cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #cybersecurity

[?]Dumb Password Rules » 🤖 🌐
@dumbpasswordrules@infosec.exchange

This dumb password rule is from LibraryThing.

"Your password cannot be longer than 20 characters"

dumbpasswordrules.com/sites/li

    [?]Mark » 🌐
    @paka@mastodon.scot

    Switzerland Ends Contract Over Risks -

    ’s decision to discontinue the use of Palantir is not a story.

    - It's a management story. The platform was not rejected because it failed to perform. On the contrary, it delivered advanced data fusion and operational insight.

    It was rejected because the residual sovereignty risk was considered unacceptable.

    [1/2]

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from Return of Reckoning.

      Password must be between 6 and 100 characters.

      It doesn't say on the website, but the password only works in the related game client if it is purely alphanumeric. Not even special characters like % or $ are allowed.

      dumbpasswordrules.com/sites/re

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from myezyaccess.com patient portal system.

        12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

        dumbpasswordrules.com/sites/my

          Terence Eden boosted

          [?]Terence Eden [He/Him/♂/男] » 🌐
          @Edent@mastodon.social

          🆕 blog! “FobCam '25 - All my MFA tokens on one page”

          Some ideas are timeless. Back in 2004, an anonymous genius set up "FobCam". Tired of having to carry around an RSA SecurID token everywhere, our hero simply left the fob at home with an early webcam pointing at it. And then left the page open for all to see.

          Security expert Bruce…

          👀 Read more: shkspr.mobi/blog/2025/04/fobca

          (Probably)

            [?]Dumb Password Rules » 🤖 🌐
            @dumbpasswordrules@infosec.exchange

            This dumb password rule is from Coventry Building Society.

            Password has to be between 6 and 10 characters, can't contain any punctuation and you have to give characters from it on the phone to confirm identity.

            dumbpasswordrules.com/sites/co

              [?]The New Oil » 🤖 🌐
              @thenewoil@mastodon.thenewoil.org

              [?]Dumb Password Rules » 🤖 🌐
              @dumbpasswordrules@infosec.exchange

              This dumb password rule is from Nelnet (student loan servicer).

              8 to 15 characters and no spaces? Why no spaces? Also limited to only these 6 special characters. That could mean that there is some process somewhere that puts this as part of a command line invocation.

              dumbpasswordrules.com/sites/ne

                Gary :party_porg: boosted

                [?]Alex@rtnVFRmedia Suffolk UK » 🌐
                @vfrmedia@social.tchncs.de

                dark humour [SENSITIVE CONTENT]

                Both for and the British pop TV show *are* similar, they both try as much as possible to hide the nonce 😁

                  [?]justsoup :asexual_flag: [he/they] » 🌐
                  @justsoup@mstdn.social

                  I don't know if I have to say this, but please do not use postmarketOS on a personal device if you are doing anything security critical or requiring high levels of data protection. Android or iOS are much better options for this. I would generally recommend a Google Pixel with GrapheneOS if you really need peace-of-mind. Heck, a random stock Android ROM from a carrier phone is probably more secure with some adb work.

                    Tom :damnified: boosted

                    [?]heise online » 🌐
                    @heiseonline@social.heise.de

                    Anthropic-KI Mythos: Dringende Warnung an US-Banken, BSI erwartet Umwälzungen

                    Anthropics neue KI Mythos sorgt für Aufregung. In den USA wurden die Chefs der systemrelevanten Banken einbestellt, hier erwartet das BSI weitreichende Folgen.

                    heise.de/news/Anthropic-KI-Myt

                    [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                    @freya@social.highenergymagic.net

                    hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                    Please boost for reach, any job offers please DM me.

                      [?]Dumb Password Rules » 🤖 🌐
                      @dumbpasswordrules@infosec.exchange

                      This dumb password rule is from Unicaja.

                      Username is your national Spanish ID (easy to find).
                      Your password must be 6 characters long. You can't type, only select characters from the virtual keyboard

                      dumbpasswordrules.com/sites/un

                        [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                        @freya@social.highenergymagic.net

                        hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                        Please boost for reach, any job offers please DM me.

