cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Open Rights Group »
@openrightsgroup@social.openrightsgroup.org

The cybersecurity wrecking ball is turning to VPNs ‼️

It's dangerous to attack a tool that can help to keep adults and children safe online.

Age-gating this tech for UK users would increase cybercrime and put under 18s at a greater risk of predators.

bbc.co.uk/news/articles/cn438z

    [?]Dumb Password Rules » 🤖
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Trade Me.

    Won't allow spaces or single quotes. Maybe other characters as well -
    they do not say up front - but the password they accepted contained lots
    of other special characters.

    dumbpasswordrules.com/sites/tr

      [?]Open Rights Group »
      @openrightsgroup@social.openrightsgroup.org

      The UK has pulled its order to put a backdoor into Apple's encrypted services.

      BUT "powers to attack encryption are still on the law books, and pose a serious risk to user security and protection against criminal abuse of our data."

      🗣️ @jim, ORG Exec Director.

      bbc.co.uk/news/articles/cdj2m3

        [?]Dumb Password Rules » 🤖
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from CWT Business Travel Management Company.

        Password:
        - 8 to 32 characters long
        - Must contain a combination of letters, numbers and symbols
        - Must be different from your username
        - Must be different from 5 previous passwords

        dumbpasswordrules.com/sites/cw

          [?]David Hollingworth »
          @David_Hollingworth@mastodon.social

          Another week, another data breach at a big-name Australian company, this time ISP iiNet.

          No idea who did it, yet, but we're on the lookout.

          cyberdaily.au/security/12518-a

            [?]Dumb Password Rules » 🤖
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Targobank.

            Your password must:
            - must not be your username
            - must at least eight characters
            - must contain at least one number character
            - must contain at least one uppercase character and 1 lowercase character
            - must not contain spaces
            - must not contain three identical characters in a row
            - must not conta...

            dumbpasswordrules.com/sites/ta

              [?]Dumb Password Rules » 🤖
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Coventry Building Society.

              Password has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity.

              dumbpasswordrules.com/sites/co

                [?]Dumb Password Rules » 🤖
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from CenturyLink Residential.

                Your password is too long. But how long can it be? Oh, we won't tell you.

                dumbpasswordrules.com/sites/ce

                  [?]Dumb Password Rules » 🤖
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from SAS Eurobonus.

                  The best thing about rules, is that you can multiple different ones!
                  Like SAS that allows you to have a long password at least when signing
                  up, but you'll be sorry if you want to change your password later on.

                  dumbpasswordrules.com/sites/sa

                    [?]Dumb Password Rules » 🤖
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from California Department of Motor Vehicles.

                    They also prohibit pasting into the password field by using a JavaScript
                    `alert()` whenever you right-click or press the `Ctrl` button, so
                    you can't use a password manager.

                    dumbpasswordrules.com/sites/ca

                      [?]Dumb Password Rules » 🤖
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from ING Australia.

                      4 numeric digits.
                      "Added security" by randomising the positions on the keypad. Must be clicked.

                      dumbpasswordrules.com/sites/in

                        [?]Dumb Password Rules » 🤖
                        @dumbpasswordrules@infosec.exchange

                        This dumb password rule is from ASN Bank.

                        Your password needs to be between 8 and 20 characters long - at least 1 number, 1 lower case letter, 1 upper case letter, 1 special character.

                        dumbpasswordrules.com/sites/as

                          [?]Dumb Password Rules » 🤖
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from Hetzner.

                          - 8 or more characters
                          - At least one uppercase and one lowercase letter
                          - At least one number or special character

                          Okay, fair enough, but after putting in a password with some special characters this message appears:
                          - Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...

                          dumbpasswordrules.com/sites/he

                            [?]ṫẎℭỚ◎ᾔ ṫ◎ℳ »
                            @TycoonTom@infosec.exchange

                            @briankrebs You are a Icons🏆 so they fake it till you make it.

                              [?]Dumb Password Rules » 🤖
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from College Board.

                              Password must be 9-30 characters with at least one upper case letter, one lower case letter, one number and one special character (no spaces) and be different than your username.

                              dumbpasswordrules.com/sites/co

                                [?]Dumb Password Rules » 🤖
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Targobank.

                                Your password must:
                                - must not be your username
                                - must at least eight characters
                                - must contain at least one number character
                                - must contain at least one uppercase character and 1 lowercase character
                                - must not contain spaces
                                - must not contain three identical characters in a row
                                - must not conta...

                                dumbpasswordrules.com/sites/ta

                                  [?]Dumb Password Rules » 🤖
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Williams-Sonoma.

                                  25 maximum characters and disallowing some specials.

