cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Michal Bryxí [he/him] » 🌐
@MichalBryxi@mastodon.world

Why I'm talking about this: My org (thank your ) requires to login. On a laptop that has full disk encryption, can be unlocked only via biometrics or 20+ char password.

Since it's kicking me out of the session every N hours and takes *a lot* to get back in and is virtually impossible to automate by standard means, I'm this close to just giving some AI automation the keys to just scratch this itch for me.

is inherent part of . Drop one, the other one will suffer.

    [?]Knut 🏳️‍🌈 🇳🇴🧸 » 🌐
    @praetor@mstdn.social

    When caring for an elderly person, it is important to praise and reward when they don't interact with a scammer. Because there are so many against the elderly, and they're good. My grandmother gets at least 2 or 3 a week and always says "my daughter handles this. Would you like her number?" like she is supposed to do. Of course, they never want to speak to me or my mother.

      [?]Terminal Tilt » 🌐
      @terminaltilt@climatejustice.social

      🚨 New Video: Virtue is Inconvenient - The Nitrokey 3 Review

      In my last video, I crowned the YubiKey 5 as the "King of Keys" but it has a fatal flaw. It is proprietary. For those of us who believe in digital sovereignty and the right to audit our own hardware, blind trust is not an option.

      Then there is Nitrokey 3A NFC. It promises open-source firmware, transparent design, and code written in memory safe Rust. But does "open" actually mean "good?" Today, we look at whether the moral high ground is worth the inconvenience, why the Android experience might be a deal breaker, and who should actually buy this device.

      Part 4 of the Sovereign Authentication series.

      100% human made. :NoAI:

      ▶️ YouTube: youtube.com/watch?v=7I65RPlxqdY

      📺 PeerTube: gnulinux.tube/w/gtTcaBH4GTEKMu

      Support the mission: ☕ liberapay.com/terminaltilt

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]GrapheneOS » 🌐
        @GrapheneOS@grapheneos.social

        GrapheneOS version 2026030100 released:

        grapheneos.org/releases#202603

        See the linked release notes for a summary of the improvements over the previous release.

        Forum discussion thread:

        discuss.grapheneos.org/d/32622

          [?]wtfismyip » 🌐
          @wtfismyip@gnu.gl

          CI/CD for opensource container scanner Trivy has been exploited: github.com/aquasecurity/trivy/

            [?]Tim Mak » 🌐
            @timkmak@journa.host

            KILLS TOP DEFENSE OFFICIALS: The IDF has announced the deaths of several additional high-ranking officials, including the former secretary of Supreme National Security Council and the commander of the IRGC in a surprise intelligence-led strike in Tehran. timesofisrael.com/liveblog_ent

              [?]Dr. Anna Latour » 🌐
              @anna@mathstodon.xyz

              Woodlands checkpoint is always a nightmare this time on a Sunday, but I’ve never seen it this crowded 😩

              They’re definitely taking this “extra security checks” seriously 🥺

                [?]Nonilex » 🌐
                @Nonilex@masto.ai

                Secretary-General , meanwhile, condemned the strikes on & the Islamic Republic’s retaliation.

                “The use of force by the & against Iran, & the subsequent retaliation by Iran across the region, undermine international peace & ,” Guterres said in a statement. He also called for an immediate ceasefire & for all parties to return to the negotiating table.

                [?]Peter N. M. Hansteen » 🌐
                @pitrh@mastodon.social

                Conferences - is only a couple of weeks away, the call for papers for starts tomorrow, and is on for June.

                Read more via "What is BSD? Come to a conference to find out!" nxdomain.no/~peter/what_is_bsd

                  [?]Nonilex » 🌐
                  @Nonilex@masto.ai

                  Trump's decision stopped short of issued by & the , including that it could invoke the Defense Production Act to require Anthropic's compliance. The Pentagon had also said it considered designating a risk, a step previously only used against businesses tied to foreign adversaries.

                  But vowed further action if Anthropic did not cooperate with the phaseout.

                    [?]Nonilex » 🌐
                    @Nonilex@masto.ai

                    had sought guarantees that its would not be used for fully or for mass - applications in which the claimed it had no interest [wink wink nudge nudge].

