @karakam@mastodon.social

                                    "The best guarantee of security for Ukraine is a strong Ukrainian army," Zelensky said.

                                      [?]Nonilex »
                                      @Nonilex@masto.ai

                                      While en route Friday, voiced hope that “something’s going to come of” the summit & reiterated that could face “very severe” consequences if it does not move to end the . For the first time publicly, Trump also said Friday that he is open to the “possibility” of guarantees for , along with other European countries. Trump cautioned that such protections could not come through , however.

                                        [?]Pete Orrall »
                                        @peteorrall@mastodon.bsd.cafe

                                        The state of packaging seems to be a perpetual mess. There is no standard packaging format among distros (something that I don't think will be resolved any time soon) and I've always viewed third party packaging tools like and with skepticism, mainly from a perspective.

                                        After reading this, I'd rather deal with the perpetual mess of different package managers than the unraveling security headache that is Flatpak.

                                        linuxjournal.com/content/when-

                                          [?]Peter N. M. Hansteen »
                                          @pitrh@mastodon.social

                                          [?]mle✨ »
                                          @mle@infosec.exchange

                                          there's lots of research that meets this criteria, but this is specifically the piece I had in mind when I wrote yesterday about reading excellent work that makes you feel energized.

                                          go read it! I guarantee you'll learn something.

                                          censys.com/blog/2025-state-of-

                                            [?]Peter N. M. Hansteen »
                                            @pitrh@mastodon.social

                                            Friends, it finally happened. On August 7th, 2025, the number of spamtraps intended to fool spammers rolled past the number of inhabitants in my home country of Norway. It's time for a retrospective.

                                            Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off? nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

                                              [?]BastilleBSD :freebsd: »
                                              @BastilleBSD@fosstodon.org

                                              BastilleBSD = FreeBSD hardened + automation ready.

                                              Ship with sane default.
                                              Build on a secure base.
                                              Run anywhere you trust.

                                                [?]chfkch :nixos: :rust: »
                                                @chfkch@ruhr.social

                                                @stalwartlabs
                                                Take their money, but do noz cooperate with these thieves from MS.

                                                Pretty please don't become evil.

                                                  Neil Brown boosted

                                                  [?]Frederik Borgesius »
                                                  @Frederik_Borgesius@akademienl.social

                                                  NL. Horrible data breach.

                                                  The data of 485,000 women who participated in the population screening for cervical cancer has been stolen via a hack. Not just personal information, such as name and address, was involved. Official identification numbers and test results were also captured.

                                                  rtl.nl/nieuws/binnenland/artik

                                                    [?]Lobsters » 🤖
                                                    @lobsters@mastodon.social

                                                    [?]Peter N. M. Hansteen »
                                                    @pitrh@mastodon.social

                                                    Back to top - More...