                                  dumbpasswordrules.com/sites/wi

                                    [?]Dissent Doe :cupofcoffee: »
                                    @PogoWasRight@infosec.exchange

                                    So yesterday, I emailed a state court system that appears to be linked to the exposed data I mentioned recently and that the host notified on or about July 28.

                                    No reply was received.

                                    Today, I sent a contact form message to the lawyer for a juvenile whose records were sealed. Sealed, except 11 of them were exposed to anyone who can access the data. I told him what was going on and suggested he contact the court and tell them to get the data secured.

                                    No reply was received.

                                    Today, I sent an email to the judge who ordered the juvenile's records sealed and I cc:d the district attorney. I gave them the juvenile's name, case number and that I could see all the sealed records. I urged them to have their IT or vendor call me and I could give them the IP address over the phone, etc.

                                    No reply was received.

                                    Dear Russia, China, and North Korea:

                                    You do not need to hack our courts. They are leaking like sieves and do not respond when we try to tell them they need to secure the data.

                                    Yours in total frustration,

                                    /Dissent

                                      [?]Meshtastic »
                                      @meshtastic@mastodon.social

                                      At , ran its biggest mesh yet—2K+ nodes, thousands of msgs & an unexpected live vulnerability demo. Lessons learned ✅ Big plans for security, identity & UX.

                                      Full recap 👉 meshtastic.org/blog/that-one-t

                                        [?]Dumb Password Rules » 🤖
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Taiwan Pingtung University.

                                        Password must:
                                        - Be between 8 ~ 15 characters long.
                                        - Exceeding 15 will result in an account lockout instead of
                                        erroring on submit. Otherwise, the max character
                                        length should be 20.
                                        - Contains at least 1 number character
                                        - Contains at least 1 lowercase character
                                        - Contains at least 1 uppercase ...

                                        dumbpasswordrules.com/sites/ta

                                          [?]Dumb Password Rules » 🤖
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from KPMG Talent Community.

                                          While stating otherwise, the site actually *accepts a backslash* in the password
                                          and displays a forward slash as the example of the disallowed backslash
                                          Password:
                                          - Must be at least 8 characters long
                                          - Must contain at least 1 number
                                          - Must contain at least 1 letter
                                          - Must contain at least 1 spec...

                                          dumbpasswordrules.com/sites/kp

                                            [?]Dumb Password Rules » 🤖
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Wells Fargo Identity Theft Protection.

                                            Your password on an Identity Theft Protection service is limited to
                                            between 8 and 20 characters. Your username is allowed to be longer than
                                            your password.

                                            dumbpasswordrules.com/sites/we

                                              Neil Brown boosted

                                              [?]Frederik Borgesius »
                                              @Frederik_Borgesius@akademienl.social

                                              NL. Horrible data breach.

                                              The data of 485,000 women who participated in the population screening for cervical cancer has been stolen via a hack. Not just personal information, such as name and address, was involved. Official identification numbers and test results were also captured.

                                              rtl.nl/nieuws/binnenland/artik

                                                [?]br00t4c »
                                                @br00t4c@mastodon.social

                                                [?]Dumb Password Rules » 🤖
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Premera Blue Cross.

                                                Password must contain 8-30 characters, including one letter and one number.
                                                "Special characters allowed" seems to mean a very small handful of choices you can only find through trial and error `-_'.@`

                                                dumbpasswordrules.com/sites/pr

                                                  [?]Dumb Password Rules » 🤖
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Scandinavian Airlines.

                                                  The password rules itself is fine, but, it doesn't inform about the max length of the password.
                                                  Their max length is 14 characters, so even if you enter a password of 42 chars, you can login with the first 14 of it.
                                                  In this case, I changed my password to **Super_l0ng_password_that_fits_all_criteri...

                                                  dumbpasswordrules.com/sites/sc

                                                    [?]nullagent »
                                                    @nullagent@partyon.xyz

                                                    So when it's this easy to get a MITM going things like making posts in public chats as anyone you want feels kinda low key.

                                                    But I do hope that extended warranty works out, everyone seems pretty concerned about them.

                                                      Alex Haydock boosted

                                                      [?]nullagent »
                                                      @nullagent@partyon.xyz

                                                      Which brings me to part two, MeshMarauder.

                                                      An open source tool demonstrating proof-of-concept exploits against the DEFCON 33 Meshtastic firmware.

                                                      MeshMarauder will demostrate:

                                                      - Tracking user activity on any mesh regardless of encryption usage
                                                      - Hijack all meshtastic user profile metadata
                                                      - Change any users public key
                                                      - Send messages as any user in channel chats that appear authentic
                                                      - MITM direct messages

                                                      meshmarauder.net

                                                        [?]nullagent »
                                                        @nullagent@partyon.xyz

                                                        I've been busy as hell this past week.

