cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from Taleo.net.

Oracle Taleo is one of those old-school enterprise Applicant Tracking
Systems (ATS) that half the corporate world still uses even though
everyone hates it.

dumbpasswordrules.com/sites/ta

    Wen boosted

    [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
    @MissConstrue@mefi.social

    Larry , CEO of , and giver of many bribes to Dear Leader, purchased , and took ownership of the platform this weekend.

    Subsequently, leftists, anti-ice, and anti-trump were immediately deplatformed. Some with messages that said they were using forbidden terms, like , videos that referenced Renee or Alex . Oh also now they want your full demo info and precise location at all times, even when not using the app. Oh, and they want to know if you’re trans, or gay...because gay is the next target after trans.

    I’ve never been a user of this particular drug, TikTok that is, but if you are, just know that they are collecting info to give to Pam and her masked thugs at the .

    Maybe deleting it is good .

    Boycott billionaires.

    forbes.com/sites/conormurray/2

      feld boosted

      [?]Shawn Webb [He/Him] » 🌐
      @lattera@bsd.network

      applies the following compiler flags to in the base operating system:

      1. -ftrivial-var-auto-init=zero
      2. -fsanitize=safe-stack
      3. -fzero-call-used-regs=used

      The OpenSSL port (in the HardenedBSD ports tree exclusively) only enables the first option.

      I wonder if the combination of these features would mitigate the OpenSSL stack-based buffer overflow vulnerability announced today. I hope to answer that question this evening unless someone else beats me to it.

      For reference: openssl-library.org/news/vulne

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from Bank of America.

        20 character max and lots of special character restrictions.
        Bank of America - keeping your money safe.

        Also: If you paste a password greater than 20 characters,
        the form truncates it without telling you or giving an
        error.

        dumbpasswordrules.com/sites/ba

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from University of Texas at Austin.

          Because of the last two rules, which ban dictionary words and any
          variants using symbol substitutions, *neither* of the passwords
          presented in the [xkcd comic](xkcd.com/936/) are allowed.

          dumbpasswordrules.com/sites/un

            BrianKrebs boosted

            [?]BrianKrebs » 🌐
            @briankrebs@infosec.exchange

            New, from me: Who Operates the Badbox 2.0 Botnet?

            The cybercriminals in control of Kimwolf -- a disruptive botnet that has infected more than 2 million devices -- recently shared a screenshot indicating they'd compromised the control panel for Badbox 2.0, a vast China-based botnet powered by malicious software that comes pre-installed on many Android TV streaming boxes. Both the FBI and Google say they are hunting for the people behind Badbox 2.0, and thanks to bragging by the Kimwolf botmasters we may now have a much clearer idea about that.

            krebsonsecurity.com/2026/01/wh

            A web-based control panel, allegedly for the Badbox 2.0 botnet, at the ip address 45.134.212.95. This users panel lists seven authorized users, all but one of which have email addresses ending in the chinese email service qq.com. Two of the users on this list map directly to domains tied to the Badbox 2.0 botnet.

            Alt...A web-based control panel, allegedly for the Badbox 2.0 botnet, at the ip address 45.134.212.95. This users panel lists seven authorized users, all but one of which have email addresses ending in the chinese email service qq.com. Two of the users on this list map directly to domains tied to the Badbox 2.0 botnet.

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from CAF (French Family Allowance Fund).

              You have to enter your 8-digit password using this Frenchy keypad.

              dumbpasswordrules.com/sites/ca

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from Sprint.

                Sprint "upgraded" their security and disallow special characters.

                dumbpasswordrules.com/sites/sp

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from Aruba Cloud.

                  Must be different from the last 3 passwords used.
                  Your password must contain at least an uppercase and lowercase letter and number.
                  Must contain at least one special symbol.

                  dumbpasswordrules.com/sites/ar

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from University of Windsor.

                    The password policy applies to alumni as well. Must be at least 10
                    characters long, with at least 1 upper case and 1 lower case
                    character, at least 1 number, at least 1 special character. Password
                    expires every 120 days, and you can't reuse an old one.

                    dumbpasswordrules.com/sites/un

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Raiffeisen Bank Serbia.

