cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖
@dumbpasswordrules@infosec.exchange

This dumb password rule is from GameFly.

Password is 6-12 characters with no other restrictions. You can easily do 6 numbers, 6 lowercase letters, etc.

dumbpasswordrules.com/sites/ga

    [?]Dumb Password Rules » 🤖
    @dumbpasswordrules@infosec.exchange

    This dumb password rule is from Securvita BKK.

    Your password can not exceed a length of 30 characters. However, they don't tell you this: If you try to set a longer password, they instead shame *you* for not including at least one uppercase letter, one lowercase letter, one digit and one symbol – *even if you did*.

    The error message translat...

    dumbpasswordrules.com/sites/se

      [?]Dumb Password Rules » 🤖
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from T-Mobile.

      We prefer to not tell you which characters you can use up front.

      dumbpasswordrules.com/sites/t-

        [?]Mark Wyner Won’t Comply :vm: »
        @markwyner@mas.to

        So…who hates those Google log-in pop-ups that are seemingly everywhere now? Wanna make them go away?

        1. Get uBlock Origin (which you should have already been using):
        ublockorigin.com/

        2. Open the plugin and click the settings button.

        3. Click on the “my filters” tab and paste this into the input:
        ||accounts.google.com/gsi/*$xhr,script,3p

        That’s it! Worked flawlessly for me.

        Screenshot of a pop-up window with the title “sign in with google” followed by other information and a button with the label “continue.”

        Alt...Screenshot of a pop-up window with the title “sign in with google” followed by other information and a button with the label “continue.”

        Two screenshots of the ublock origin interface. The first one shows where the settings button is. The second shows where the filters input is on the view behind the tab with the label “my filters.”

        Alt...Two screenshots of the ublock origin interface. The first one shows where the settings button is. The second shows where the filters input is on the view behind the tab with the label “my filters.”

          [?]Dumb Password Rules » 🤖
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Global Entry.

          "Our duties are wide-ranging, and our goal is clear - keeping America
          safe."

          dumbpasswordrules.com/sites/gl

            [?]MJ »
            @mj@social.treehouse.systems

            I DID IT!

            Dewey invented the Dewey Decimal System, Morse invented the Morse Code, Plato invented the plate. I, influenced by what I saw at a conference I have designed and dedicated to the Public Domain the penultimate way to get removed from sales offerings.

            I present to you the "No Purchasing Authority" seal. Put it on a button, wear it as a sticker, respond to emails with it. Regardless, this helps you and the sales person understand that this relationship is going nowhere.

            White on black "No Purchasing Authority" with the symbols for dollar (green), euro (blue), yen (red) with a circle and line through symbolizing "no"

Underneath, a dedication to the Public Domain CC0 1.0 Universal.

            Alt...White on black "No Purchasing Authority" with the symbols for dollar (green), euro (blue), yen (red) with a circle and line through symbolizing "no" Underneath, a dedication to the Public Domain CC0 1.0 Universal.

              [?]Dumb Password Rules » 🤖
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Netflix.

              [The help page](help.netflix.com/de/node/54078)
              and the [password reset page](netflix.com/password) say:

              Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.

              dumbpasswordrules.com/sites/ne

                [?]defguard »
                @defguard@floss.social

                🎉 Defguard 1.5 alpha - finally Mobile Wireguard with Multi-Factor Authentication

                📱Help us test Multi-Factor Authentication on mobile devices: docs.defguard.net/help/mobile-

                🔑 Multi-Factor Authentication with External OIDC/SSO - now you can configure on each location separately which OIDC secures the MFA process: internal (with MFA configured in the user profile) or external like Google/Okta/Microsoft: docs.defguard.net/admin-and-fe

                  [?]Dumb Password Rules » 🤖
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Movistar.

                  Min 7 and max 8 characters for password! Also to be different than the
                  username: the user name is automatically generated and is based on the
                  surname of the user with some characters replaced by digits :)
                  Has been that way for more than 10 years.

                  dumbpasswordrules.com/sites/mo

                    [?]Dendrobatus Azureus »
                    @Dendrobatus_Azureus@mastodon.bsd.cafe

                    @nixCraft

                    Thus the fix is simple; don't use large language models LLM that you do not control 100% from server to client

                      [?]nixCraft 🐧 »
                      @nixCraft@mastodon.social

                      Security? Oh, you mean those mythical beasts we tell tales about around the digital campfire. Meanwhile, in the real world, someone's "secure" password vault is a Excel Sheet named "Passwords_FINAL_REALLY_FINAL.xlsx" being emailed around like a halloween candy. Forget your fancy backend architecture and battle-hardened sysadmins and firewalls. The true corporate security strategy is apparently hope and a prayer emoji.

                        Karl Baron boosted

                        [?]Pheonix »
                        @pheonix@fosstodon.org

                        Don't trust cloud services with your creative work.