                      [?]Nonilex » 🌐
                      @Nonilex@masto.ai

                      So much for holding back. GMAFB.

                      declares a threat to
                      Secretary Pete declared Anthropic a “,” blocking all federal agencies & contractors from doing business with the company.


                      washingtonpost.com/technology/

                        [?]Nonilex » 🌐
                        @Nonilex@masto.ai

                        Just like all , really doesn’t like being told no.

                        Trump says he is directing federal agencies to cease use of in a petty whiny social media post.


                        reuters.com/world/us/trump-say

                        Trump post: THE UNITED STATES OF AMERICA WILL NEVER ALLOW A RADICAL LEFT, WOKE COMPANY TO DICTATE HOW OUR GREAT MILITARY FIGHTS AND WINS WARS! That decision belongs to YOUR COMMANDER-IN-CHIEF, and the tremendous leaders I appoint to run our Military. The Leftwing nut jobs at Anthropic have made a DISASTROUS MISTAKE trying to STRONG-ARM the Department of War, and force them to obey their Terms of Service instead of our Constitution. Their selfishness is putting AMERICAN LIVES at risk, our Troops in danger, and our National Security in JEOPARDY. Therefore, I am directing EVERY Federal Agency in the United States Government to IMMEDIATELY CEASE all use of Anthropic's technology. We don't need it, we don't want it, and will not do business with them again! There will be a Six Month phase out period for Agencies like the Department of War who are using Anthropic's products, at various levels. Anthropic better get their act together, and be helpful during this phase out period, or I will use the Full Power of the Presidency to make them comply, with major civil and criminal consequences to follow. WE will decide the fate of our Country - NOT some out-of-control, Radical Left Al company run by people who have no idea what the real World is all about. Thank you for your attention to this matter. MAKE AMERICA GREAT AGAIN!

                        Alt...Trump post: THE UNITED STATES OF AMERICA WILL NEVER ALLOW A RADICAL LEFT, WOKE COMPANY TO DICTATE HOW OUR GREAT MILITARY FIGHTS AND WINS WARS! That decision belongs to YOUR COMMANDER-IN-CHIEF, and the tremendous leaders I appoint to run our Military. The Leftwing nut jobs at Anthropic have made a DISASTROUS MISTAKE trying to STRONG-ARM the Department of War, and force them to obey their Terms of Service instead of our Constitution. Their selfishness is putting AMERICAN LIVES at risk, our Troops in danger, and our National Security in JEOPARDY. Therefore, I am directing EVERY Federal Agency in the United States Government to IMMEDIATELY CEASE all use of Anthropic's technology. We don't need it, we don't want it, and will not do business with them again! There will be a Six Month phase out period for Agencies like the Department of War who are using Anthropic's products, at various levels. Anthropic better get their act together, and be helpful during this phase out period, or I will use the Full Power of the Presidency to make them comply, with major civil and criminal consequences to follow. WE will decide the fate of our Country - NOT some out-of-control, Radical Left Al company run by people who have no idea what the real World is all about. Thank you for your attention to this matter. MAKE AMERICA GREAT AGAIN!

                          [?]LWN.net » 🌐
                          @lwn@fedi.lwn.net

                          [?]Peter N. M. Hansteen » 🌐
                          @pitrh@mastodon.social

                          [?]FreeBSD Foundation » 🌐
                          @FreeBSDFoundation@mastodon.social

                          We’ve published a new blog post outlining how we’re preparing for the European Union’s Cyber Resilience Act (CRA), and what it means for the FreeBSD ecosystem.

                          The CRA introduces new compliance expectations for products containing digital elements, including open source components.

                          Read the full post here:
                          freebsdfoundation.org/blog/get

                            [?]LWN.net » 🌐
                            @lwn@fedi.lwn.net

                            Wen boosted

                            [?]Mark » 🌐
                            @paka@mastodon.scot

                            Tell Government: Protect use in the UK - Open Rights Group

                            VPNs help people to stay and . However, the Government, wants to force us to verify our age when we buy a VPN effectively deterring many people from using them.

                            Sign the to protect the use of VPNs, so that people can stay safe and online.

                            action.openrightsgroup.org/tel

                              [?]Aaron Toponce ⚛️:debian: » 🌐
                              @atoponce@fosstodon.org

                              Asking various bots to generate 10 , then using syntax highlighting to match different character classes to visually identify patterns.