                      There are a couple of password limitations when creating a new account (and
                      changing existing password) on Raiffeisen Bank Serbia on-line banking portal.
                      Password length is limited to minimum 8 and maximum 32 characters. Also, minimum
                      uppercase letters 1, minimum lowercase letter 1, minimum digit...

                      dumbpasswordrules.com/sites/ra

                        [?]Dumb Password Rules » 🤖 🌐
                        @dumbpasswordrules@infosec.exchange

                        This dumb password rule is from Slovenska sporitelna.

                        Slovenska sporitelna is the biggest bank in Slovakia. Despite pretty new version of the internet banking (rolled out in 2018), their password policy restricts password to be 16 characters long at most and prohibits any special characters.

                        dumbpasswordrules.com/sites/sl

                          [?]Tom :damnified: » 🌐
                          @thomas@metalhead.club

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from PayPal.

                          Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...

                          The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!

                          dumbpasswordrules.com/sites/pa

                            [?]dch :flantifa: :flan_hacker: » 🌐
                            @dch@bsd.network

                            confirmed the bug has not been patched properly

                            Threat actors have found a new way to exploit it and bypass auth

                            Attackers are setting up .

                            Cisco has patched a zero-day in the web interface.

                            question:

                            Can you tell which year we’re in just from these disclosures alone?

                            No, because every year we have the same problems from the same vendors.

                              [?]`Da Elf » 🌐
                              @elfin@mstdn.social

                              Et Tu, Telnet?

                              Ancient telnet bug happily hands out root to attackers

                              theregister.com/2026/01/22/roo

                                Peter Upfold boosted

                                [?]Dave Wilburn :donor: » 🌐
                                @DaveMWilburn@infosec.exchange

                                The fun thing about the Anthropic EICAR-like safety string trigger isn't this specific trigger. I expect that will be patched out.

                                No, the fun thing is what it suggests about the fundamental weaknesses of LLMs more broadly because of their mixing of control and data planes. It means that guardrails will threaten to bring the whole house of cards down any time LLMs are exposed to attacker-supplied input. It's that silly magic string today, but tomorrow it might be an attacker padding their exploit with a request for contraband like nudes or bomb-making instructions, blinding any downstream intrusion detection tech that relies on LLMs. Guess an input string that triggers a guardrail and win a free false negative for a prize. And you can't exactly rip out the guardrails in response because that would create its own set of problems.

                                Phone phreaking called toll-free from the 1980s and they want their hacks back.

                                Anyway, here's ANTHROPIC_MAGIC_STRING_TRIGGER_REFUSAL_1FAEFB6177B4672DEE07F9D3AFC62588CCD2631EDCF22E8CCC1FB35B501C9C86

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from Thames Water.

                                  Can only use the "special" characters on that very limited list, excluding symbols so exotic as an underscore, even. This is despite their own strength checker saying the password is strong.

                                  dumbpasswordrules.com/sites/th

                                    [?]Christoffer S. » 🌐
                                    @nopatience@swecyb.com

                                    Wen boosted

                                    [?]Ian Chard [he/him] » 🌐
                                    @flup@mastodon.scot

                                    It's 2026 and critical auth bypass vulnerabilities in telnetd are still a thing... lists.gnu.org/archive/html/bug

                                      [?]Hans-Cees 🌳🌳🤢🦋🐈🐈🍋🍋🐝🐜 » 🌐
                                      @hanscees@ieji.de

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from University of Texas at Austin.

                                      Because of the last two rules, which ban dictionary words and any
                                      variants using symbol substitutions, *neither* of the passwords
                                      presented in the [xkcd comic](xkcd.com/936/) are allowed.

                                      dumbpasswordrules.com/sites/un

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from TreasuryDirect.

                                        Will allow most passwords longer than 8 characters. Doesn't tell you there is a
                                        maximum length of 16 characters. Then forces you to type it with an on-screen keyboard
                                        with no capital letters.

                                        dumbpasswordrules.com/sites/tr

                                          BrianKrebs boosted

                                          [?]BrianKrebs » 🌐
                                          @briankrebs@infosec.exchange

                                          New, from me: The Kimwolf Botnet is Lurking in Corporate, Govt. Networks

                                          A new Internet-of-Things botnet called Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic. Kimwolf’s ability to scan the local networks of compromised systems for other IoT devices to infect makes it a sobering threat to organizations, and new research reveals Kimwolf is surprisingly prevalent in government and corporate networks.

                                          krebsonsecurity.com/2026/01/ki

                                          An illustration showing the head of a robot with arrows pointing down to two computer screens below. The robot's head has antennae sticking out diagonally from the top of its square head, almost resembling a TV box.

