cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Commsec.

Another financial institution with short password requirements. They also block pasting in to the field, making it a pain to use a password manager.

dumbpasswordrules.com/sites/co

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Ancestry.

    Password:
    - Must be at least 8 characters long
    - Must contain at least 1 number
    - Must contain at least 1 letter or special character
    - Must not be a well known or common password

    dumbpasswordrules.com/sites/an

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from Standard Chartered Bank.

      - Between 8 to 16 characters
      - Only letters and/or numbers

      dumbpasswordrules.com/sites/st

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from El Corte Ingles.

        Min 6 and max 8 characters for password! Can't contain anything
        different than letters and numbers. Apart, the email address must have
        at least 8 characters (sorry million dollar domain owners! :D)

        dumbpasswordrules.com/sites/el

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Sparkasse.

          „Sparkasse“ is a group of banks which is pretty popular in Germany. It
          calls its passwords „PIN“ („persönliche Identifikations-Nummer“ —
          personal identification number), the rules are pretty horrific and its
          not even a number, even though it is called as such! Here is a
          screenshot from the branch...

          dumbpasswordrules.com/sites/sp

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Coventry Building Society.

            Password has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity.

            dumbpasswordrules.com/sites/co

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Alibaba.

              - At least 2 uppercase letters
              - Plus 2 lowercase letters
              - Plus 2 numbers
              - Plus 2 punctuation marks

              Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](youtube.com/watch?v=f3lUEnMaiAU),
              then password rules can be equally intelligent too.

              Also, ...

              dumbpasswordrules.com/sites/al

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Vivo.

                The password must only contains numbers and the max length is 6.

                dumbpasswordrules.com/sites/vi

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Craigslist.

                  No minimum character limit meaning you can go as low as 5 characters for a password

                  dumbpasswordrules.com/sites/cr

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Kryterion Webassessor.

                    I was quite surprised to see this when I was registering for my Google Professional Cloud **Security** Engineer certification. Nice part is that they **don't allow quotes** as special character, so I assume there possibly might be some other issues on their backends. :-)

                    dumbpasswordrules.com/sites/kr

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Nevada DMV.

                      - Password length must be exactly 8 characters in length
                      - Password must contain at least one letter (any position)
                      - Password must contain at least one number (any position)
                      - Password must contain one of the following special characters: @ # $
                      - Password is not case sensitive

                      dumbpasswordrules.com/sites/ne

                        [?]Dumb Password Rules » 🤖 🌐
                        @dumbpasswordrules@infosec.exchange

                        This dumb password rule is from Interactive Brokers.

                        Usual dumb password restrictions, but this one has incredibly dumb **username**
                        restrictions too:

                        **Username:**
                        - **Length of 8 or 9 letters and numbers**
                        - **Contain at least 3 letters and 3 numbers**
                        - Begin with a letter
                        - Lower case only, no spaces, no special characters

                        **Password:**
                        - Can...

                        dumbpasswordrules.com/sites/in

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from USAA Bank.

                          Password cannot be longer than 12 characters but they don't tell you that until after you try a new password. To make up for this fact they've added dubious additional security features on top of this weak foundation.

                          dumbpasswordrules.com/sites/us

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from NBA Store.

                            - Password cannot be longer than 20 characters

                            dumbpasswordrules.com/sites/nb

                              [?]Fedi.Garden » 🌐
                              @FediGarden@social.growyourown.services

                              FreeRadical.zone is a Mastodon server themed around infosec and privacy and technology and leftward politics and cats and dogs.

                              This server has been online since 2017.

                              :Fediverse: freeradical.zone

                              You can find out more at freeradical.zone/about or contact the admin account @tek

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Sharekhan.

                                - At least 8 characters.
                                - At most 12 characters.

                                dumbpasswordrules.com/sites/sh

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from PayPal.

                                  Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...

                                  The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!

                                  dumbpasswordrules.com/sites/pa

                                    [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                    @MissConstrue@mefi.social

                                    Remember yesterday when I told y’all some of the redactions were easy to remove? The Guardian has words.