                          [?]Andrew 🌻 Brandt 🐇 » 🌐
                          @threatresearch@infosec.exchange

                          I have an all-hands-on-deck call to action today.

                          At what point do we stop owning the things we buy, and just rent everything?

                          That's the problem that the movement is trying to address.

                          In Colorado, where we finally (just 3 months ago!) saw the nascent first awakening of a new right to repair law come in to effect, that infant could end up smothered in its crib this week, as the Colorado senate considers a bill that would roll back the right to repair for any device considered "critical infrastructure" - and yes, it is that vague in its wording.

                          404media.co/data-center-tech-l

                          If you care about whether we get to control and use (to whatever purpose we see fit) the things we buy -- including commercial servers, firewalls, routers, or other electronic gear -- then please consider signing on to this petition urging the Colorado legislature to reject the fearmongering and bad-faith arguments of the tech industry, who are making a desperate attempt to protect the long term revenue stream of support contracts.

                          Don't get angry; Get active. We can win this one with reasoned arguments. Please ask the Colorado legislature to not give in to FUD, and embrace Coloradans' resiliency and willingness to fight the good fight.

                          Sign the petition here:

                          pirg.org/colorado/take-action/

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from Itaú Bank.

                            I know, it's in spanish, let me translate this monstrosity for you.

                            - Allowed characters: letters A to Z uppercase or lowercase (ñ is not allowed), number 0 to 9, #, $, %, &, +, -, . :, ;, _.
                            - You must use 8 characters.
                            - The password must contain at least one letter and at least one number.
                            - ...

                            dumbpasswordrules.com/sites/it

                              Gary :party_porg: boosted

                              [?]Neil Brown [he/him/his] » 🌐
                              @neil@mastodon.neilzone.co.uk

                              If you are interested in a Free, interactive, application firewall for Linux, do take a look at opensnitch:

                              github.com/evilsocket/opensnit

                              It pops up a dialogue window when it detects a connection, allowing you to control what to do with it (allow/drop traffic, do so permanently/temporarily etc.).

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Bank Millennium.

                                Passwords limited to 8 digits.

                                dumbpasswordrules.com/sites/ba

                                  [?]Tara 🕷️:blobbat: [she/her, they/them] » 🌐
                                  @tarajdactyl@anarres.family

                                  :boosts_ok_gay:

                                  attention anybody with substantial experience with Rust and networking: my team is hiring!!

                                  one of few rust jobs I'm aware of that is not web 3.0 horseplop.

                                  fully remote (US timezones), good culture, good trans-inclusive healthcare, good work/life balance, and a nice defensive cybersecurity mission i can get behind.

                                  feel free to reach out for more details and the job posting.

                                  :boosts_ok_gay:

                                    [?]Ra (Freyja) (it/its)𒀭𒈹𒍠𒊩 [it/its; q=1.0, she/her; q=0.9; they/them; q=0.1, */*; q=0.0] » 🌐
                                    @freya@social.highenergymagic.net

                                    hey so this is probably completely pointless but: looking for a job (NZ or fully remote willing to hire a kiwi) in SRE, security, or linux/Unix system administration. 15 years expereince administering Linux and Unix boxes, intermediate level of experience working with docker compose and containerisation and container security. No prior job experience unfortunately, all those 15 years were mostly personal projects and small-scale stuff for friends. Currently running an entire multi-machine personal cloud infrastructure with a demonstration of all the services I have running at status.highenergymagic.net. Entirely willing to accept entry-level job placements, no expectation of being paid a lot or anything, just want to be doing something and move the needle a little on my current "being broke" status.

                                    Please boost for reach, any job offers please DM me.

                                      [?]Aaron Toponce ⚛️:debian: » 🌐
                                      @atoponce@fosstodon.org

                                      The and maintainer accounts have been locked out by Microsoft. They are now unable to deliver Windows updates.

                                      cybernews.com/security/microso

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Inria.

