cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This dumb password rule is from Parnassus Investments.
A site responsible for protecting your investments limiting you to a
four character range with a bunch of other stupid rules? Shocking.
https://dumbpasswordrules.com/sites/parnassus-investments/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
The scam email I wrote about last week (https://blog.kamens.us/2026/06/11/hilariously-bad-scam-email-obviously-written-by-ai/) is apparently part of an ongoing campaign. They're getting better at it, but it's not clear what their end goal is.
Ref: https://blog.kamens.us/2026/06/15/scam-email-i-wrote-about-last-week-is-part-of-an-ongoing-campaign/
#infosec #spam #scam #phishing
Using Loupe, we found out that Proton VPN is the only VPN that prevents internal tunnel IP fingerprinting by assigning 10.2.0.2 to all users. Other VPNs, such as Mullvad, assign a static and unique IP per session. This allows iOS apps to track user sessions across apps.
Mullvad is aware of this issue. It is described in this blog:
https://mullvad.net/en/help/why-wireguard
You can download Loupe here:
https://apps.apple.com/app/id6766152470
This dumb password rule is from MKB NetBankár.
It only accepts lowercase letters, uppercase letters and numbers (any
other character counts as forbidden character).
Also, if your password contains any invalid character, it will get
marked as "Identical to the former 10 passwords".
To make it more fun, during the registration, it allows to se...
https://dumbpasswordrules.com/sites/mkb-netbankar/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
⚽ New Blog Post: I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
Registered on FIFA's public Agent Platform, got added to their Entra tenant, and accessed the Streaming Management panel for every live World Cup 2026 match. RTMP ingest URLs, stream keys, all five camera angles. Confirmed live in VLC. An attacker could have replaced live camera feeds on TV worldwide.
Full writeup: https://bobdahacker.com/blog/fifa-hack
#InfoSec #BugBounty #ResponsibleDisclosure #FIFA #WorldCup #Security #CyberSecurity #RTMP #BrokenAccessControl
This dumb password rule is from INSS (Instituto Nacional do Seguro Social).
The National Social Security Institute (INSS) is an autarchy of the Government of Brazil linked to the Ministry of Economy that receives the contributions for the maintenance of the General Social Security System, responsible for the payment of pensions, maternity pay, death pay, sickness pay, ac...
https://dumbpasswordrules.com/sites/inss-instituto-nacional-do-seguro-social/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from WellStar MyChart.
Your password must be between 8 and 20 characters.
https://dumbpasswordrules.com/sites/wellstar-mychart/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Broadcom.
- Between 8 and 50 characters
- Can't contain any substring of length 3 or more from your email address.
- At least 1 uppercase letter, lowercase letter, and digit, and special character.
- Oh right, to really mess with password managers: no more than 10 special characters and pasting into the pa...
https://dumbpasswordrules.com/sites/broadcom/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Afraid.org FreeDNS.
Password must be between 4 and 16 characters long
https://dumbpasswordrules.com/sites/afraid-org-freedns/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
frequently, i’m given a heavily locked down windows machine i can’t install any software on or don’t have admin too etc.
my default pentesting technique in this situation - check to see if powershell is still accessible and you can run scripts. most of the time it is.
if it is, you have a port scanner, domain enumeration suite, port 80/443 screenshotter etc. use it.
This dumb password rule is from PCPartPicker.
There are no rules for passwords. Passwords can be any length (including one character)
of any complexity. No password change confirmation emails are sent.
https://dumbpasswordrules.com/sites/pcpartpicker/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Copyright.gov.
I wonder if they cooperate with NSA to enforce the password rules.
https://dumbpasswordrules.com/sites/copyright-gov/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
PSA regarding a change in how Secure Boot will work in Fedora soon. The change isn't urgent, but it is something you should take a look at.
If you have any questions about this, please ask in our forum. 🙏
➡️ https://fedoramagazine.org/expiration-of-microsoft-secure-boot-keys/
Forum: https://discussion.fedoraproject.org/c/ask/6
#Fedora #Linux #OpenSource #Cybersecurity #InfoSec #SecureBoot
It's been a while, so how about a Plexfiltration update?
Some orgs have 'fixed their shit', but the vast majority have continued to send me emails containing PII every day.
The hotel booking system still does, for example. Pretty much all of the cyber security companies do as well.
