cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

Chewie boosted

[?]PrivacyDigest » 🌐
@PrivacyDigest@mas.to

Government-Mandated Software a Looming Threat to

An increasing number of governments around the world are requiring that come with specific software pre-installed. The notion of government-mandated software, whether it is a separate app or a routine part of the operating system, represents a grave threat to our .

aclu.org/news/privacy-technolo

    🗳

    [?]Beardy Star Stuff 🏴🌹🇵🇸 » 🌐
    @dennyhenke@social.coop

    If you're a part of the to and the regime you should absolutely be using @signal which also means you should be donating to Signal. Now, more than ever, they'll need donations. That said, if you cannot afford to donate, you should still use it! We can all contribute to the larger cause in our own way.❤️

    Cross platform, works on almost any recent computing device, fully encrypted texts, calls and video. Folks, use Signal, stay safe.

    I don't use Signal:12
    I use Signal and have donated:71
    I use Signal, I'll donate for the first time today:5
    I'll start using Signal and I'll donate today:1

      [?]Nonilex » 🌐
      @Nonilex@masto.ai

      The was among several to join the US in Afghanistan after NATO’s collective clause was invoked for the first & only time in its history by the following the 9/11 attacks. During the conflict, 457 British service personnel were killed.

      Article 5 of states that an attack on one member is considered an attack against all.

        [?]Terminal Tilt » 🌐
        @terminaltilt@climatejustice.social

        Is it 2026 or 2006? I just went to harden my PayPal account with my new review units.

        Turns out, PayPal still only supports one physical security key. No backups allowed. If you want redundancy, they force you back to TOTP apps or (worse) SMS.

        A screenshot of the PayPal "Manage 2-step verification" settings page. It shows 2 step verification is ON, with a "YubiKey 5C NFC" listed as the only primary device. Under the "Your backups" section, only a "Third-party code generator" authenticator app is listed, with no option to add additional backup security keys.

        Alt...A screenshot of the PayPal "Manage 2-step verification" settings page. It shows 2 step verification is ON, with a "YubiKey 5C NFC" listed as the only primary device. Under the "Your backups" section, only a "Third-party code generator" authenticator app is listed, with no option to add additional backup security keys.

          [?]Tom :damnified: » 🌐
          @thomas@metalhead.club

          Wen boosted

          [?]Ian Chard [he/him] » 🌐
          @flup@mastodon.scot

          It's 2026 and critical auth bypass vulnerabilities in telnetd are still a thing... lists.gnu.org/archive/html/bug

            [?]Tim Mak » 🌐
            @timkmak@journa.host

            Here’s what The Counteroffensive is reading today:

            Putin offered to give $1 billion to ’s Board of Peace from the $5 billion Russian frozen assets in the U.S, at a Russia’s Council meeting.

            The rest of the funds will be put to Ukraine’s post-war reconstruction.

            bloomberg.com/news/articles/20

              [?]Paco Hope [He/Him] » 🌐
              @paco@infosec.exchange

              This silly statement from about drives me crazy. People talk about this all the time as if it means something.

              ‘files in ChatGPT as a whole are "encrypted by default at rest and in transit"’

              What attack does that encryption at rest defeat? What hacker says “darn it! I would have gotten the data if it hadn’t been for that pesky encryption at rest?”

              Think it over. Go ahead. I’ll wait.

              Physical theft of hard drives/storage. That’s it. Encryption at rest at OpenAI, or any cloud, defeats the same singular attack that it defeats when you encrypt the hard drive on your laptop: if someone physically steals the device, they don’t get the data.

              They can sell your data. They can store it (encrypted at rest) on a web site that has a vulnerability or incorrect security, and bad people can download the unencrypted data. They can share it with “partners” who misuse it. Encrypting at rest is NOT an important protection. Literally every other protection is more important.

              darkreading.com/remote-workfor

                [?]Wen » 🌐
                @Wen@mastodon.scot

                I would hope I don’t need to let most people know, but…

                Lastpass phishing - and this might be expensive for the unwary

                Remember, following liks in emails can be dangerous - following links to shortened URLS is silly

                theregister.com/2026/01/21/las

                  [?]Jan Wildeboer 😷:krulorange: » 🌐
                  @jwildeboer@social.wildeboer.net

                  Heads up for my fellow Red Hat Enterprise Linux (RHEL) 10 users:

                  Important: kernel security update

                  kernel: libceph: fix potential use-after-free in have_mon_and_osd_map() (CVE-2025-68285)

                  So do your `dnf update` ASAP :)

