cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This dumb password rule is from Rediff.
A maximum password length of 12. The hidden requirements are:
- at least 1 uppercase letter
- at least 1 lowercase letter
- at least 1 numeric character
- at least 1 special symbol (which can not be ^, %)
https://dumbpasswordrules.com/sites/rediff/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Alibaba.
- At least 2 uppercase letters
- Plus 2 lowercase letters
- Plus 2 numbers
- Plus 2 punctuation marks
Phew, too many rules, because why not, if [Ma thinks AI stands for Alibaba Intelligence](https://www.youtube.com/watch?v=f3lUEnMaiAU),
then password rules can be equally intelligent too.
Also, ...
https://dumbpasswordrules.com/sites/alibaba/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
boostedWir haben uns mal wieder mit Sicherheitslücken in Wechselrichtern beschäftigt. Was soll ich sagen: es sieht nicht gut aus. Lustigerweise regen sich viele im Kommentarbereich über die Überschrift auf. Natürlich gibt es auch noch andere Probleme. Aber IT-Sicherheit als ein nachrangiges Thema zu behandeln - das ist doch genau das Problem!
Anyway, von daher bin ich nicht so optimistisch, dass das bald besser wird. Hier ein Freebie-Link für euch:
https://www.zeit.de/digital/2026-07/balkonkraftwerk-hoymiles-hacker?freebie=00908b00
#cybersecurity #photovoltaik
This dumb password rule is from Trenord.
- Password must consist of 8-16 characters
- Must contain 3 out of 4 of the following: lowercase characters, uppercase character, digits (0-9), and one or more of the following symbols: @#$%^&*-_+=[]{}|\:',?/`~“();.
https://dumbpasswordrules.com/sites/trenord/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
New, by me: Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intelligence companies and a now-defunct AI-based lobbying platform they operated under assumed names.
https://krebsonsecurity.com/2026/07/felons-fraudsters-flog-offensive-cybersecurity-startup/
This dumb password rule is from NetworkRail Open Data Feeds.
Does require special characters but limits password length to 20.
https://dumbpasswordrules.com/sites/networkrail-open-data-feeds/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from University of California San Diego.
Passwords must be between 8 and **11** characters long!
https://dumbpasswordrules.com/sites/university-of-california-san-diego/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Meazure Learning.
The exam proctoring platform requires 12 to 128 characters and at least one from each of the four groups: lowercase letters, uppercase letters, digits, and special characters.
They explicitly ban spaces, more than two repeating characters and personal information.
So far, not too bad, although t...
https://dumbpasswordrules.com/sites/meazure-learning/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from State Bank of India (Foreign Travel Card).
State Bank of India is the largest government operated bank in India.
They offer "travel" prepaid cards for foreign currencies, this is for
their portal for the prepaid card users to manage their account.
Your password must:
- Be between 8 and 9 characters long
- Contain at least 1 lowercase c...
https://dumbpasswordrules.com/sites/state-bank-of-india-foreign-travel-card/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
I think some botherder fed their clanker the username/password thing the wrong way around again:
Jul 6 11:36:46 portal sshd-session[50983]: Failed password for invalid user 123Qzasx from 45.43.60.220 port 42096 ssh2
#cybercrime #ssh #sshgroping #passwordgropers #passwordguessers #morons #cybersecurity
🔒 A 19-year-old cybercriminal was caught despite using a VPN across multiple countries - because Windows has a tracking number built into every install that a VPN can't hide.
Peter Stokes, arrested in Finland in April and extradited to the US last week, is tied to Scattered Spider, the hacking group behind the 2023 MGM and Caesars casino breaches. The group is linked to 100+ intrusions and over $100 million in extortion.
The FBI didn't crack his VPN. Microsoft handed over his Global Device ID (GDID), a unique identifier baked into every Windows installation at setup. It doesn't change when you update, switch networks, or use a VPN. The only way to reset it is a full OS reinstall.
Investigators matched Stokes's GDID across IP addresses in Estonia, New York, and Thailand, correlating with login times on his Snapchat, Apple, and Facebook accounts. The same device that breached a luxury jewelry retailer and demanded $8 million in ransom also logged into Snapchat and a video game from his real network.
So while VPNs mask your IP address, they were never designed to hide device-level identifiers embedded in your operating system. The tracking can live one layer deeper than the one most people defend.