                                        This is the account for those who work at [Inria](inria.fr/)
                                        "the French national research institute for
                                        the digital sciences".

                                        You have to wonder what's wrong with these special characters but not
                                        the other ones.
                                        - Password expiration once a year
                                        - Your password must contain at leas...

                                        dumbpasswordrules.com/sites/in

                                          [?]Neil Brown [he/him/his] » 🌐
                                          @neil@mastodon.neilzone.co.uk

                                          New, dull, blogpost:

                                          "Thoughts on increasing ssh security using a hardware security key"

                                          No luck with a FOSS solution for Android yet :(

                                          neilzone.co.uk/2026/04/thought

                                            [?]BeyondMachines :verified: » 🤖 🌐
                                            @beyondmachines1@infosec.exchange

                                            Critical File Upload Vulnerability Reported in Ninja Forms Plugin for WordPress

                                            A critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms – File Upload plugin (CVE-2026-0740) allows attackers to achieve remote code execution.

                                            **If you are using the Ninja Forms File Upload plugin, this is urgent! Immediately update to version 3.3.27. You can't hide WordPress from the internet, it's made to be visible online. Since this flaw is being actively scanned for, any delay in patching leaves your site exposed to automated attacks. After the update, review server logs for suspicious requests targeting the handle_upload action.**

                                            beyondmachines.net/event_detai

                                              [?]Dumb Password Rules » 🤖 🌐
                                              @dumbpasswordrules@infosec.exchange

                                              This dumb password rule is from Deutsche Kreditbank AG (DKB).

                                              Passwords for the online banking web frontend do not have a max length constraint, but using the same password to
                                              log in to the official iOS DKB app requires the password to be no longer than 38 characters.

                                              dumbpasswordrules.com/sites/de

                                                [?]IFIN » 🌐
                                                @ifin@infosec.exchange

                                                Hello, world!

                                                We are IFIN, the Independent Federated Intelligence Network, and we want to change how threat intelligence is done.

                                                We believe we're all safer when we share what we know. Come learn more and join us!

                                                ifin-intel.org/blog/hello/

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from Air France.

                                                  - Between 8 to 12 characters
                                                  - Should contain capital, lowercase letters and numbers

                                                  dumbpasswordrules.com/sites/ai

                                                    [?]WTL » 🌐
                                                    @WTL@mastodon.social

                                                    Can anyone recommend a good "introduction to 2fa" article/video for dummies that I can forward to some non-technical folks? Also not slop-generated.

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from MySwissLife.

                                                      User ID *has to* be 8 characters exactly, password *has to be* 8 characters and numbers only.

                                                      dumbpasswordrules.com/sites/my

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Bank of America.

                                                        20 character max and lots of special character restrictions.
                                                        Bank of America - keeping your money safe.

                                                        Also: If you paste a password greater than 20 characters,
                                                        the form truncates it without telling you or giving an
                                                        error.

                                                        dumbpasswordrules.com/sites/ba

                                                          Aral Balkan boosted

                                                          [?]Demokritus Jorik :v_gay: » 🌐
                                                          @serigala_tropis@lgbtqia.space

                                                          RE: mastodon.thenewoil.org/@thenew

                                                          The accusation is much scarier as it taps into corporate espionage and mass surveillance.

                                                          Microsoft is accused of illegally searching browser extension whenever a user sign in into LinkedIn. It scans for any signs of use of religious belief, political orientation, as well as disabilities of individuals. There is also the accusation of the data being handed over to Israeli spyware firm.

                                                          "This is illegal and potentially a criminal offense in every jurisdiction we have examined."

                                                          browsergate.eu/

                                                            [?]Dumb Password Rules » 🤖 🌐
                                                            @dumbpasswordrules@infosec.exchange

                                                            This dumb password rule is from Trenord.

                                                            - Password must consist of 8-16 characters
                                                            - Must contain 3 out of 4 of the following: lowercase characters, uppercase character, digits (0-9), and one or more of the following symbols: @#$%^&*-_+=[]{}|\:',?/`~“();.

