cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from BMW ConnectedDrive.

Although the prompt suggests good things, after many failed attempts to
set a new password, it turns out you can ONLY use the special characters
shown in the prompt

dumbpasswordrules.com/sites/bm

    Wen boosted

    [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
    @MissConstrue@mefi.social

    Hey, were you feeling at all optimistic about anything? Silly you. Brian, @briankrebs, has a new story about a new data leak. Yay! This one is bad. Badder than usual.

    Evidence suggests that the data is being exfiltrated from New Orleans-based identity provider idscan.net, even as we speak.

    The company provides identity verification services for numerous big brands, including retailers, cannabis dispensaries, car rental companies, financial institutions, et al., with more than 21 million verifications monthly, at more than 20,000 locations around the world.

    So, that’s fun! All the deets at Brian’s site:

    krebsonsecurity.com/2026/09/fb

      [?]SP⟁CED GO⟁T » 🌐
      @finner@appdot.net

      Well this seems a bit wrong.

      I was trying to click on the Support link in the menu, but it seems broken and I clicked on the Open Box link instead.

      And that loads a page of crypto casino links.

      Im assuming the townew us site has been .

      townew.us/

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from SunTrust.

        At least there are a variety of special characters to choose from.

        dumbpasswordrules.com/sites/su

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Lenovo.

          - **Between 8 and 20 characters, not more.**
          - 1 alphabetic letter
          - 1 number (0-9)
          - **1 symbol ($!#&)**

          dumbpasswordrules.com/sites/le

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Eurocircuits.

            Minimum 4 and maximum 30 chars. Use only letters (a-z), numbers (0-9) and underscore (_)

            dumbpasswordrules.com/sites/eu

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Dwr Cymru (Welsh Water).

              Limits password length to a maximum of 16 characters

              dumbpasswordrules.com/sites/dw

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Very.co.uk.

                Password field allows *only* the listed Special Characters ($ . , ! % ^ \*).
                You're also forced to use both upper, and lower letters, as well as a number.

                dumbpasswordrules.com/sites/ve

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from GoDaddy SFTP.

                  Max 14 characters for the most important password in your shared hosting environment.

                  dumbpasswordrules.com/sites/go

                    Socket boosted

                    [?]AA » 🌐
                    @AAKL@infosec.exchange

                    New.

                    Socket: 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds socket.dev/blog/packagist-them @SocketSecurity

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Raiffeisen Bank Serbia.

                      There are a couple of password limitations when creating a new account (and
                      changing existing password) on Raiffeisen Bank Serbia on-line banking portal.
                      Password length is limited to minimum 8 and maximum 32 characters. Also, minimum
                      uppercase letters 1, minimum lowercase letter 1, minimum digit...

                      dumbpasswordrules.com/sites/ra

                        Tim Hergert boosted

                        [?]Justin Derrick » 🌐
                        @JustinDerrick@infosec.exchange

                        Hey Mastodon.

                        I’ve been tasked with building a small camera system for monitoring a pet - and the request specifically asks for it to have zero services. There’s a mostly-static IP, and web traffic is permitted. I’m planning on putting it behind a self-hosted VPN connection…

                        What I need help with is decent hardware that has an open source firmware - or hardware that can be flashed with an open source firmware. HD or better (3-8MP?) with support for high quality video (MPEG4?). Bonus Points for POE & Pan/Tilt/Zoom.

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from HDFC Bank.

                          Only a maximum of 15 characters and some special characters are not allowed.

                          dumbpasswordrules.com/sites/hd

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from NordVPN.

                            - Password cannot be longer than 48 characters.

                            dumbpasswordrules.com/sites/no

                              [?]Dumb Password Rules » 🤖 🌐
                              @dumbpasswordrules@infosec.exchange

                              This dumb password rule is from CAF (French Family Allowance Fund).

                              You have to enter your 8-digit password using this Frenchy keypad.

                              dumbpasswordrules.com/sites/ca

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from NVV (Nordhessische VerkehrsVerbund).

                                Password length must be 4 to 10 characters with only a few special characters allowed.

                                dumbpasswordrules.com/sites/nv

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Itaú Bank.

                                  I know, it's in spanish, let me translate this monstrosity for you.

                                  - Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
                                  - You must use 8 characters.
                                  - The password must contain at least one letter and at least one number.
                                  - ...

                                  dumbpasswordrules.com/sites/it

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from E-Redes.

                                    Portuguese power distribution company, which requires short passwords (10 to 15 characters), no repetition of the same character, not using the username, the word "PASS" or the word "SAP" in the password, and limiting which special characters can be used.