Read more:
https://www.itnews.com.au/news/microsoft-device-telemetry-key-to-unmasking-alleged-scattered-spider-hacker-627148
https://www.databreachtoday.com/scattered-spider-suspect-extradited-from-finland-to-us-a-32140
This dumb password rule is from AmiAmi.
Your password needs to be between 6 and 12 characters long, must contain only letters and numbers.
https://dumbpasswordrules.com/sites/amiami/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from E-Trade.
Causes:
* Your two-factor authentication code must be appended to the end of the password
* Passwords have a limit of 32 characters
Effect:
If your account has a 32-character password and has two-factor authentication,
their system appears to cut off the token, making it impossible to login.
Yo...
https://dumbpasswordrules.com/sites/e-trade/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Nelnet (student loan servicer).
8 to 15 characters and no spaces? Why no spaces? Also limited to only these 6 special characters. That could mean that there is some process somewhere that puts this as part of a command line invocation.
https://dumbpasswordrules.com/sites/nelnet-student-loan-servicer/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Best Buy.
You can enter whatever password you like! But you probably don't want to
make it too long, because you'll break us and you'll never be able to
login again.
https://dumbpasswordrules.com/sites/best-buy/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AOK (German Health Insurance).
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one number and one special character
- Special characters are: !...
https://dumbpasswordrules.com/sites/aok-german-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Intelink Passport.
Intelink is a group of "secure" intranets used by the United States Intelligence Community. Passport is
an identity and access management service for Intelink.
Rule #3 prohibits three or more consecutive uppercase, lowercase, or digit characters, even if those
characters are not the same. For ex...
https://dumbpasswordrules.com/sites/intelink-passport/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
New citizenlab report: a member of a European Parliament committee tasked with investigating spyware abuses was himself hacked with Pegasus. 🔍🛡️ The findings raise serious questions about accountability and surveillance. #spyware #Pegasus #cybersecurity https://citizenlab.ca/research/member-of-committee-investigating-spyware-hacked-with-pegasus/
This dumb password rule is from Trade Me.
Won't allow spaces or single quotes. Maybe other characters as well -
they do not say up front - but the password they accepted contained lots
of other special characters.
https://dumbpasswordrules.com/sites/trade-me/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
🚨 OONI reports Spain’s IP-based anti-piracy blocking tied to LaLiga unauthorized streams disrupted access to 554,507 legitimate domains (>500k) during match windows—and even flagged TLS MitM interception on a Spanish ISP. ⚠️ Collateral damage raises security concerns. Read: https://cyberinsider.com/ooni-laliga-piracy-blocks-disrupted-over-500000-legitimate-sites/ #OONI #LaLiga #Cybersecurity #InternetShutdown #Privacy #NetBlocks
This dumb password rule is from Rediff.
A maximum password length of 12. The hidden requirements are:
- at least 1 uppercase letter
- at least 1 lowercase letter
- at least 1 numeric character
- at least 1 special symbol (which can not be ^, %)
https://dumbpasswordrules.com/sites/rediff/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from SAS Eurobonus.
The best thing about rules, is that you can multiple different ones!
Like SAS that allows you to have a long password at least when signing
up, but you'll be sorry if you want to change your password later on.
https://dumbpasswordrules.com/sites/sas-eurobonus/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from WellStar MyChart.
Your password must be between 8 and 20 characters.
https://dumbpasswordrules.com/sites/wellstar-mychart/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Estheticon.
- At least 8 characters but limited to 20 characters at max
- At least 1 digit
- At least one letter (just a letter in general, no specific casing required)
- No special characters at all
https://dumbpasswordrules.com/sites/estheticon/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
I only now notice that my "What has (can) the EU Cyber Resilience Act done (do) for you?" article, in its tracked incarnation https://bsdly.blogspot.com/2026/06/what-has-can-eu-cyber-resilience-act.html made it onto @vermaden's Valuable news: https://vermaden.wordpress.com/2026/06/29/valuable-news-2026-06-29/ #cra #cybersecurity #cyberresilience #development #security #freesoftware #libresoftware #openbsd #netbsd #freebsd #bsdcan #eurobsdcon
This dumb password rule is from Citi.
* Password is case-insensitive
* Can't use ANY special characters (although, adding special characters increases the "password strength" meter?!)
* Allows for a minimum password length of 6 characters
* No runs of more than two identical characters (eg. "aaa" is not allowed.)
* Does not allow you...
https://dumbpasswordrules.com/sites/citi/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AirAsia.