                                                            dumbpasswordrules.com/sites/tr

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from Safeway.

                                                              Passwords limited to 8-12 characters.

                                                              dumbpasswordrules.com/sites/sa

                                                                [?]AI6YR Ben » 🌐
                                                                @ai6yr@m.ai6yr.org

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from Green Flag.

                                                                - 8 to 10 characters
                                                                - No special characters

                                                                dumbpasswordrules.com/sites/gr

                                                                  [?]Graham Perrin » 🌐
                                                                  @grahamperrin@mastodon.bsd.cafe

                                                                  @nielsa no, that's not what I'm telling you.

                                                                  I prefer to believe that most people will be thoughtful.

                                                                  "… a huge number of bugs. I have so many bugs in the Linux kernel that I can't report because I haven't validated them yet. I'm not going to make some open source developer validate bugs that I haven't checked yet. I'm not going to send them potential slop … I now have … several hundred crashes that they haven't seen because I haven't had time to check them. We need to find a way to fix this …"

                                                                  – Nicholas Carlini

                                                                  Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

                                                                  Alt...Screenshot: a frame from https://www.youtube.com/watch?v=1sd26pWhfmg

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from State Bank of India (Foreign Travel Card).

                                                                    State Bank of India is the largest government operated bank in India.
                                                                    They offer "travel" prepaid cards for foreign currencies, this is for
                                                                    their portal for the prepaid card users to manage their account.

                                                                    Your password must:
                                                                    - Be between 8 and 9 characters long
                                                                    - Contain at least 1 lowercase c...

                                                                    dumbpasswordrules.com/sites/st

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Paytm.

                                                                      Password must be between 5 and 15 characters. Also, spaces don't count
                                                                      as characters.

                                                                      dumbpasswordrules.com/sites/pa

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from LINE.

                                                                        Password must:
                                                                        - be between 8 to 20 characters
                                                                        - not contain characters that repeat in a row
                                                                        Password must contain three of the following:
                                                                        - an upper-case letter
                                                                        - a lower-case letter
                                                                        - a number
                                                                        - a symbol

                                                                        dumbpasswordrules.com/sites/li

                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from Telekom.

                                                                          At first glance, their policy looks good - sure, the upper limit was chosen without necessity
                                                                          and they enforce characters from all four groups, but your password manager will most likely come up with something suitable.

                                                                          The website even tells you how 'wunderbar' your new password is - only to t...

                                                                          dumbpasswordrules.com/sites/te

                                                                            [?]Dumb Password Rules » 🤖 🌐
                                                                            @dumbpasswordrules@infosec.exchange

                                                                            This dumb password rule is from Alipay.

                                                                            - 8-20 characters (numbers or letters)
                                                                            - no special characters allowed
                                                                            - in the mobile app

                                                                            dumbpasswordrules.com/sites/al

                                                                              [?]occult » 🌐
                                                                              @occult@vox.ominous.net

                                                                              Watching the livestream of the Artemis II launch, I just witnessed one of the astronauts type in the password on their tablet while sitting in the capsule on camera.

                                                                              Alt...Astronauts sitting in the Artemis II capsule using a tablet computer.

                                                                                [?]Paco Hope [He/Him] » 🌐
                                                                                @paco@infosec.exchange

                                                                                We can quit and just go farm potatoes or something. After 25 years of one of the most talked-about tech companies invents a daemon process that

                                                                                makes use of a file-based “memory system” designed to allow for persistent operation across user sessions.

                                                                                Sure. Just store your system instructions in a random text file.

                                                                                Why are we installing endpoint protection on this system?

                                                                                Why do we verify cryptographic signatures on software updates to this system?

                                                                                Why are we building a zero trust security environment?

                                                                                Why do we do scan email to avoid social engineering emails?

                                                                                Our AI-assisted users are gonna YOLO right past all that. And if they can’t get past our controls, this agentic Frankenstein will write itself some markdown and work quietly in the background figuring out how to bypass something the user couldn’t bypass on their own.

                                                                                This is in 2026

                                                                                  Back to top - More...