                                    dumbpasswordrules.com/sites/e-

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      [?]Andy Wootton » 🌐
                                      @woo@fosstodon.org

                                      @GossiTheDog They aren't clueless but when I worked in , they didn't have a good history of sharing intelligence gained with others, in case it damaged brand value.

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Zurich.

                                        Password must be EXACTLY 8 characters long.

                                        Alpha numeric characters ONLY.

                                        The first character must be alphabetic.

                                        NO spaces.

                                        The new Password cannot be the same as the last 32 passwords you have used. (they actually store your last 32 passwords)

                                        dumbpasswordrules.com/sites/zu

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from Polytechnique Montreal.

                                          Passwords must have a minimum length of 8 characters

                                          Passwords must have a maximum length of 30 characters

                                          Passwords must contain a minimum of 2 digits

                                          Passwords must contain a minimum of 2 letters

                                          Password must be different than the last one used

                                          Passwords may contain these special characte...

                                          dumbpasswordrules.com/sites/po

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from University of Windsor.

                                            The password policy applies to alumni as well. Must be at least 10
                                            characters long, with at least 1 upper case and 1 lower case
                                            character, at least 1 number, at least 1 special character. Password
                                            expires every 120 days, and you can't reuse an old one.

                                            dumbpasswordrules.com/sites/un

                                              Wen boosted

                                              [?]Ian Campbell 🏴 » 🌐
                                              @neurovagrant@masto.deoan.org

                                              Hello friends, I've seen the below image come up a few times elsewhere and am going to expound a little!

                                              While the hyperlinks in the image display correctly, those aren't actually the addresses of those sites! Instead, they're the Internationalized Domain Name replacements - examples of what are called IDN Homograph Attacks.

                                              It's incredibly hard to include all characters from all active alphabets in the mechanisms that resolve domain names - so currently that letter set is restricted, and instead uses a translation system called Punycode to move between a visual URL with the correct characters and a domain name your computer can actually resolve to a website.

                                              So while neurovagrant[.]com is fine either way, nӘ̃urovagrant[.]com isn't! The actually domain would be xn--nurovagrant-rkg322d[.]com.

                                              Notice that xn-- ! That's what tells browsers and other software that it's an IDN domain, and to try and translate it.

                                              Attackers use this to their benefit. So:

                                              xn--mcrosoft-security-teams-1ec[.]com can appear in your email, on your twitter feed, in other places visually as: mícrosoft-security-teams[.]com

                                              You may think you're signing in to check your retirement at vanguarɗ[.]com but it's actually sent you to xn--vanguar-4cd[.]com

                                              A link that appears as vḙnmo[.]com actually sends you to the website xn--vnmo-q64a[.]com

                                              They even target kids! Take a look at xn--rblox-jua[.]com - which looks like röblox[.]com in most settings. Note the diacritical mark above the first o.

                                              If anything looks off, there's a reason. Always view links with skepticism, don't click on things unnecessarily, and always sign into the sites you use by going to the domain name you know.

                                              Stay frosty out there, friends.

                                              Screenshot that says "Spot the difference" and shows two different maybank and citibank addresses - one that is legitimate, and one that uses a cyrillic 'a' to send you to an illegitimate site.

                                              Alt...Screenshot that says "Spot the difference" and shows two different maybank and citibank addresses - one that is legitimate, and one that uses a cyrillic 'a' to send you to an illegitimate site.

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Munich Foerdermittel Portal.

                                                You register on their funding portal and receive an email with an activation link to set a password.
                                                The email further informs you about their password policy:
                                                - At least 8, but no more than 20 characters
                                                - At least one lowercase and uppercase letter
                                                - At least two digits (1,2,3,4,5,6,7,8,9,0) or...

                                                dumbpasswordrules.com/sites/mu

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Jaa Lifestyle.

                                                  When we try to change password and accidentally gave a wrong password for confirm password.
                                                  Lets try to read and figure out what they are trying to point out.

                                                  dumbpasswordrules.com/sites/ja

                                                    [?]Mike Sheward » 🌐
                                                    @SecureOwl@infosec.exchange

                                                    It is the year 2026 and I am still finding the one of the fastest ways to get local admin in a Windows environment is to search out the unattended setup XML's, because the passwords are still only base64 encoded.

                                                    People don't realize and just leave the files out on open file shares so they are easy to grab.

                                                    Thanks, people!

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Sephora.

                                                      Password must be between 6 and 12 characters. No other rules
                                                      specified.

                                                      dumbpasswordrules.com/sites/se

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from KPMG Talent Community.

                                                        While stating otherwise, the site actually *accepts a backslash* in the password
                                                        and displays a forward slash as the example of the disallowed backslash
                                                        Password:
                                                        - Must be at least 8 characters long
                                                        - Must contain at least 1 number
                                                        - Must contain at least 1 letter
                                                        - Must contain at least 1 spec...