                        Tumblr post by maerossi.

screenshot - "Google Sheets
We're sorry. You can’t access this item because it is in violation of our
Terms of Service."

Everyone: Please please please don't write your books in Google Docs. Frankly don't use Google Drive for personal stuff. Their terms of service say they take down stuff like content related to terrorism and trafficking, but this Google Sheet was literally a list of movies I'd watched this year and books I'd read.

23 Jul
Holy smokes, guys. It's way worse than | thought. Google actually took away access to every single file of fiction writing I'd made on that account. BUT |
backed it all up on Scrivener yesterday by coincidence. So | haven't lost my work, but I could have just lost the 12,000 words I've written this month after a year of really intense writer's block. I honestly don't know what that would have done to
my psyche. Please be careful out there, folks! <3

                        Alt...Tumblr post by maerossi. screenshot - "Google Sheets We're sorry. You can’t access this item because it is in violation of our Terms of Service." Everyone: Please please please don't write your books in Google Docs. Frankly don't use Google Drive for personal stuff. Their terms of service say they take down stuff like content related to terrorism and trafficking, but this Google Sheet was literally a list of movies I'd watched this year and books I'd read. 23 Jul Holy smokes, guys. It's way worse than | thought. Google actually took away access to every single file of fiction writing I'd made on that account. BUT | backed it all up on Scrivener yesterday by coincidence. So | haven't lost my work, but I could have just lost the 12,000 words I've written this month after a year of really intense writer's block. I honestly don't know what that would have done to my psyche. Please be careful out there, folks! <3

                          [?]Dumb Password Rules » 🤖
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from Safeway.

                          Passwords limited to 8-12 characters.

                          dumbpasswordrules.com/sites/sa

                            BrianKrebs boosted

                            [?]AA »
                            @AAKL@infosec.exchange

                            Maybe we should change the spelling of "vulnerabilities" to read "Microsoft?" It's hard to pin the worst offenders. There are others, so many more.

                            Kaspersky: ToolShell: a story of five vulnerabilities in Microsoft SharePoint securelist.com/toolshell-expla @Kaspersky

                              [?]keef »
                              @keefmarshall@mastodon.online

                              So my first evil genius robot honeypot, the word frequency one, seems to be getting hit by a distributed botnet.

                              It started around 2-3 requests per second but seems to be ramping up.

                              It's using IP addresses from all over the world - could be hacked personal devices? - and a wide range of plausible-looking User Agent strings.

                              My server is fine for now - 95% idle CPU.

                              Are there people for whom any of the IP or agent data might be useful? Botnet detectorists?

                                [?]Dumb Password Rules » 🤖
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from KPMG Talent Community.

                                While stating otherwise, the site actually *accepts a backslash* in the password
                                and displays a forward slash as the example of the disallowed backslash
                                Password:
                                - Must be at least 8 characters long
                                - Must contain at least 1 number
                                - Must contain at least 1 letter
                                - Must contain at least 1 spec...

                                dumbpasswordrules.com/sites/kp

                                  [?]Dumb Password Rules » 🤖
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Estheticon.

                                  - At least 8 characters but limited to 20 characters at max
                                  - At least 1 digit
                                  - At least one letter (just a letter in general, no specific casing required)
                                  - No special characters at all

                                  dumbpasswordrules.com/sites/es

                                    [?]Hans-Cees 🌳🌳🤢🦋🐈🐈🍋🍋🐝🐜 »
                                    @hanscees@ieji.de

                                    @jwildeboer wow you are using as a corporate user is running in a notebook container. These researchers hacked it to find out what's what and so on. Interesting read.
                                    and rule for sure
                                    Explanation on jupyter here: docs.jupyter.org/en/latest/wha

                                      [?]Dumb Password Rules » 🤖
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from Bloomingdale's.

                                      16 characters maximum, no `.` `,` `-` `|` `/` `=` or `_` allowed.

                                      dumbpasswordrules.com/sites/bl

                                        [?]Dumb Password Rules » 🤖
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from GoDaddy SFTP.

                                        Max 14 characters for the most important password in your shared hosting environment.

                                        dumbpasswordrules.com/sites/go

                                          [?]Michał "rysiek" Woźniak · 🇺🇦 »
                                          @rysiek@mstdn.social

                                          Oh I see the absurdly, negligently insecure Tea app is now getting the "hackers hacked" treatment, so that it can comfortably deflect blame to some unspecified scary hackers?

                                          Cool, cool.

                                          *takes out a bullhorn*

                                          📢 Tea kept drivers license photos of thousands of women in an unprotected Google Firebase storage bucket.

                                          📢 Centering "hackers" means helping let those responsible for the horrendous negligence at Tea off the hook.

                                          👏 There is no "hack", only other people's negligence.

                                          Screenshot of NBC News article headline and lede:

Hackers leak 13,000 user photos and IDs from the Tea app, designed as a women's safe space

The viral app requires new users to take selfies, which it says it deletes after review.

