cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Bank of America.

20 character max and lots of special character restrictions.
Bank of America - keeping your money safe.

Also: If you paste a password greater than 20 characters,
the form truncates it without telling you or giving an
error.

dumbpasswordrules.com/sites/ba

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Banco Nacional (Costa Rica National Bank).

    Between 8 and 16 characters.

    Must have 4 numbers and 4 letters.

    Must not contain same letter or number in consecutive order.

    Can't contain vowel letters neither the letter Ñ.

    Password can't be the same as the previous 6 used.

    dumbpasswordrules.com/sites/ba

      JP boosted

      [?]Heliograph » 🌐
      @Heliograph@mastodon.au

      😆 this is excellent @daedalus

      "We take security seriously!!
      Cover up that incident with this handy sticking plaster."

      redbubble.com/shop/ap/174240626

      EIGENMAGIC sticker in form of a band-aid claiming "We take security seriously."

      Alt...EIGENMAGIC sticker in form of a band-aid claiming "We take security seriously."

        🗳
        Paco Hope boosted

        [?]Jonathan Kamens 86 47 » 🌐
        @jik@federate.social

        I have an old WiFi acting as an access point. This router is end-of-life and supposedly no longer receives firmware updates; there was a security update last September, so it isn't _too_ stale.
        Because it's serving as an access point it has no public IP address, though obviously a sufficiently dedicated attacker could literally sit outside our house and talk to it over WiFi.
        If you were in my shoes, what would you do with this router?

        leave it, it's fine:7
        too risky, replace it:0
        too risky, flash it to DD-WRT:8
        something else, see reply:0

          [?]Mike Sheward » 🌐
          @SecureOwl@infosec.exchange

          i was quite surprised to discover that no one had registered deleteduser [dot] com, and was curious to see how many emails i'd get if i registered it, assuming many orgs 'delete' logic probably just overwrote the email address with blahblah@deleteduser.com or similar.

          The answer, is at least 3 different orgs in the hour that I've owned that domain and been listening for email.

          And yes, all of those emails contain the actual PII of the person who has been 'deleted' :-D

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from MetLife.

            Max length of 20 characters, no special characters allowed.
            Pasting into the second password field is disabled even with
            the Chrome extension Don't Fuck With Paste.

            dumbpasswordrules.com/sites/me

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Vancity Credit Union.

              Personal Access Code (or PAC–they are too ashamed to call it a password), must be between 5 to 8 digits and cannot start with '0'. (no letters or symbols)

              dumbpasswordrules.com/sites/va

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Scandinavian Airlines.

                The password rules itself is fine, but, it doesn't inform about the max length of the password.
                Their max length is 14 characters, so even if you enter a password of 42 chars, you can login with the first 14 of it.
                In this case, I changed my password to **Super_l0ng_password_that_fits_all_criteri...

                dumbpasswordrules.com/sites/sc

                  [?]AA » 🌐
                  @AAKL@infosec.exchange

                  It doesn't just live on. It's thriving because criminals know they operate in a reactionary environment. It's leverage, and it's working and will continue to works so long as the crisis management model remains the same.

                  Security Boulevard: Ransomware Lives On, Blending Hacktivism and Crime, Fueled by AI securityboulevard.com/2026/04/

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Benergy4.

                    12 to 25 characters, only these special chars allowed: @+/'!#$^?:,.(){}[]~-.
                    Also, security questions.

                    dumbpasswordrules.com/sites/be

                      [?]Frank » 🌐
                      @fschaap@mastodon.social

                      Why is not every emailaddress an alias?

                      Access to your mailbox would be a totally unrelated username + password/MFA.

                      Why are we still giving away a free factor for compromise with every email we send?

                        [?]🆘Bill Cole 🇺🇦 [Honestly I don’t care but no one will understand if you use she/her.] » 🌐
                        @grumpybozo@toad.social

                        @fschaap Skill issue.

                        Some of us have divorced authentication from message transport and delivery for decades. And talked about it. And advocated for it. And been mostly ignored.

                        Literally every email address that delivers to my main mailbox is an alias of some sort. Has been since 1995 when I fired up my own mail server. My mail is delivered into a Maildir+ mailbox owned by a system account whose name I have never used in an email address and never will.

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from LibraryThing.

                          "Your password cannot be longer than 20 characters"

                          dumbpasswordrules.com/sites/li

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from Return of Reckoning.

                            Password must be between 6 and 100 characters.

                            It doesn't say on the website, but the password only works in the related game client if it is purely alphanumeric. Not even special characters like % or $ are allowed.