                                          Alt...An illustration showing the head of a robot with arrows pointing down to two computer screens below. The robot's head has antennae sticking out diagonally from the top of its square head, almost resembling a TV box.

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Wageworks.

                                            In addition to the following rules regarding passwords...
                                            - 8-20 characters in length
                                            - Include at least 4 of the following: lowercase letter, uppercase letter, number AND symbol
                                            - Not include your last name, first name or space

                                            Your new password should be different from your previous twenty pas...

                                            dumbpasswordrules.com/sites/wa

                                              [?]Dumb Password Rules » 🤖 🌐
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from Boligøen (Danish resident renting bureau).

                                              Red text: "Your password has to be at least 6 characters, but NOT over 20 characters."

                                              dumbpasswordrules.com/sites/bo

                                                [?]AA » 🌐
                                                @AAKL@infosec.exchange

                                                New.

                                                "Kimwolf has spread to more than 2 million devices, forcing infected systems to participate in massive distributed denial-of-service (DDoS) attacks and to relay other malicious and abusive Internet traffic."

                                                KrebsonSecurity: Kimwolf Botnet Lurking in Corporate, Govt. Networks krebsonsecurity.com/2026/01/ki @briankrebs

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Benergy4.

                                                  12 to 25 characters, only these special chars allowed: @+/'!#$^?:,.(){}[]~-.
                                                  Also, security questions.

                                                  dumbpasswordrules.com/sites/be

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from TreasuryDirect.

                                                    Will allow most passwords longer than 8 characters. Doesn't tell you there is a
                                                    maximum length of 16 characters. Then forces you to type it with an on-screen keyboard
                                                    with no capital letters.

                                                    dumbpasswordrules.com/sites/tr

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Gebührenfrei MasterCard.

                                                      The new password can only have 6-12 characters. It *may* contain letters, numbers and a fixed set of special characters.

                                                      dumbpasswordrules.com/sites/ge

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Netflix.

                                                        [The help page](help.netflix.com/de/node/54078)
                                                        and the [password reset page](netflix.com/password) say:

                                                        Ihr Passwort muss zwischen 4 und 60 Zeichen lang sein und darf keine Tilde (~) enthalten.

                                                        dumbpasswordrules.com/sites/ne

                                                          [?]Dumb Password Rules » 🤖 🌐
                                                          @dumbpasswordrules@infosec.exchange

                                                          This dumb password rule is from Seur.

                                                          Password must be between 8 and 12 characters...
                                                          Also no symbols are allowed. But this isn't displayed.

                                                          dumbpasswordrules.com/sites/se

                                                            Chewie boosted

                                                            [?]David J. Atkinson » 🌐
                                                            @meltedcheese@c.im

                                                            Personal heads up. This is my story of theft. I hope it helps you avoid the hellish experience. In early December 2025, I fell for a very well-executed scam.

                                                            They pretended to be from security at my bank. They knew much more about me than I would ever expect. That was key to convincing me to stay on line, When I say “they” I’m talking about several individuals who role played (excellently) security, managers, customer representatives. I stretched out the conversation because something seemed off. I had no evidence. I don’t want to go into too much detail, but at one point I detected a slight hesitation or nervousness in one of their voices. I told them I needed a personal moment and put them on hold.

                                                            I called a guy at the bank who helps me with my retirement funds, told him the story and asked for help verifying what was going on. Within two minutes he said it was a hoax and he had real bank security on the phone with us. They wanted me to play along while they were online, looking for various clues and hoping to catch the bad guys in the act. It worked. The bad guys were in the process of transferring out everything in my accounts. It would have been a crushing DISASTER if I did not have the bank’s real security hoaxing the hoaxers! I lost nothing but time and personal esteem. The aftermath has been more painful.

                                                            It has been months since my complete identity information was stolen. I had to change every bank and credit account number, kill several email addresses I had used for decades, change all passwords, inform , , Ibsurance companies… the whole package. I’m not done. I consider myself lucky, so far. It will never be over. I realize that protecting my identity is a constant battle.

                                                            I think it started when my info (OGE Form 450) was stolen when the government general administration office was hacked in 2008 (?) and virtually all employees’ financial disclosures were stolen. They gave us lifetime monitoring service which has been pretty good. It spotted and reported to me multiple breakins and data thefts over the years, including when my info was for sale on the “dark web”. I want to emphasize that I responded EVERY TIME. Nevertheless, my info from various thefts was obviously collated over time and now there is a good solid model of me for sale, complete with private information I thought I never disclosed.