                                          Alt...Screenshot of NBC News article headline and lede: Hackers leak 13,000 user photos and IDs from the Tea app, designed as a women's safe space The viral app requires new users to take selfies, which it says it deletes after review.

                                            [?]Dumb Password Rules » 🤖
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from CAF (French Family Allowance Fund).

                                            You have to enter your 8-digit password using this Frenchy keypad.

                                            dumbpasswordrules.com/sites/ca

                                              [?]Dumb Password Rules » 🤖
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from ING a dutch bank in almost 50 countries.

                                              Max 20 characters, must have one number, one upper case character and one lower case character.
                                              You can only use certain special characters.
                                              When i asked about it they answer that it's really hard to change it.
                                              When i asked if the password is saved as a hash or just plain they send the answer to ...

                                              dumbpasswordrules.com/sites/in

                                                [?]nixCraft 🐧 »
                                                @nixCraft@mastodon.social

                                                [?]Dumb Password Rules » 🤖
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from BCV.

                                                Username is randomly generated, example: 'H2487414'. The password must have **6** digits only.

                                                Password can only be changed from the mobile application:

                                                dumbpasswordrules.com/sites/bc

                                                  [?]Dumb Password Rules » 🤖
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Bendigo Bank.

                                                  **Exactly** eight characters.

                                                  dumbpasswordrules.com/sites/be

                                                    [?]Dumb Password Rules » 🤖
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from HM Revenue & Customs (UK Tax).

                                                    We store basically all of your data, but we can't store your password.

                                                    dumbpasswordrules.com/sites/hm

                                                      [?]Dumb Password Rules » 🤖
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from AT&T.

                                                      The only special characters allowed are underscores and hyphens.

                                                      dumbpasswordrules.com/sites/at

                                                        [?]Dumb Password Rules » 🤖
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Walmart.

                                                        Your password must include the following:
                                                        - 8-100 characters
                                                        - Upper & lowercase letters
                                                        - At least one number or special character

                                                        dumbpasswordrules.com/sites/wa

                                                          [?]Dumb Password Rules » 🤖
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Bendigo Bank.

                                                          **Exactly** eight characters.

                                                          dumbpasswordrules.com/sites/be

                                                            [?]Mike Sheward »
                                                            @SecureOwl@infosec.exchange

                                                            I believe I may have come up with a new analogy today, that I am very proud of. So, if I didn’t and someone else already did it, then I’m sorry but I checked the internets and couldn’t find any record of it..also…this is potentially a terrible analogy.

                                                            Anyway, someone was getting a self signed certificate warning from a dev version of a webpage. So they sent me a screenshot and said, “so when I see this, what exactly is the risk? Should I trust it or not?”

                                                            So, what I said was. “Would you trust a doctor who prescribed themselves medication to look after you? Sure, sometimes it’s probably ok and innocent, but what if it means that they couldn’t get another doctor to sign off on it? That’s the risk you’re taking with a self signed certificate.”

                                                              [?]Dumb Password Rules » 🤖
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Virgin Mobile.

                                                              You can only use PIN as your password.

                                                              dumbpasswordrules.com/sites/vi

                                                                [?]nixCraft 🐧 »
                                                                @nixCraft@mastodon.social

                                                                One weak password is believed to have been all it took for a ransomware gang to destroy a 158-year-old company and put 700 people out of work in UK. This is why you need a strong password along with 2FA and all other cybersecurity practices that can be maintained by good IT staff, including verified backups.

                                                                bbc.com/news/articles/cx2gx288

                                                                  [?]Dumb Password Rules » 🤖
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  [?]Dumb Password Rules » 🤖
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Battle.net.

                                                                  8 to 16 characters, at least one number and one letter and last but not least NO special characters, and can't have a password that looks like your username too. Oh, and passwords are NOT case sensitive.
                                                                  A real time travel adventure through the password rules of 2005!

                                                                  dumbpasswordrules.com/sites/ba

                                                                    [?]Dumb Password Rules » 🤖
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Citi.

                                                                    * Password is case-insensitive
                                                                    * Can't use ANY special characters (although, adding special characters increases the "password strength" meter?!)
                                                                    * Allows for a minimum password length of 6 characters
                                                                    * No runs of more than two identical characters (eg. "aaa" is not allowed.)
                                                                    * Does not allow you...

                                                                    dumbpasswordrules.com/sites/ci

                                                                      [?]Dumb Password Rules » 🤖
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Inria.

                                                                      This is the account for those who work at [Inria](inria.fr/)
                                                                      "the French national research institute for
                                                                      the digital sciences".

                                                                      You have to wonder what's wrong with these special characters but not
                                                                      the other ones.
                                                                      - Password expiration once a year
                                                                      - Your password must contain at leas...

                                                                      dumbpasswordrules.com/sites/in

                                                                        Back to top - More...