                  More details: access.redhat.com/errata/RHSA-

                  @homelab

                    Wen boosted

                    [?]JuneSim63 💚 » 🌐
                    @junesim63@mstdn.social

                    "The first duty of a government is to keep its people safe. And in today’s unpredictable world, that won’t be achieved by clinging to outdated ideas about security, or cowering at Trump’s feet in the hopes that he will protect us"

                    Green Party leader Zack Polanski writes in the New Statesman

                    Trump's threat to Greenland must be a wake up call for Britain - New Statesman
                    newstatesman.com/politics/uk-p

                      [?]Doug [he / him] » 🌐
                      @doug@union.place

                      I'm begging you, before you find your API key hard-coded in a clients browser, or have malware injected into your super cool vibe coded website - check the security!

                      Your fun project could ruin somebody's online safety.

                        Wen boosted

                        [?]Mark » 🌐
                        @paka@mastodon.scot

                        Does or actually threaten

                        Experts say Trump’s warnings don’t match reality

                        Trump’s Greenland obsession is not new. He 1st suggested it in 2019

                        Security experts & officials say Greenland faces no immediate military threat — raising a pointed question:

                        - Are Trump’s warnings about Greenland genuine concerns, or a pretext for a more unilateral push in the ?

                        kyivindependent.com/does-russi

                          [?]GrapheneOS » 🌐
                          @GrapheneOS@grapheneos.social

                          Vanadium version 144.0.7559.76.1 released:

                          github.com/GrapheneOS/Vanadium

                          See the linked release notes for a summary of the improvements over the previous release and a link to the full changelog.

                          Forum discussion thread:

                          discuss.grapheneos.org/d/30839

                            hexa- boosted

                            [?]Kuketz-Blog 🛡 » 🌐
                            @kuketzblog@social.tchncs.de

                            IT-»Sicherheit« wird hierzulande oft mit Compliance verwechselt: Richtlinien, Vorlagen, Prozesse – alles sauber dokumentiert und abheftbar. Hauptsache: Niemand ist schuld, wenn es knallt.

                            Reale Sicherheit entsteht nicht durch Papier, sondern durch gute IT-Leute, Zeit, Budgets, klare Zuständigkeiten – und Technik, die wirklich gehärtet, gepflegt und überprüft wird.

                            Checkboxen senken keine Risiken. Sie senken nur das Haftungsgefühl.

                              Wen boosted

                              [?]Mark » 🌐
                              @paka@mastodon.scot

                              Scrap cards

                              Government plan for digital ID cards is £1.8 billion white elephant

                              It is little more than an echo of the failed Tony Blair ID card scheme, now with an expensive digital element bolted on

                              We rejected ID cards then and we reject them now.

                              Despite the government’s partial U-turn on some compulsory elements of the scheme, the huge cost remains – alongside many other problems.

                              r.ippl.es/digital-id/

                                Terence Eden boosted

                                [?]Terence Eden [He/Him/♂/男] » 🌐
                                @Edent@mastodon.social

                                🆕 blog! “Responsible Disclosure: Chimoney Android App and KYCaid”

                                Chimoney is a new "multi-currency wallet" provider. Based out of Canada, it allows users to send money to and from a variety of currencies. It also supports the new Interledger protocol for WebMonetization.

                                But it has a security flaw which cannot be ignored.

                                👀 Read more: shkspr.mobi/blog/2026/01/respo

                                  [?]Peter N. M. Hansteen » 🌐
                                  @pitrh@mastodon.social

                                  [?]Rory McCune » 🌐
                                  @raesene@infosec.exchange

                                  For anyone who's been to one of my talks over the last couple of years, you may have seen me mention "the unpatchable 4", which is a set of Kubernetes CVEs for which there are no patches, you need to mitigate them with configuration or architecture choices.

                                  I've been meaning to write more about them, and finally got a chance so here's the first in a mini-series of posts looking at the CVEs and the underlying reasons they occur. This time it's CVE-2020-8554.

                                  securitylabs.datadoghq.com/art

                                    Aral Balkan boosted

                                    [?]diana 🏳️‍⚧️🦋🌱 » 🌐
                                    @dianea@lgbtqia.space

                                    The PAM Duress is a module designed to allow users to generate 'duress' passwords that when used in place of their normal password will execute arbitrary scripts.

                                    This functionality could be used to allow someone pressed to give a password under coercion to provide a password that grants access but in the background runs scripts to clean up sensitive data, close connections to other networks to limit lateral movement, and/or to send off a notification or alert (potentially one with detailed information like location, visible wifi hot-spots, a picture from the camera, a link to a stream from the microphone, etc). You could even spawn a process to remove the pam_duress module so the threat actor won't be able to see if the duress module was available.