                            dumbpasswordrules.com/sites/re

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from myezyaccess.com patient portal system.

                              12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

                              dumbpasswordrules.com/sites/my

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Coventry Building Society.

                                Password has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity.

                                dumbpasswordrules.com/sites/co

                                  s1m0n4 boosted

                                  [?]Patrick » 🌐
                                  @ppb1701@ppb.social

                                  Proton built their entire brand on one promise: Swiss law means government agencies can't touch your data.
                                  Their own Terms of Service, their own infrastructure contracts, and a federal court case from March say otherwise.

                                  blog.ppb1701.com/not-even-gove

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from Nelnet (student loan servicer).

                                    8 to 15 characters and no spaces? Why no spaces? Also limited to only these 6 special characters. That could mean that there is some process somewhere that puts this as part of a command line invocation.

                                    dumbpasswordrules.com/sites/ne

                                      [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                      @freya@social.highenergymagic.net

                                      hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                      Please boost for reach, any job offers please DM me.

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Unicaja.

                                        Username is your national Spanish ID (easy to find).
                                        Your password must be 6 characters long. You can't type, only select characters from the virtual keyboard

                                        dumbpasswordrules.com/sites/un

                                          [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                          @freya@social.highenergymagic.net

                                          hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                          Please boost for reach, any job offers please DM me.

                                            [?]ṫẎℭỚ◎ᾔ ṫ◎ℳ » 🌐
                                            @TycoonTom@infosec.exchange

                                            @briankrebs Breaking Electronic Frontier Foundation Announces Departure from X After Nearly 20 Years👏🏼 :clap_claw:

                                              [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                              @MissConstrue@mefi.social

                                              RE: mastodon.social/@campuscodi/11

                                              This is a big freaking deal, and Anthropic is handwaving it away. Basically a malicious actor can remove the safety rails, and Claude becomes a pretty serious penetration tool.

                                                [?]Jonathan Kamens 86 47 » 🌐
                                                @jik@federate.social

                                                RE: flipboard.com/@404media/404-me

                                                If you think there's any chance that law enforcement might ever be interested in the content of your Signal chats, and you don't want them to have access to them, then setting up disappearing messages is necessary but not sufficient. You also need to go into the Signal settings and either disable notifications completely or set them to show "No name or message" so the content won't be capture and preserved in the phone's notification database.
                                                ""

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Itaú Bank.

                                                  I know, it's in spanish, let me translate this monstrosity for you.

                                                  - Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
                                                  - You must use 8 characters.
                                                  - The password must contain at least one letter and at least one number.
                                                  - ...

                                                  dumbpasswordrules.com/sites/it

                                                    [?]Dendrobatus Azureus » 🌐
                                                    @dendrobatus_azureus@polymaths.social

                                                    Does this mean that you shall also stop using curl?

                                                    AFAIK Daniel doesn't care what is used to find bugs

                                                    @rl_dane

                                                    https://mastodon.social/@bagder/116373716541500315

                                                    #curl #LLM #hallucinated #slop #AI #InfoSec #programming #technology

                                                      [?]Michał "rysiek" Woźniak · 🇺🇦 » 🌐
                                                      @rysiek@mstdn.social

                                                      Oh boy…
                                                      edition.cnn.com/2026/04/08/chi

                                                      > A [cyberthreat actor] has allegedly stolen a massive trove of sensitive data – including highly classified defense documents and missile schematics – from a state-run Chinese supercomputer

                                                      > The dataset, which allegedly contains more than 10 petabytes of sensitive information, is believed by experts to have been obtained from the National Supercomputing Center (NSCC) in Tianjin

                                                      🧵

                                                        [?]Hans-Cees 🌳🌳🤢🦋🐈🐈🍋🍋🐝🐜 » 🌐
                                                        @hanscees@ieji.de

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Bank Millennium.

                                                        Passwords limited to 8 digits.

                                                        dumbpasswordrules.com/sites/ba

                                                          [?]Tara 🕷️:blobbat: [she/her, they/them] » 🌐
                                                          @tarajdactyl@anarres.family

                                                          :boosts_ok_gay:

                                                          attention anybody with substantial experience with Rust and networking: my team is hiring!!

                                                          one of few rust jobs I'm aware of that is not web 3.0 horseplop.

                                                          fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind.

                                                          feel free to reach out for more details and the job posting.

                                                          :boosts_ok_gay:

                                                            [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                                            @freya@social.highenergymagic.net

                                                            hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                                            Please boost for reach, any job offers please DM me.

