cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Bloomingdale's.

16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.

dumbpasswordrules.com/sites/bl

    [?]Dumb Password Rules » 🤖 🌐
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from SAP Cloud Appliance Library.

    Passwords between 8 and 9 characters are the best.

    dumbpasswordrules.com/sites/sa

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from South Western Railway.

      Certain special characters disallowed, but notably the phrase " or " is disallowed also. They're probably papering over SQL injection vulnerabilities 🤦

      dumbpasswordrules.com/sites/so

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from Dell.

        Okay at least 6, that's alright I guess.

        Oh at least one number and one letter, bit dumb but hey not that dumb.

        But hiding the fact that it has a max of 20, now THAT is dumb!

        dumbpasswordrules.com/sites/de

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Dutch Tax Authorities (Belastingdienst).

          At least 8 and at most 25 characters, of which at least 3 of the characters were not used in the previous password.
          No more than 3 of the same characters.
          At least 1 upper case and 4 lower case characters.
          No more than 3 special characters.

          It's not like hashing passwords is a thing or something.

          dumbpasswordrules.com/sites/du

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from UniSuper.

            Passwords need:
            - a lower case letter
            - a number
            - a capital letter
            - at least 8 characters

            In the 'Change password' form,
            passwords are now restricted to a `maxlength` of 18.

            If your current password is longer than 18 characters,
            you won't be able to change your password.
            When I contacted them...

            dumbpasswordrules.com/sites/un

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Three.

              Password must be at least 7 characters long.
              The maximum length is inconsistent, however: when changing password, the maximum length is 30, but when resetting password via email link, the maximum length is 12.

              dumbpasswordrules.com/sites/th

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from University of Texas at Austin.

                Because of the last two rules, which ban dictionary words and any
                variants using symbol substitutions, *neither* of the passwords
                presented in the [xkcd comic](xkcd.com/936/) are allowed.

                dumbpasswordrules.com/sites/un

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Dwr Cymru (Welsh Water).

                  Limits password length to a maximum of 16 characters

                  dumbpasswordrules.com/sites/dw

                    It's Just Me boosted

                    [?]Stefano Marinelli » 🌐
                    @stefano@mastodon.bsd.cafe

                    Just received an email from my mail server administrator. They sent me a link to change my password because it's 'insecure'.

                    My mail admin is so efficient...

                    ...hey, wait a minute... I AM my mail administrator! 🤦‍♂️

                      BrianKrebs boosted

                      [?]Nonilex » 🌐
                      @Nonilex@masto.ai

                      This has to be a Easter Egg.

                      “improperly” [accidentally-on-purpose] disclosed tax data to
                      
The agency only recently discovered the “mistake” & is working with other federal agencies on a response.


                      washingtonpost.com/business/20

                        6 ★ 2 ↺
                        Mike Sheward boosted

                        [?]sam » 🌐
                        @sam@cablespaghetti.dev

                        Fediverse, I have a rant I need to get off my chest. Groups in Google Workspace is a security nightmare and has been for years! Why has Google STILL not fixed the glaring problems!?

                        I've had admin powers at 5+ companies' Google Workspace/G Suite over the past decade or so. Every single one had groups which were misconfigured, often so anyone in the whole company could join without approval or see the message history at https://groups.google.com without being a member at all.

                        This is because for any sensible configuration of Google Groups when using it for email groups you have to use the "Custom" permissions mode. The default Public mode doesn't allow external people to email the group, but does allow the whole company to see all the messages. The default Team mode, has the same problem of everyone being able to see all the messages.

                        Also let's not forget that dangerous little "Anyone in the organisation can join" toggle at the bottom which is on by default. So any random new starter can join your confidential company directors group and get all the emails sent to it.

                        Giving Google the benefit of the doubt here, I think the reasoning might be that Google Groups is intended as a kind of company forum, not for private email groups. However that isn't how anyone uses it in my experience...


                        Screenshot of the default Google Group settings for team mode

                        Alt...Screenshot of the default Google Group settings for team mode

                        Screenshot of the default Google Group settings for public mode

                        Alt...Screenshot of the default Google Group settings for public mode