- Between 8 and 16 characters
- Must contain a number, a lowercase letter, and an uppercase letter
- Special characters allowed, but not periods, commas, tildes, or angle brackets
https://dumbpasswordrules.com/sites/airasia/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ticketmaster.de.
Your password length is limited between 8 and 32 characters.
https://dumbpasswordrules.com/sites/ticketmaster-de/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
The Guardian: ‘It’s dangerous and it’s going to erode trust’: redesign of US government websites stokes surveillance fears
The National Design Studio, staffed by Doge veterans, installed visitor-tracking software on vital federal websites
"...An opaque White House office staffed largely by veterans of Elon Musk’s “department of government efficiency” (Doge) has quietly rebuilt some of the federal government’s most sensitive websites – for passport applications, voter registration, prescription-drug pricing and children’s savings – in ways critics say appear to violate federal law...."
This dumb password rule is from Ubisoft.
Only tells you the rules after submitting and clicking a link to a pop
up window.
https://dumbpasswordrules.com/sites/ubisoft/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Ancestry.
Password:
- Must be at least 8 characters long
- Must contain at least 1 number
- Must contain at least 1 letter or special character
- Must not be a well known or common password
https://dumbpasswordrules.com/sites/ancestry/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from URSSAF (French employers tax collection service).
When setting a new password:
Password must be exactly 8 characters, at least 1 letter, at least 1 number, but no special characters.
https://dumbpasswordrules.com/sites/urssaf-french-employers-tax-collection-service/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Pole-Emploi.
Password must contain at least one letter, one number and one character from `&-_@*%=.,;:!?` only.
It rejected passwords generated by pass, while accepting `p@ssw0rd!`...
They also block pasting on the password confirmation field,
forcing you to manually type your 32-letters-long generated passwo...
https://dumbpasswordrules.com/sites/pole-emploi/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇
This dumb password rule is from Onleihe.
Password is your birthday in format ddmmyyyy. Users are not allowed to change their passwords
https://dumbpasswordrules.com/sites/onleihe/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
arrakeen_urbanite [he/him] » 🌐
@arrakeen_urbanite@universeodon.com
PSA: Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs. After reading this, I removed all installed apps from my in-use LG TV, and told my router to deny internet access to it. I’ve been using an Apple TV device for all living room streaming anyway. Also applies to Samsung TVs. https://spur.us/blog/smart-tv-apps-residential-proxy-sdks
#CyberSecurity #LG #Samsung
This dumb password rule is from Sears.
"cAsE sensitive, no spaces, ! or ?
8 characters min - 1 letter, 1 number
Can't repeat same character more than 3 times in a row
Cannot be or contain your username or email address"
https://dumbpasswordrules.com/sites/sears/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Premera Blue Cross.
Password must contain 8-30 characters, including one letter and one number.
"Special characters allowed" seems to mean a very small handful of choices you can only find through trial and error `-_'.@`
https://dumbpasswordrules.com/sites/premera-blue-cross/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from Hetzner.
- 8 or more characters
- At least one uppercase and one lowercase letter
- At least one number or special character
Okay, fair enough, but after putting in a password with some special characters this message appears:
- Invalid characters, allowed are: A-Z a-z 0-9 ä ö ü ß Ä Ö Ü ^ ! $ % / ( ) = ?...
https://dumbpasswordrules.com/sites/hetzner/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from ICAgile.
Observed on November 17, 2020:
Password must contain:
- 8-15 total characters
- At least one lowercase letter
- At least one uppercase letter
- At least one number
- At least one special character (e.g., !#$%^*)
They don't seem to have a public registration form. You receive a registration link...
https://dumbpasswordrules.com/sites/icagile/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
This dumb password rule is from AOK (German Health Insurance).
This is the online customer portal of the German health insurance company AOK. They have an extensive set of rules for both passwords and usernames.
The password rules are:
- Length between 8 and 14 characters
- At least one letter, one number and one special character
- Special characters are: !...
https://dumbpasswordrules.com/sites/aok-german-health-insurance/
#password #passwords #infosec #cybersecurity #dumbpasswordrules
KDDI's email system for internet service providers has been breached, the company said, with up to 14.22 million sets of email addresses and passwords possibly leaked. https://www.japantimes.co.jp/business/2026/06/24/companies/kddi-data-breach-cyberattack/?utm_medium=Social&utm_source=mastodon #business #companies #cybersecurity #kddi #personalinformation