                                                              [?]Socket » 🌐
                                                              @SocketSecurity@fosstodon.org

                                                              Attackers are impersonating a @linuxfoundation leader in Slack to target developers with a multi-stage attack that ends in malware delivery. @openssf issued a high-severity advisory.

                                                              More details and screenshots of the lure: socket.dev/blog/attackers-impe

                                                                [?]Jonathan Kamens 86 47 » 🌐
                                                                @jik@federate.social

                                                                locks account that maintainer uses to sign bootloaders with no explanation or route for appeal. If they don't fix this, in a few months every Windows computer that uses VeraCrypt whole-disk encryption will stop being able to boot and all the data on it that isn't backed up elsewhere will be lost. 🤦
                                                                If this doesn't convince you big tech has too much control, I don't know what will.
                                                                h/t @zackwhittaker
                                                                techcrunch.com/2026/04/08/vera

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Inria.

                                                                  This is the account for those who work at [Inria](inria.fr/)
                                                                  "the French national research institute for
                                                                  the digital sciences".

                                                                  You have to wonder what's wrong with these special characters but not
                                                                  the other ones.
                                                                  - Password expiration once a year
                                                                  - Your password must contain at leas...

                                                                  dumbpasswordrules.com/sites/in

                                                                    [?]BeyondMachines :verified: » 🤖 🌐
                                                                    @beyondmachines1@infosec.exchange

                                                                    Critical File Upload Vulnerability Reported in Ninja Forms Plugin for WordPress

                                                                    A critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms – File Upload plugin (CVE-2026-0740) allows attackers to achieve remote code execution.

                                                                    **If you are using the Ninja Forms File Upload plugin, this is urgent! Immediately update to version 3.3.27. You can't hide WordPress from the internet, it's made to be visible online. Since this flaw is being actively scanned for, any delay in patching leaves your site exposed to automated attacks. After the update, review server logs for suspicious requests targeting the handle_upload action.**

                                                                    beyondmachines.net/event_detai

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Deutsche Kreditbank AG (DKB).

                                                                      Passwords for the online banking web frontend do not have a max length constraint, but using the same password to
                                                                      log in to the official iOS DKB app requires the password to be no longer than 38 characters.

                                                                      dumbpasswordrules.com/sites/de

                                                                        [?]Mike Sheward » 🌐
                                                                        @SecureOwl@infosec.exchange

                                                                        one of my favorite google sheets features is when you are compiling lists of malicious actors email identifiers it pops up and says "hey, you mentioned blah@evil.com, but they don't have access to this sheet! would you like to give them access?"

                                                                          [?]IFIN - The Independent Federated Intelligence Network » 🌐
                                                                          @ifin@infosec.exchange

                                                                          Hello, world!

                                                                          We are IFIN, the Independent Federated Intelligence Network, and we want to change how threat intelligence is done.

                                                                          We believe we're all safer when we share what we know. Come learn more and join us!

                                                                          ifin-intel.org/blog/hello/

                                                                            [?]AA » 🌐
                                                                            @AAKL@infosec.exchange

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Air France.

                                                                            - Between 8 to 12 characters
                                                                            - Should contain capital, lowercase letters and numbers

                                                                            dumbpasswordrules.com/sites/ai

                                                                              [?]Wulfy—Speaker to the machines » 🌐
                                                                              @n_dimension@infosec.exchange

                                                                              @bagder

                                                                              Just so I understand this correctly...
                                                                              We don't want machine generated vulerability reports...

                                                                              ...so we can leave our projects vulnerable to hackers who are not constrained by ideology in their sploits using ?

                                                                              Yeah, that tracks with the current majority of "professionals" letting the Rome burn while they roast the marshmallows, feeling super pure and superior.

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from MySwissLife.

                                                                                User ID *has to* be 8 characters exactly, password *has to be* 8 characters and numbers only.

                                                                                dumbpasswordrules.com/sites/my

                                                                                  [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                                  @markwyner@mas.to

                                                                                  It’s interesting how many people think wanting privacy means you’re doing something nefarious. The fact is, privacy is about sharing what you want with whom you choose.

                                                                                  (I don’t recall who wrote these words or where I originally saw them. I only made the graphic.)

                                                                                  Illustration of some eyes looking straight at you followed by text that reads “I need privacy, not because my actions are questionable. But because your judgment and intentions are.”

                                                                                  Alt...Illustration of some eyes looking straight at you followed by text that reads “I need privacy, not because my actions are questionable. But because your judgment and intentions are.”

                                                                                    Back to top - More...