                                                        dumbpasswordrules.com/sites/kp

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Sparkasse.

                                                          „Sparkasse“ is a group of banks which is pretty popular in Germany. It
                                                          calls its passwords „PIN“ („persönliche Identifikations-Nummer“ —
                                                          personal identification number), the rules are pretty horrific and its
                                                          not even a number, even though it is called as such! Here is a
                                                          screenshot from the branch...

                                                          dumbpasswordrules.com/sites/sp

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from Easyjet.

                                                            No more than 20 characters, use any symbols you like... Oh except #, &, +, or space of course.

                                                            dumbpasswordrules.com/sites/ea

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from LINE.

                                                              Password must:
                                                              - be between 8 to 20 characters
                                                              - not contain characters that repeat in a row
                                                              Password must contain three of the following:
                                                              - an upper-case letter
                                                              - a lower-case letter
                                                              - a number
                                                              - a symbol

                                                              dumbpasswordrules.com/sites/li

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Replit.

                                                                Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                                                                dumbpasswordrules.com/sites/re

                                                                  [?]mc.fly [he/him] » 🌐
                                                                  @mcfly@milliways.social

                                                                  Every single blueteamer in information security at the moment...

                                                                  tis picture shows the "this is fine meme", a comic dog sitting in a room on fire saying "this is fine"

                                                                  Alt...tis picture shows the "this is fine meme", a comic dog sitting in a room on fire saying "this is fine"

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from SONY.

                                                                    - between 8 and 30 characters
                                                                    - at least one number or special character
                                                                    - not part of email address
                                                                    - avoid common passwords
                                                                    - repeating characters 3 or more times should be avoided
                                                                    - currency characters and 3 or more consecutive characters, also in reverse order, should be avoided
                                                                    Somehow "$" i...

                                                                    dumbpasswordrules.com/sites/so

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Mobility.

                                                                      The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
                                                                      The password has to be exactly 6 digits long, only numbers allowed.

                                                                      dumbpasswordrules.com/sites/mo

                                                                        Socket boosted

                                                                        [?]AA » 🌐
                                                                        @AAKL@infosec.exchange

                                                                        New.

                                                                        Socket: Popular Rust Crates Compromised in Build-Time Supply Chain Attack socket.dev/blog/popular-rust-c @SocketSecurity

                                                                          Wen boosted

                                                                          [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                          @MissConstrue@mefi.social

                                                                          Oh. My. Bob, you can override guardrails with . Beautiful.

                                                                          “Rony Utevsky, a researcher at security firm , recently discovered a simple way to completely bypass that restriction. Rather than composing the harmful instruction in plaintext, the hacker encrypts it. The website hosting the ciphertext also includes plaintext instructions for decrypting the encrypted content, along with the decryption key. Using this simple sequence, then follows the command as soon as the user instructs the assistant to summarize the page. There is no warning, and no confirmation is required.”

                                                                          arstechnica.com/security/2026/

                                                                          Ahahahahahahahah. Turn them off my dudes, your techbro fantasies are disasters.

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Dnevnik.ru.

                                                                            Silently (sic!) trim password to 30 symbols.

                                                                            That causes the stupid case when you could successfully registrate an account with password length of 52 and can't login with the password.

                                                                            dumbpasswordrules.com/sites/dn

                                                                              [?]Dumb Password Rules » 🤖 🌐
                                                                              @dumbpasswordrules@infosec.exchange

                                                                              This dumb password rule is from CWT Business Travel Management Company.

                                                                              Password:
                                                                              - 8 to 32 characters long
                                                                              - Must contain a combination of letters, numbers and symbols
                                                                              - Must be different from your username
                                                                              - Must be different from 5 previous passwords

                                                                              dumbpasswordrules.com/sites/cw

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from Jaa Lifestyle.

                                                                                When we try to change password and accidentally gave a wrong password for confirm password.
                                                                                Lets try to read and figure out what they are trying to point out.

                                                                                dumbpasswordrules.com/sites/ja

                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Ticketmaster.de.

                                                                                  Your password length is limited between 8 and 32 characters.

                                                                                  dumbpasswordrules.com/sites/ti

                                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                                    @dumbpasswordrules@infosec.exchange

                                                                                    This dumb password rule is from Nectar API.

                                                                                    The Nectar website allows strong passwords.
                                                                                    However, when trying to link my Sainsbury's account, I found the API has different ideas...
                                                                                    - Password field length capped to 16 characters

                                                                                    dumbpasswordrules.com/sites/ne

                                                                                      Back to top - More...