cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Peter N. M. Hansteen » 🌐
@pitrh@mastodon.social

[?]LWN.net » 🌐
@lwn@fedi.lwn.net

Woodruff: You shouldn't trust trusted publishing

lwn.net/Articles/1081690/

    Wen boosted

    [?]Mark » 🌐
    @paka@mastodon.scot

    Security and Privacy by Design

    Get a truly without hidden or : , lists, and groups are managed in a manner directly on the involved devices – no is stored on a server.

    This way, your communication remains and fully under your control at all times.

    threema.com/en/products/private

    Comparison chart of the following messenger apps: 

Threema Private
Whatsapp
Signal
Telegram

There's a lot of text in this graphic so here's a summary of the most important aspects:

Jurisdiction:

Switzerland - Threema Private

USA - Whatsapp, Signal

Unclear - Telegram

Funding:

- Meta data/advertising - Whatsapp
- Donations - Signal
- Pavel Dorov, subscriptions, advertising - Telegram
- App users ($6 one time fee) - Threema Private

Privacy by Design:

- No phone number of email address required - Threema Private

- Phone number required - Whatsapp, Signal, Telegram

    Alt...Comparison chart of the following messenger apps: Threema Private Whatsapp Signal Telegram There's a lot of text in this graphic so here's a summary of the most important aspects: Jurisdiction: Switzerland - Threema Private USA - Whatsapp, Signal Unclear - Telegram Funding: - Meta data/advertising - Whatsapp - Donations - Signal - Pavel Dorov, subscriptions, advertising - Telegram - App users ($6 one time fee) - Threema Private Privacy by Design: - No phone number of email address required - Threema Private - Phone number required - Whatsapp, Signal, Telegram

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      [?]signifier of eschaton » 🌐
      @lw@mastodon.bsd.cafe

      RouterOS 7.23.2 release notes:

      !) fixed a service security issue, home user with default config not affected, but we recommend the upgrade for all users regardless;

      so... we fixed a security vulnerability, but we're not going to tell you what it is, so you have no idea how urgent this update is or how exposed you are or if you're even affected at all.

      thanks, i guess?

      (rumour has it this is a memory disclosure or potential RCE in pptp/l2tp/ppoe...)

        [?]Peter N. M. Hansteen » 🌐
        @pitrh@mastodon.social

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]Tom :damnified: » 🌐
        @thomas@metalhead.club

        🔑 DNSSEC is now enabled for media.metalhead.club as well!

        Previously this has only been the case for metalhead.club, but not for media resources, because the zone files for my CDN are hosted on external name servers. :server:

        dnsviz.net/d/media.metalhead.c

        Lets hope my config change does not cause any issues with the service 😅

          [?]LWN.net » 🌐
          @lwn@fedi.lwn.net

          [?]Hylke Bons 🥜 » 🌐
          @hbons@mastodon.social

          done! drew the rest of the f***ing owl.

          App icon for BitRitter in the GNOME icon style. A light blue shield with a thick darker blue border. Overlayed is a password field.

          Alt...App icon for BitRitter in the GNOME icon style. A light blue shield with a thick darker blue border. Overlayed is a password field.

            [?]h3artbl33d :openbsd: :antifa: [Try/Me] » 🌐
            @h3artbl33d@exquisite.social

            Whereas DirtyClone exploits a kernel module (which can be tackled by unloading and blocking it), Bad Epoll (CVE-2026-46242) does not.

            Alt...Elmo reigning fire

              [?]Tim Mak » 🌐
              @timkmak@journa.host

              , AND AGREE TO ENSURE IN : On July 3, French and UK issued a joint announcing an with Oman, in which the three countries will work together to ensure safe through the .

              gov.uk/government/news/joint-s

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                [?]Michal Bryxí [he/him] » 🌐
                @MichalBryxi@mastodon.world

                question: Why no service shows you a list of currently logged in sessions right after login? In my head, this would address so much bigger security space than the “automatic session timeout” theatre:
                - User is in control
                - User can spot and question deviations
                - No thing is taking decision on behalf of user
                - Waaaaaaay better UX

                  [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                  @MissConstrue@mefi.social

                  Ok, to start, let me define "" in . Steganography in computer security is the practice of hiding information within another file, message, image, or video, making the concealed information undetectable to an unsuspecting observer.