                                    github.com/nuvious/pam-duress

                                      Hugh boosted

                                      [?]🔻 aetios 🇪🇺 » 🌐
                                      @aetios@sns.minovsky.space

                                      #getfedihired in #nederland ? We zijn bij mijn werkgever Vest Informatiebeveiliging op zoek naar meerdere medior of senior security consultants. Het werk behelst onder andere pentesting van websites, netwerken of assessments van computersystemen, maar we hebben ook een aantal structurele opdrachtgevers die regelmatig technisch meer interessante onderwerpen onze kant op sturen (onder andere in de energie- en luchtvaartsector)

                                      Certificeringen zijn natuurlijk leuk maar niet vereist (ik heb zelf geen spannende certificeringen) - we zoeken vooral iemand met werkervaring om ons team te versterken.
                                      We communiceren en schrijven veel van onze rapporten in het Nederlands, en verwachten dat je dat zelf ook kunt.
                                      Ervaring met pentesten, speciale Linux- Windows- (AD!?) of Mac (wuh???) ervaring of andere specialismen (Mobiel? RF? X.25??) zijn super welkom en we doen altijd ons best om bij de kennis van onze medewerkers leuke opdrachten te vinden.

                                      We hebben een gezellig (neuro?)divers team van zo'n 25 man en een relaxte werksfeer. Ik werk al bijna 8 jaar bij deze werkgever en meerdere collega's werken al 10 of 15 jaar bij ons.

                                      Thuiswerken is bij ons mogelijk en heel flexibel maar we vinden het wel gezellig als je af en toe in Naarden kantoor kan komen. Ik ben zelf bv jarenlang met een NS-Businesskaart het land door gereisd.

                                      Als je interesse hebt kijk dan even op de site (vest.nl) of stuur me hier een berichtje.

                                      #itsecurity #pentesting #security #itsec #vacature #hacken

                                        [?]Aral Balkan » 🌐
                                        @aral@mastodon.ar.al

                                        🥳 Auto-Encrypt Localhost version 9.0.0 released

                                        Bye bye, Windows.

                                        • Windows is no longer supported as Microsoft is complicit in Israel’s genocide of the Palestinian people¹ and Small Technology Foundation² stands in solidarity with the Boycott, Divestment, and Sanctions (BDS) movement³. Windows is an ad-infested and surveillance-ridden dumpster fire of an operating system and, alongside supporting genocide, you are putting both yourself and others at risk by using it.

                                        Enjoy!

                                        💕

                                        About Auto-Encrypt Localhost:

                                        codeberg.org/small-tech/auto-e

                                        Auto Encrypt Localhost is similar to the Go utility [mkcert](github.com/FiloSottile/mkcert/) but with the following important differences:

                                        1. It’s written in pure JavaScript for Node.js.

                                        2. It does not require certutil to be installed.

                                        3. It uses a different technique to install its certificate authority in the system trust store of macOS.

                                        4. It uses enterprise policies on all platforms to get Firefox to include its certificate authority from the system trust store.

                                        5. In addition to its Command-Line Interface, it can be used programmatically to automatically handle local development certificate provisioning while creating your server.

                                        Auto-Encrypt Localhost is licensed under AGPL version 3.0.

                                        ¹ bdsmovement.net/microsoft
                                        ² small-tech.org/
                                        ³ bdsmovement.net/

                                          [?]BastilleBSD :freebsd: » 🌐
                                          @BastilleBSD@fosstodon.org

                                          2026 didn't waste any time in telling 2025 to "hold my beer".

                                          Share your favorite internet privacy and secure communications tools to help us make it to the other side of this.

                                          #

                                            [?]Peter N. M. Hansteen » 🌐
                                            @pitrh@mastodon.social

                                            The recording from NYC*BUG Saturday January 10th, 2026 session "The Book of PF 4th ed + EU CRA: It's time to Engineer up" is now available:

                                            Youtube: youtu.be/HOCsvcCm1Ec
                                            Peertube: toobnix.org/w/bQPtKXKqJMdeYDbz

                                              [?]Tim Mak » 🌐
                                              @timkmak@journa.host

                                              U.S. URGES CITIZENS TO LEAVE : The State Department has urged all to leave immediately due to extreme risks. theguardian.com/us-news/2026/j

                                                [?]GrapheneOS » 🌐
                                                @GrapheneOS@grapheneos.social

                                                GrapheneOS version 2026011000 released:

                                                grapheneos.org/releases#202601

                                                See the linked release notes for a summary of the improvements over the previous release.