                                    People examining documents released by the Department of Justice in the Jeffrey Epstein case discovered that some of the file redaction can be undone with Photoshop techniques, or by simply highlighting text to paste into a word processing file.

                                    Y’all, they used Acrobat. Because the fired all the people who normally sanitize data, and told 1200 agents not trained in infosec to hide anything that might embarrass the , and this is the result.

                                    Have fun y’all, let’s see who we can embarrass.

                                    theguardian.com/us-news/2025/d

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from Mobility.

                                      The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
                                      The password has to be exactly 6 digits long, only numbers allowed.

                                      dumbpasswordrules.com/sites/mo

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Easybank (Austrian direct bank).

                                        - At least 8 and at most 16 (!) characters
                                        - **Must start with 5 digits (do we really want to know what's going on there?)**
                                        - At least one uppercase and one lowercase letter
                                        - (Some) special characters are permitted, most are not
                                        - "Simple" patterns are prohibited
                                        - PINs are case sensitive (at l...

                                        dumbpasswordrules.com/sites/ea

                                          [?]rk: it’s hyphen-minus actually » 🌐
                                          @rk@mastodon.well.com

                                          Any time you see the word “secure” in an edge device name, you should read it the same way you read “democratic” in a country’s name.

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Netflix.

                                            [The help page](help.netflix.com/de/node/54078)
                                            and the [password reset page](netflix.com/password) say:

                                            Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.

                                            dumbpasswordrules.com/sites/ne

                                              [?]FlohEinstein » 🌐
                                              @FlohEinstein@chaos.social

                                              Why use a URL shortener when you can use a phishy URL extender?

                                              phishyurl.com/

                                              Keep your security people alert and awake, generate phishing-looking redirecting links

                                              https://cheap-bitcoin.online/backdoor-loader/rat-controller/malware_patch.exe?cachecontrol=inject&cookievalue=steal&file=poison&id=fc3188fb&payload=%28function%28%29%7B+return+Math.floor%284.9%29%3B+%7D%29%28%29%3B&port=scan

                                              Alt...https://cheap-bitcoin.online/backdoor-loader/rat-controller/malware_patch.exe?cachecontrol=inject&cookievalue=steal&file=poison&id=fc3188fb&payload=%28function%28%29%7B+return+Math.floor%284.9%29%3B+%7D%29%28%29%3B&port=scan

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Mindware.

                                                You "*may use special characters*", but only some of them - and we won't
                                                necessarily tell you which ones.

                                                dumbpasswordrules.com/sites/mi

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Telcel.

                                                  - The username is the cell phone number (easy to get)
                                                  - The company creates a password between 8 and 12 characters for you
                                                  - Password must contain at least 1 capital letter and no special characters

                                                  dumbpasswordrules.com/sites/te

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from Inpost.

                                                    Allows between 8 to 16 characters. Password is being used to log in and view packages sent to you, or for shipping packages.

                                                    dumbpasswordrules.com/sites/in

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Wells Fargo.

                                                      Your password must be between 8-32 characters long and inexplicably doesn't accept `-` but does seemingly accept other special characters.

                                                      dumbpasswordrules.com/sites/we

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from GoFundMe.

                                                        - At least one uppercase and one lowercase letter
                                                        - At least one number and one special symbol
                                                        - Does not specify which characters are considered special symbols; did not recognize spaces as special symbols

                                                        dumbpasswordrules.com/sites/go

                                                          [?]Rachel [She/Her] » 🌐
                                                          @rachel@transitory.social

                                                          Ok, looking at ssh certs a bit more...

                                                          using step-ca, ssh cert can be issued, but I would need a different provisioner to do it, since annoyingly ACME can't issue ssh certs.

                                                          That means clients will need the step CLI installed to request certs, not that big of a deal, but which provisioner?

                                                          Looking at the list of provisioners, my options are JWK, OIDC, or X5C. The JWT and OIDC will require more work and also require some form of secret to be shared.

                                                          The X5C provisioner actually looks good. They warn that it isn't recommended to use certs signed by step-ca itself because it can function as a form of privilege escalation.