Occasionally, new ones will pop up - like today, I got some vacation booking thing that had replaced the email with $randomNumber@deleteduser.com - this one stood out because the full name of the deleted user was still present in the email.
Password reset was possible, and offered access to:
- Name
- Home Address
- Email
- Phone
- Order History
- Holiday Plans
They have been advised.
This dumb password rule is from Digital Credit Union (DCU).
Must be between 8 and 40 characters, uppercase and lowercase, one number, one special character... whatever. But special characters are limited to -#$%+?~*!. (and space). WHY?!
https://dumbpasswordrules.com/sites/digital-credit-union-dcu/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Certsign - the Dutch government goto-CA fucked up and accidentally kinda revoked an intermediate CA certificate.
Basically everything government related is affected.
(Translation in threat)
Added books big tracker link: https://bugzilla.mozilla.org/show_bug.cgi?id=2046230
This dumb password rule is from Alibaba.
- At least 2 uppercase letters
- Plus 2 lowercase letters
- Plus 2 numbers
- Plus 2 punctuation marks
Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](https://www.youtube.com/watch?v=f3lUEnMaiAU),
then password rules can be equally intelligent too.
Also, ...
https://dumbpasswordrules.com/sites/alibaba/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Onleihe.
Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords
https://dumbpasswordrules.com/sites/onleihe/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Tangerine.
Your PIN can only contain numbers and must be between 4 and 6 numbers.
https://dumbpasswordrules.com/sites/tangerine/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Hey, can I get some legal experts in here to tell me I’m wrong about what I think this ruling means? Also, how does international case precedence work?
A #German court has ruled that Google is directly liable for what its #AI #search overviews say. Previous case law shielding search engine operators from liability doesn't apply to AI overviews.
That’s freaking massive. Google’s AI responses are wrong almost 10% of the time, make up sources, and infer facts not in evidence, and cause real harm. Germany says publisher immunity does not convey when the company product, the ai, is stating things as fact.
Losing publisher #immunity is a really, really big deal. Especially if we can get a similar ruling in the US, and if this ruling flows into EU precedent.(I don’t know how any of that works)
In any case, go German law writers.
#infosec #truthiness #llm https://the-decoder.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-answers/
Interesting article to read over the latest npm / python Malware.
Malware is now using triggering terms from biological and nuclear background to prevent analysis by LLM/ AI
#InfoSec #cyber #cybersecuriy #ai
H/t @spoonz
This dumb password rule is from Canada Revenue Agency.
Password checklist:
- 8 to 16 characters
- At least 1 upper-case character
- At least 1 lower-case character
- At least 1 digit
- No space
- No accented characters
- No special characters except: dot (.), dash (-), underscore (_), and apostrophe (')
- No more than 4 consecutive identical characters
https://dumbpasswordrules.com/sites/canada-revenue-agency/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Aetna Health Insurance.
- Password cannot be longer than 20 characters
- Password cannot have spaces and more 2 characters repeated in a row
- Password cannot have user's first name, last name or username
https://dumbpasswordrules.com/sites/aetna-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from United Parcel Service of America.
Your password must:
- Be between 7 and 26 characters long
- Contain at least 1 lowercase character
- Contain at least 1 uppercase character
- Contain at least 1 number character
- Contain one special character (!@#$%*)
- NOT contain first or last name
- NOT contain UPS user ID
- NOT contain email...
https://dumbpasswordrules.com/sites/united-parcel-service-of-america/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
New.
Infoblox: Residential Proxies in the Wild https://www.infoblox.com/blog/threat-intelligence/residential-proxies-in-the-wild/ @InfobloxThreatIntel #infosec #threatintel #threatintelligence #botnet
Reading this I wonder how we came to make so many wrong turns.
Every time I hear someone sing the praise of "cloud" deployments, "ai" agents, and vscode with 50 plugins I want to say "you have no idea what you're even doing". But then mostly don't because it'd be futile anyway.
#infosec
https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
Amnesty International is recruiting for a technologist to join their Security Lab team. Various international locations can be considered for the role: Bangkok; Berlin; Colombo; Johannesburg; London; Mexico City and Nairobi. Closing date is 21 June.
More info:
https://careers.amnesty.org/jobs/vacancy/technologist-4246/4274/description/
This dumb password rule is from AOL.