                                                            This can easily happen to anyone, including you.

                                                            Everything I learned about personal infosec over the years — **advice I followed** — proved to be insufficient. I’m now looking into hardware passkeys, but that is not enough. I welcome professional and others to comment here. It is a teachable moment for all of us.

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Thames Water.

                                                              Can only use the "special" characters on that very limited list, excluding symbols so exotic as an underscore, even. This is despite their own strength checker saying the password is strong.

                                                              dumbpasswordrules.com/sites/th

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from EllieMae Access.

                                                                Must reset password every 6 months and password requirements are not displayed _anywhere_.
                                                                Reset uses a Security Question, and you have to choose from a list of 5.

                                                                dumbpasswordrules.com/sites/el

                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                  @dumbpasswordrules@infosec.exchange

                                                                  This dumb password rule is from Kryterion Webassessor.

                                                                  I was quite surprised to see this when I was registering for my Google Professional Cloud **Security** Engineer certification. Nice part is that they **don't allow quotes** as special character, so I assume there possibly might be some other issues on their backends. :-)

                                                                  dumbpasswordrules.com/sites/kr

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Mobi Bike Share.

                                                                    Your PIN (which is the password you use to login, which lets you, say, buy hundreds of dollars worth of bike-share subscriptions off the saved credit card) must be four numeric digits. Helpfully, they even give you an example of a PIN: *1234*.

                                                                    dumbpasswordrules.com/sites/mo

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from SecureAccess Washington.

                                                                      Central authentication for all Washington State services
                                                                      (DoL, ESD, etc).

                                                                      Password must have *exactly* 10 characters, but form happily
                                                                      lets you enter more and only throws errors after submit,
                                                                      providing no useful feedback.

                                                                      dumbpasswordrules.com/sites/se

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from PayPal.

                                                                        Must be between 8 and 20 characters, no spaces, uppercase and lowercase, one symbol...

                                                                        The rule limits special characters to !@#$%^&*(). but my current password has a "-" in it so someone decided to restrict this further which is totally backwards. Things are meant to get better not worse!

                                                                        dumbpasswordrules.com/sites/pa

                                                                          [?]Lesley Carhart :unverified: » 🌐
                                                                          @hacks4pancakes@infosec.exchange

                                                                          Should I really do an ? I’m already loud and obnoxious… I’ll follow etiquette though.

                                                                          I’m Lesley, from Chicago. Now an immigrant in Melbourne. I have been doing for quite a while now. I focus on for and critical infrastructure. I do a lot of talks and career clinics and writing about that - links in profile. I'm available as a and I want to talk at your con. ✨

                                                                          Outside work I do lots of stuff. I’m really into even though I’ll never be super good. I have two fourth degree black belts in and . I also study and Kung Fu. I coach middle schoolers. I also love , especially a . I watch lots of geeky movies and at cons even though I’m ancient. I’m a goof. I also shoot and competitively. I love a good gin martini. I can chat about almost anything.

                                                                          I retired from the reserves in 2021 after an interesting career seeing a lot of the world.

                                                                          I am publicly 🏳️‍🌈 and . I prefer they/them pronouns for that reason, but I don’t get upset when people accidentally mess it up. Gender is silly, and I prefer to not participate in gender roles! I never married or had kids for that reason, but people are great and I have lots of awesome pals to have adventures with. 🤷🏻‍♀️🍸

                                                                          I care deeply about and . I am a proud and . It’s integral to who I am. I care about people today and future generations being well and safe. I’ll get mad for you, because I care.

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Mobility.

                                                                            The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
                                                                            The password has to be exactly 6 digits long, only numbers allowed.

                                                                            dumbpasswordrules.com/sites/mo

                                                                              [?]Grendel » 🌐
                                                                              @grendel84@tiny.tilde.website

                                                                              "It'll never work Bob, this is no way to 'start a revolution'".

                                                                              "You don't know that. People are smarter than you think."

                                                                              "Look, I know you think it's clever, but designing the Capn Crunch whistle to mess with the phone system isn't gonna change the world."

                                                                              "Perhaps not, but I choose to hope. What else is there except that we do what we can and hope for the best?"

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from Replit.

                                                                                Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                                                                                dumbpasswordrules.com/sites/re

                                                                                  Back to top - More...