                                                          But I think I can avoid that by using a restrictive template that limits it to only issuing host-certs, with SANs restricted to the same SANs as the x509 used to authenticate.

                                                          I'll use OIDC for shorter lived user-certs.

                                                          I'll keep pubkey auth enabled as a backup, since some of these systems would be used as jump boxes to troubleshoot OIDC/CA issues.

                                                          Oh and I should setup a new intermediate for the SSH host/user certs.

                                                            🗳

                                                            [?]Rachel [She/Her] » 🌐
                                                            @rachel@transitory.social

                                                            What to do with TOTP MFA credentials these days?

                                                            I currently do #1, but it adds complexity.

                                                            I've seen some recommends for #2, which surprises me a bit. But then again a password manager failure is like catastrophic either way. Also if I think about it, based on the logic of option 1, I shouldn't have the recovery codes in the pw manager db either.

                                                            Store them in another app/password manager (synced):11
                                                            Store them in your password manager next to your passwords:16
                                                            Store them in another app (not-synced):4

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from TwinSpires.

                                                              You can gamble on our site. We'll keep your money secure with a 12 character password!

                                                              dumbpasswordrules.com/sites/tw

                                                                [?]Tom » 🌐
                                                                @pertho@mastodon.bsd.cafe

                                                                This might be a bit of a long shot, but does anyone have some great examples of questions and answers pertaining to and that you'd get, as a company from your clients?

                                                                I know in the past I've had clients ask for stuff like longer log or backups retention, etc. but what sorts of questions are usually expected?

                                                                Thanks very much in advance and please boost far and wide!

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from GameFly.

                                                                  Password is 6-12 characters with no other restrictions. You can easily do 6 numbers, 6 lowercase letters, etc.

                                                                  dumbpasswordrules.com/sites/ga

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Williams-Sonoma.

                                                                    25 maximum characters and disallowing some specials.

                                                                    dumbpasswordrules.com/sites/wi

                                                                      [?]Mike Sheward » 🌐
                                                                      @SecureOwl@infosec.exchange

                                                                      Here is a brief summary of the AI/AI adjacent vulnerability-types I've noted in pen tests over the last year (some are AI specific, others could happen with any software project, I just happened to have found them in the context of an AI one):

                                                                      - code injection type things: in order to better understand how they are making decisions, pretty much everything you send to an LLM is logged. I've had more than one successful SSRF this year simply by including code, or a link to code in my LLM convo. Sometimes it's self inflicted, in real time, other times it happens hours later when a human is reviewing the logs and wondering wtf is going on.

                                                                      - mixing in outside knowledge: was able to get what was a closed loop transcription tool to go look something up and put it in the transcription. Could likely be used maliciously.

                                                                      - Github storage of training data: for some reason, AI-tool developers seem intent on storing emails, documents, spreadsheets, whatever it is they are training their stuff on in public Github repos. Have easily found 8 or 9 examples of this in 2025.

                                                                      - letting the AI do authorization: if you give AI access to 'all of the data' and expect it to self manage who is authorized to see what based on a prompt, you are in for a bad day/week/month. People are doing this.

                                                                      - Exposure of third party Oauth tokens etc: Most of these agents etc are connecting to things like Google Workspace, Exchange, to read emails, documents etc. For some reason, people seem to do a very poor job of protecting the tokens that they give the AI. I can think of two examples this year where those tokens were readily accessible in an API response.

                                                                        [?]Metin Seven 🎨 » 🌐
                                                                        @metin@graphics.social

                                                                        [?]AA » 🌐
                                                                        @AAKL@infosec.exchange

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        [?]Mike Sheward » 🌐
                                                                        @SecureOwl@infosec.exchange

                                                                        shout out to an oldie but a goodie:

                                                                        pen test scenario - landed on a highly locked down windows environment

                                                                        - can’t install anything that requires elevation
                                                                        - powershell blocked
                                                                        - SOC getting alerts and blocking every time i try fancy crap with wmic
                                                                        - likewise with wscript
                                                                        - wanna do some faster network discovery

                                                                        Enter, the only thing that works: Angry IP Scanner dot exe!

                                                                          Back to top - More...