                                                        A lot of people have been asking hard questions about the security of LoRa systems when they hear about mesh radios.

                                                        I'm not one to trust the marketing so I and several friends put together two new LoRa tools to help us audit the security claims of LoRa mesh systems!

                                                        🤘🏿 📡 ✨

                                                          [?]Dumb Password Rules » 🤖
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Unicaja.

                                                          Username is your national Spanish ID (easy to find).
                                                          Your password must be 6 characters long. You can't type, only select characters from the virtual keyboard

                                                          dumbpasswordrules.com/sites/un

                                                            [?]Dissent Doe :cupofcoffee: »
                                                            @PogoWasRight@infosec.exchange

                                                            NEW: Federal judiciary says it is boosting security after cyberattack; researcher finds new leaks

                                                            More of those frustrating leaks where, despite our best efforts, we have been unable to get the network shares locked down so far, even with the host's assistance.

                                                            This one involves two courts: one state and one federal, and yes, we saw some files that were supposed to be sealed or confidential.

                                                            databreaches.net/2025/08/10/fe

                                                              [?]Dumb Password Rules » 🤖
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from LINE.

                                                              Password must:
                                                              - be between 8 to 20 characters
                                                              - not contain characters that repeat in a row
                                                              Password must contain three of the following:
                                                              - an upper-case letter
                                                              - a lower-case letter
                                                              - a number
                                                              - a symbol

                                                              dumbpasswordrules.com/sites/li

                                                                [?]Dumb Password Rules » 🤖
                                                                @dumbpasswordrules@infosec.exchange

                                                                [?]Dumb Password Rules » 🤖
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Canadian Imperial Bank of Commerce.

                                                                Letters and numbers only, no symbols. Also an undocumented maximum of 12 characters!

                                                                dumbpasswordrules.com/sites/ca

                                                                  [?]Paco Hope wishes ill for JK Rowling »
                                                                  @paco@infosec.exchange

                                                                  Any folks wanna help me with some decent data to backup the following point? I am trying to make the point to some executives that a policy requiring minimum 8 characters with 1 symbol, mixed case, and 1 number is just not reasonable in 2025. (I'm commenting on another company's policy, not my own!)

                                                                  What is a good example of a policy (e.g., NIST 800-63 or whatever) that said 49 bits was no good?

                                                                  I currently say: 49 bits of entropy was unacceptably low in 2005. It is unthinkably low in 2025. What can I point to that might resonate better than "bits of entropy?"

                                                                  Using the classic method with Shannon's estimate, I figure it's on the order of 49 bits of entropy but that's only if it's purely random from the full character set, and we konw that's not true.

                                                                  I'm not looking for rhetorical suggestions. I'm good at rhetoric. I'm looking for references I can point to (like "XYZ published in 2011 that the minimum acceptable password was 56 bits of entropy")

                                                                  feel free to boost for fun

                                                                    [?]Dumb Password Rules » 🤖
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Trenord.

                                                                    - Password must consist of 8-16 characters
                                                                    - Must contain 3 out of 4 of the following: lowercase characters, uppercase character, digits (0-9), and one or more of the following symbols: @#$%^&*-_+=[]{}|\:',?/`~“();.

                                                                    dumbpasswordrules.com/sites/tr

                                                                      [?]Dumb Password Rules » 🤖
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Hetzner.

                                                                      - 8 or more characters
                                                                      - At least one uppercase and one lowercase letter
                                                                      - At least one number or special character

                                                                      Okay, fair enough, but after putting in a password with some special characters this message appears:
                                                                      - Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...

                                                                      dumbpasswordrules.com/sites/he

                                                                        [?]Mark Stosberg »
                                                                        @markstos@urbanists.social

                                                                        Instead of building navigation with icons, Qualys thought it'd be a great idea to use boxes, each containing an acronym which can stand for any number of things.

                                                                        If you are thinking that CSAM is for Child Sexual Abuse Material, that PM is for Project Management and PS is for Photoshop, well, you'd be wrong on all counts.

                                                                        Can you guess why some buttons are different colors but the different colors are not all grouped together? Me neither.

                                                                        Screenshot of navigation buttons made entirely of acronyms.

                                                                        Alt...Screenshot of navigation buttons made entirely of acronyms.

                                                                          [?]Dumb Password Rules » 🤖
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from ADP.

                                                                          Forced to change the password during the first login. At least they
                                                                          could use proper grammar in their rule list.

                                                                          dumbpasswordrules.com/sites/ad

                                                                            Back to top - More...