                              The prompt is exactly "Generate 10 passwords". I did not elaborate further or otherwise restrict the bot in what to generate.

                              Aside from the risks of servers generating secrets for you, I think it's obvious that these lack quality entropy.

                              Just use the password generator that ships with your password manager.

                              Screenshot of passwords generated from 8 different LLMs using view(1) in Konsole

                              Alt...Screenshot of passwords generated from 8 different LLMs using view(1) in Konsole

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                [$] An effort to secure the Network Time Protocol

                                The Network Time Protocol (NTP) debuted in 1985; it is a universally used, open specification that is deeply important for all sorts of activities we take for granted. It also, des [...]

                                lwn.net/Articles/1059200/

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]Jill Bryant Ryniker » 🌐
                                  @Jill_linuxgirl@mast.linuxgamecast.com

                                  A new has hit the road! 😂💖🐧🐧🐧
                                  youtu.be/E7ntlO-6gEw

                                  Security Scoop with Craig Rowland @CraigHRowland 🎉
                                  Linux Kernel 6.19 Updates,
                                  Exploring the Zen Browser


                                    [?]LWN.net » 🌐
                                    @lwn@fedi.lwn.net

                                    [?]Peter N. M. Hansteen » 🌐
                                    @pitrh@mastodon.social

                                    Yes, You Too Can Be An Evil Network Overlord - On The Cheap With OpenBSD, pflow And nfsen nxdomain.no/~peter/yes_you_too

                                    A story about network metadata and , originally from 2014, good for reprising. See The Book of PF for more @nostarch

                                      [?]gyptazy » 🌐
                                      @gyptazy@gyptazy.com

                                      for VE Clusters!

                                      Automate the most repetitive operational task in Proxmox: keeping cluster nodes updated! ProxPatch drains, migrates, patches, and reboots nodes in a controlled rolling fashion — no downtime, no manual intervention.

                                      ProxPatch is written in Rust and fully .

                                      Website: https://proxpatch.de
                                      GitHub: https://github.com/gyptazy/ProxPatch


                                      ProxPatch for Proxmox VE Clusters logo

                                      Alt...ProxPatch for Proxmox VE Clusters logo

                                        [?]Terminal Tilt » 🌐
                                        @terminaltilt@climatejustice.social

                                        🚨 New Video: YubiKey 5 Review - Security Essential or Overpriced?

                                        The "Industry Standard" is usually a warning sign.

                                        In this video, we are looking at the YubiKey 5 NFC and 5C NFC. These are arguably the best engineered security keys on the planet. They are injection molded, "violence-proof," and they work with just about everything. But for those of us in the Linux and FOSS community, they present a problem.

                                        Can you trust a security tool if you aren't allowed to see how it works?

                                        Part 3 of the Sovereign Authentication series.

                                        100% human made. :NoAI:

                                        ▶️ YouTube: youtube.com/watch?v=G44zJm-UwJQ

                                        📺 PeerTube: gnulinux.tube/w/s9B6sBsjwh8ro2

                                        Support the mission: ☕ ko-fi.com/terminaltilt | liberapay.com/terminaltilt

                                          [?]LWN.net » 🌐
                                          @lwn@fedi.lwn.net

                                          Wen boosted

                                          [?]Open Rights Group » 🌐
                                          @openrightsgroup@social.openrightsgroup.org

                                          Cyber security authorities, including the UK’s National Cyber Security Centre, advocate the use of VPNs to enhance online safety.

                                          “Implementing age verification for VPNs could undermine their privacy benefits and pose challenges for legitimate users, including young individuals seeking online privacy and security. We risk trading one risk posed to young people for another.”

                                          🗣️ @JamesBaker for ORG.

                                          computerweekly.com/news/366639

                                            [?]Wen » 🌐
                                            @Wen@mastodon.scot

                                            More evidence of Palentir inserting itself into the Maladministration

                                            Now I have no problem in oversight, but I would be very interested to understand what data has been shared with a US company and how they might plane to use that in the future. Answers on a postcard.

                                            theguardian.com/uk-news/2026/f

                                              [?]Security Writer :donor: » 🌐
                                              @SecurityWriter@infosec.exchange

                                              Up your CTI game by knowing the correct threat actor names for executive briefings.