                  It is not necessarily malicious, but it certainly can be. I tell you that story to tell you this one:

                  Code Is Steganographically Marking Requests

                  CC silently alters the system prompt using invisible-ish Unicode markers. It encodes proxy / gateway classification into a sentence that looks like plain English. It hides the domain list behind XOR and base64.

                  Is it malicious? Probably not. Is a pretty big marker on the "Why not to trust AI companies" list of reasons? Yeah, yeah it is.

                  thereallo.dev/blog/claude-code

                    [?]LWN.net » 🌐
                    @lwn@fedi.lwn.net

                    [$] Secure Boot certificate expiration is here

                    Linux users who have Secure Boot enabled on their systems rely on certificates issued by Microsoft to verify the software used to boot a system is trusted by the user. One of those [...]

                    lwn.net/Articles/1079808/

                      [?]LWN.net » 🌐
                      @lwn@fedi.lwn.net

                      [?]Nonilex » 🌐
                      @Nonilex@masto.ai

                      admin plans to withhold homeland to force into changes

                      The Trump admin is threatening to withhold tens of millions of dollars in federal homeland security funds from states unless they adopt a sweeping set of election changes, according to multiple sources & internal documents obtained by CNN.


                      cnn.com/2026/06/22/politics/ho

                        Wen boosted

                        [?]Rita, antifascist 🏴🦯🦯🦯 [any] » 🌐
                        @OldSquida2@kolektiva.social

                        RE: todon.eu/@MediaActivist/116840

                        “It’s time for people to have control over their own tech, not governments and corporations. Worker-owned, The People's Tech will help you and your organisation choose at the intersection of , , AND . Stay tuned!” ~ @thepeoplestech

                        buttondown.com/thepeoplestech

                          [?]Peter N. M. Hansteen » 🌐
                          @pitrh@mastodon.social

                          [?]LWN.net » 🌐
                          @lwn@fedi.lwn.net

                          Paco Hope boosted

                          [?]Stefan Bohacek » 🌐
                          @stefan@stefanbohacek.online

                          Holy crap.

                          "Nearly a million passports and photo IDs from multiple countries were exposed across unprotected public URLs, accessible to anyone with a link. The documents remained discoverable this way for months, according to reporting by The Verge, before being taken offline."

                          cambridgeanalytica.org/data-br

                          Original article: theverge.com/tech/947157/passp

                          Via an extensive series of links starting at mastodon.social/@Gargron/11682

                            [?]AmmarSpaces » 🌐
                            @AmmarSpaces@infosec.exchange

                            The doom of cyber security is not about companies get breached by AI.

                            But, if the one who should be protected (the citizen) no longer own the rights of their own in digital world , and being watched 24 hours 7 days.

                            In that age, infosec is no longer about "protecting people", but it shifted to "protecting interest".

                              [?]BLACKVOID ⚫️ » 🌐
                              @blackvoid@mastodon.social

                              How to update reverse proxy with zero downtime? A new one in parallel and switch a port on the router.

                              After I have been postponing the migration to a new/latest version, today I finally did it.

                              With too many changes along the way I didn't want to risk it. 50 hosts to manually move over, I took the time to clean up some old and unused records.

                              Running now the latest, single setup.

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                [?]Mysk🇨🇦🇩🇪 » 🌐
                                @mysk@mastodon.social

                                🚨PSA: If you think you're a targeted individual, don't install macOS apps from the web. macOS code signing and TCC are broken. We accidentally found a bug that lets any command modify the binaries of other apps, including Signal, Brave, Chrome, and even Xcode. Watch the demo👇

                                Alt...Demo showing how a command replaces the binaries of Signal, Brave, and Slack

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  The "Akrites" vulnerability-mitigation project launches

                                  lwn.net/Articles/1079657/

                                    Aral Balkan boosted

                                    [?]Tuta » 🌐
                                    @Tutanota@mastodon.social

                                    🚨 They are bringing back 🚨

                                    Metsola doesn't understand that no means no.