                                                Forum discussion thread:

                                                discuss.grapheneos.org/d/30465

                                                  [?]GrapheneOS » 🌐
                                                  @GrapheneOS@grapheneos.social

                                                  GrapheneOS version 2026010800 released:

                                                  grapheneos.org/releases#202601

                                                  See the linked release notes for a summary of the improvements over the previous release.

                                                  Forum discussion thread:

                                                  discuss.grapheneos.org/d/30419

                                                    [?]Marcos Dione » 🌐
                                                    @mdione@en.osm.town

                                                    TIL you can mount on top of symlinks; meaning, you can use a symlink as a mount point. This sounds like a really bad idea, specially after watching Alksa Sarai's talk at the Linux Plumber's Conf:

                                                    youtube.com/watch?v=z8v7ovIeDRM

                                                      [?]Peter N. M. Hansteen » 🌐
                                                      @pitrh@mastodon.social

                                                      [?]Mark Stosberg » 🌐
                                                      @markstos@urbanists.social

                                                      As a test, I tried "tailscale funnel" to test sharing a Valhalla service running on port 8002 on my laptop over the internet. The Tailscale park was fast and easy, amazing even.

                                                      But as I sat and stared and marveled at my idle service logs, in less than a minute they went crazy with attack traffic looking for all sorts of common vulns.

                                                      Less than a minute! Port 8002!

                                                      Just best assume anything that's public on any port is immediately and constantly scanned for vulns.

                                                        WTL boosted

                                                        [?]Roni Rolle Laukkarinen » 🌐
                                                        @rolle@mementomori.social

                                                        As our company hosts servers, we have a public Security Policy and a security.txt file for ethical hackers to disclose vulnerabilities responsibly: handbook.dude.fi/security-poli

                                                        Because of this, I receive quite a few reports, most of them ineligible. I've also run into some "security experts" getting upset about not receiving a bounty for a non-issue or putting heavy pressure on payments for valid ones. It often feels unfair, like I'm being held hostage.

                                                        That's why replies like the one I just received warm my heart so much:

                                                        "Thank you very much for the clarification and for taking quick action to remove the DNS record. I appreciate the transparency and the kind offer as well.

                                                        I'd prefer to donate the amount to a child support charity instead. You’re very welcome to donate it on my behalf to any such organization of your choice."

                                                        Donation made. Thank you, stranger. Kindness costs nothing.

                                                          [?]Peter N. M. Hansteen » 🌐
                                                          @pitrh@mastodon.social

                                                          [?]Peter N. M. Hansteen » 🌐
                                                          @pitrh@mastodon.social

                                                          There will be a "Network Management with the OpenBSD Packet Filter Toolset" at AsiaBSDCon in Taipei Thursday, March 19 2026.

                                                          Yours truly and Max Stucchi teaching networking goodness.

                                                          Details soon to emerge at 2026.asiabsdcon.org/ @stucchimax

                                                            [?]heise online » 🌐
                                                            @heiseonline@social.heise.de

                                                            Cybersicherheit: BSI-Portal geht online – und nutzt dafür AWS

                                                            Das neue BSI-Portal soll zentraler Anlaufpunkt für IT-Sicherheit bei kritischen Infrastrukturen werden. Für Stirnrunzeln sorgt die Wahl des Anbieters: AWS.

                                                            heise.de/news/Cybersicherheit-

                                                              [?]Nonilex » 🌐
                                                              @Nonilex@masto.ai

                                                              The mission to the has requested an emergency Council [] meeting & has asked the Council to condemn the military strikes against the country.

                                                              Venezuela’s ambassador, Samuel Reinaldo Moncada Acosta, said in a letter to the UNSC president: “The United States of America always uses lies to fabricate wars. It is an international imposed with the of death: the recent past confirms this.”

                                                                [?]Jiří Eischmann » 🌐
                                                                @sesivany@social.vivaldi.net

                                                                When you think that things like turning off as a precaution are overkill, security researchers drop a bomb like this. (long, but interesting read)

                                                                insinuator.net/2025/12/bluetoo

                                                                  [?]Nonilex » 🌐
                                                                  @Nonilex@masto.ai

                                                                  strongly condemned the strike in & the action against its president, the Foreign Ministry said, adding the Beijing govt was “deeply shocked” & firmly opposed to the operation.

                                                                  “Such hegemonic acts of the US seriously violate & Venezuela’s & threaten & in & the region,” it said.

                                                                    [?]Nonilex » 🌐
                                                                    @Nonilex@masto.ai

                                                                    called on the to comply with & the principles of the Charter, urging it to stop violating the & of other nations.

                                                                      Back to top - More...