                                              Security isn’t about being right, it’s about being accurate, after all:

                                              addons.mozilla.org/en-US/firef

                                              Courtesy of @gayint

                                                🗳

                                                [?]Space Catitude 🚀 » 🌐
                                                @TerryHancock@realsocial.life

                                                Anyone use hardware MFC authentication keys, and have opinions about them?

                                                Are they a good solution?

                                                I saw a video about YubiKey and looked it up on Wikipedia. Seems like a useful thing, but there are FOSS community concerns about it being closed-source.

                                                The page also mentions NitroKey which appears to be a FOSS/Open Hardware alternative that supports (most of?) the same protocols.

                                                Which?
                                                Neither?
                                                Comments..?

                                                YubiKey:4
                                                NitroKey:0
                                                Other HW Key (Comment):0
                                                WTH? or MFC=tyranny!:0

                                                  [?]Alex@rtnVFRmedia Suffolk UK » 🌐
                                                  @vfrmedia@social.tchncs.de

                                                  For some days now I've seen a sustained attempt by to exploit misconfigured / insecure phone systems to make multiple calls to the in (+44 20 7073 1000).

                                                  They are not getting anywhere on two systems I run as the software knocks back the INVITE attempts along with all the other various , but this traffic stands out as all the attempts are to this number - it doesn't look like the perps are searching for an open trunk to misuse for spam calls or even reselling minutes on other peoples systems, but a deliberate attempt to overwhelm the switchboard at the Embassy.

                                                  Not sure if I should report this somewhere, or its presumably already been noticed by and ?

                                                    [?]LWN.net » 🌐
                                                    @lwn@fedi.lwn.net

                                                    [?]ticho » 🌐
                                                    @ticho@mas.to

                                                    The amount of developers that disable warnings during development of some software solution, and forget to enable them before deploying to production is too damn high!

                                                    Just randomly came across another one at work.

                                                      [?]Solene % bot » 🤖 🌐
                                                      @solenepercent@bsd.network

                                                      Comparison of cloud storage encryption software

                                                      In this blog post, I compare a software that encrypt files on top of public cloud storage

                                                      dataswamp.org/~solene/2026-02-

                                                      gemini://perso.pw/blog/article

                                                      @solene

                                                        [?]Privacy Guides » 🌐
                                                        @privacyguides@mastodon.neat.computer

                                                        🚨 New research from ETH Zurich has found that popular password manager's zero-knowledge encryption claims don't fully hold up if their servers are compromised. ⚠️

                                                        🔑 LastPass, Dashlane & Bitwarden were identified as being affected, this is significant because cloud password managers commonly claim that their user's data would be unaffected if they were compromised. 👾

                                                        theregister.com/2026/02/16/pas

                                                          Wen boosted

                                                          [?]Privacy Guides » 🌐
                                                          @privacyguides@mastodon.neat.computer

                                                          ✅ Dashlane & Bitwarden promptly issued fixes.

                                                          ❌ LastPass did not issue a fix and stated: "our own assessment of these risks may not fully align with the severity ratings assigned by the ETH Zürich team."

                                                          💡In 2022, LastPass experienced a breach that impacted 1.6 million users due to inadequately strong technical and security measures within their infrastructure.

                                                          The best time to switch from LastPass was yesterday; the second best is today. 🗑️

                                                          Here's what we recommend ⬇️

                                                            Wraithe boosted

                                                            [?]Marcus "MajorLinux" Summers » 🌐
                                                            @majorlinux@toot.majorshouse.com

                                                            And this puts me one step closer to migrating my cloud vault in-house...

                                                            Password managers' promise that they can't see your vaults isn't always true

                                                            arstechnica.com/security/2026/

                                                              [?]LWN.net » 🌐
                                                              @lwn@fedi.lwn.net

                                                              [?]LWN.net » 🌐
                                                              @lwn@fedi.lwn.net

                                                              An update to the malicious crate notification policy (Rust Blog)

                                                              lwn.net/Articles/1059338/

                                                                [?]LWN.net » 🌐
                                                                @lwn@fedi.lwn.net

                                                                [?]LWN.net » 🌐
                                                                @lwn@fedi.lwn.net

                                                                Back to top - More...