Between 8 and 16, so I can't go up to 20.
https://dumbpasswordrules.com/sites/aol/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Vistara.
Password must contain:
- 8 to 12 Characters.
- At least one lowercase and uppercase letter.
- At least one numeric character.
- At least one special character (!, @, #, $, %, %, ^, &, +, =).
Must not contain space, first or last name.
https://dumbpasswordrules.com/sites/vistara/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from amaysim.
Passwords must be 6-15 characters. If you enter more than 15 characters at signup, there is no error,
but the system apparently silently truncates to 15 characters. So of course, logging in subsequently
fails if you enter the untruncated password. How convenient.
https://dumbpasswordrules.com/sites/amaysim/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from MKB NetBankár.
It only accepts lowercase letters, uppercase letters and numbers (any
other character counts as forbidden character).
Also, if your password contains any invalid character, it will get
marked as "Identical to the former 10 passwords".
To make it more fun, during the registration, it allows to se...
https://dumbpasswordrules.com/sites/mkb-netbankar/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from NBC (National Bank of Canada).
- Password length must be 8 to 25 characters
- Password must contain at least one lower letter (any position)
- Password must contain at least one digit (any position)
- Password cannot contain spaces.
- Copy/paste is not allowed when trying to set a new password
https://dumbpasswordrules.com/sites/nbc-national-bank-of-canada/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
If you are a US-based organisation working in support of human rights and/or the environment looking to swiftly migrate your server infrastructure and data to safer soil, get in touch.
We have extensive experience helping frontline at-risk orgs find a safer home for their work, on their terms and under their control, with a particular focus on hosting in jurisdictions with robust data-protection laws.
Pass it on.
Current Mikrotik home firewall strategy: * Add log rules to the end of firewall chains bonus round: move as much traffic from ipv4 to ipv6. The majority of the IoT are a lost cause there however.
* Stream logs and parse via script (pending: grafana dashboard). The script shows all packets that hit the log rules before the default-allow at the end
* add rules to cover excisting traffic (or fix shit if broken or sending unwanted packets)
* Optimize
* After a sufficient time period of no log rule hits, change the log rules to default-drop
This dumb password rule is from Delta.
It's a good thing they don't store personal information such as your passport number... oh wait.
https://dumbpasswordrules.com/sites/delta/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
Introducing Loupe, our latest privacy app for iOS. Discover what apps can learn about you just by reading data your iPhone already exposes, such as your languages, installed apps, device sensors, and much much more
Loupe is free, private, and open source. Give it a try 👇
https://apps.apple.com/app/id6766152470
Link to source code:
This dumb password rule is from MyAnimeList.
Password must be between 6 - 50 characters long and contain at least two of the following: uppercase, lowercase, numbers and symbols.
https://dumbpasswordrules.com/sites/myanimelist/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Alibaba.
- At least 2 uppercase letters
- Plus 2 lowercase letters
- Plus 2 numbers
- Plus 2 punctuation marks
Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](https://www.youtube.com/watch?v=f3lUEnMaiAU),
then password rules can be equally intelligent too.
Also, ...
https://dumbpasswordrules.com/sites/alibaba/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from LibraryThing.
"Your password cannot be longer than 20 characters"
https://dumbpasswordrules.com/sites/librarything/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
If there is anyone out there doing any #FediHire stuff and is looking for someone to help support their #infosec programs, I would love to help.
Looking for anything at this point but compliance, vendor management, supply chain and dependency management, app sec, assessment prep and support, risk management, and AI governance/compliance.
I hold a current CISM certification and available for contract, fte, or consulting roles. I am eligible for fed clearance and qualified for ISSM roles.
Details in bio, thanks!
This dumb password rule is from Coventry Building Society.
Password has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity.
https://dumbpasswordrules.com/sites/coventry-building-society/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Paytm.
Password must be between 5 and 15 characters. Also, spaces don't count
as characters.
https://dumbpasswordrules.com/sites/paytm/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from La Banque Postale.
Password must be 6 digits and entered on custom pad.
https://dumbpasswordrules.com/sites/la-banque-postale/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Itaú Bank.
I know, it's in spanish, let me translate this monstrosity for you.
- Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
- You must use 8 characters.
- The password must contain at least one letter and at least one number.
- ...
https://dumbpasswordrules.com/sites/itau-bank/
#password #passwords #infosec #cybersecurity #dumbpasswordrules