                                    Discussion is scheduled for Monday, so act now: fightchatcontrol.eu/

                                    Screenshot from fight chat control website

                                    Alt...Screenshot from fight chat control website

                                      [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                                      @gamingonlinux@mastodon.social

                                      [?]Doug Belshaw » 🌐
                                      @dajb@social.coop

                                      Securing Verifiable Credentials for a world of agentic AI substrate.dougbelshaw.com/secu

                                      An artist’s illustration of artificial intelligence (AI). This image depicts how AI can help humans to understand the complexity of biology. It was created by artist Khyati Trehan as part of the Visualising AI project launched by Google DeepMind." w

                                      Alt...An artist’s illustration of artificial intelligence (AI). This image depicts how AI can help humans to understand the complexity of biology. It was created by artist Khyati Trehan as part of the Visualising AI project launched by Google DeepMind." w

                                        [?]LWN.net » 🌐
                                        @lwn@fedi.lwn.net

                                        LWN.net boosted

                                        [?]Python Software Foundation » 🌐
                                        @ThePSF@fosstodon.org

                                        Great coverage from @lwn of the PSF PyPI Safety & Security Engineer @miketheman's talk on Trusted Publishing at Open Source Summit. 36% of @pypi uploads now use Trusted Publishing. Is yours one of them?

                                        lwn.net/Articles/1076205/

                                          [?]MiaK 🏴󠁧󠁢󠁷󠁬󠁳󠁿 🇵🇸 » 🌐
                                          @MiaMarkTwo@syzito.xyz

                                          Tick box to prove you're not a bot

                                          Pick all the images of a fire hydrant

                                          Now pick all the images of a motorcycle

                                          Now pick all the images of a bus

                                          Now pick all the images of a motorcycle again

                                          Now pick all the images of traffic lights

                                          Enter your email and password

                                          We've sent you a one-time code

                                            [?]Andy Fletcher » 🌐
                                            @X31Andy@mastodon.green

                                            Where I am working has a 3 month password change policy and they send daily reminders 2 weeks before the current one expires.

                                            I always wait until the last day to change my password as changing it early feels wasteful and I want to get the maximum use from each password before discarding it.

                                            I have pointed out to IT that recent recommendations are not to have a periodic password expiry as it encourages poor user security practices but it fell on deaf ears.

                                              [?]LWN.net » 🌐
                                              @lwn@fedi.lwn.net

                                              [?]Python Software Foundation » 🌐
                                              @ThePSF@fosstodon.org

                                              The Python Security Response Team patched an authentication bypass in the python.org release management API in under 48 hours. No evidence of exploitation, all artifacts verified.

                                              Check out the full writeup 👇
                                              pyfound.blogspot.com/2026/06/m

                                                [?]LWN.net » 🌐
                                                @lwn@fedi.lwn.net

                                                [?]LWN.net » 🌐
                                                @lwn@fedi.lwn.net

                                                [?]Python Software Foundation » 🌐
                                                @ThePSF@fosstodon.org

                                                Watch PSF PyPI Safety & Security Engineer @miketheman's talk from Open Source Summit NA 2026: Trusted Publishing uses OIDC to generate short-lived tokens from CI/CD. No passwords. No tokens to rotate. No secrets in repos.

                                                youtube.com/watch?v=i0BWrWdZ3Wg

                                                  [?]LWN.net » 🌐
                                                  @lwn@fedi.lwn.net

                                                  [?]nixCraft 🐧 » 🌐
                                                  @nixCraft@mastodon.social

                                                  strncpy() has been removed from the kernel. All former callers have +been migrated to safer alternatives. strncpy() is major source of bugs. The replacements are listed now.
                                                  git.kernel.org/pub/scm/linux/k
                                                  FYI, this is starting from Linux kernel v7.2 but it was the need of the hour.

                                                    Chewie boosted

                                                    [?]PrivacyDigest » 🌐
                                                    @PrivacyDigest@mas.to

                                                    Think Of The Children: How To Force For All Internet Traffic (2023)

                                                    OR ... How to trick billions into voluntarily self and Real ID

                                                    Preface: Recently some states and a country have been implementing a centralized commercial database that will be required to upload state ID's and other documents to prove one is an when logging into adult websites. And this is how it starts.

                                                    nochan.net/b/Internet-Crap/202

                                                      Back to top - More...