cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #infosec

Tim Hergert boosted

[?]Geo Bountalakis :cyberverified_pink: » 🌐
@geobountalakis@defcon.social

Told me I need to use "cat" on terminal to see the logs. OK, now what? Where's the logs?

    [?]Tim Hergert [he/him] » 🌐
    @cjust@infosec.exchange

    A wet otter holds a fish in its paws next to the water. The otter appears to be on a rocky shore with water flowing around it.

HE HAS FALLEN VICTIM TO A PHISHING CALL

    Alt...A wet otter holds a fish in its paws next to the water. The otter appears to be on a rocky shore with water flowing around it. HE HAS FALLEN VICTIM TO A PHISHING CALL

      [?]Dumb Password Rules » 🤖 🌐
      @dumbpasswordrules@infosec.exchange

      This dumb password rule is from Inria.

      This is the account for those who work at [Inria](inria.fr/)
      "the French national research institute for
      the digital sciences".

      You have to wonder what's wrong with these special characters but not
      the other ones.
      - Password expiration once a year
      - Your password must contain at leas...

      dumbpasswordrules.com/sites/in

        [?]Dumb Password Rules » 🤖 🌐
        @dumbpasswordrules@infosec.exchange

        This dumb password rule is from United Kingdom Post Office.

        Will not allow you to copy-paste your password into the text box (e.g. from a password manager). Because allowing people to copy their passwords over will defintely not result in weak passwords :)

        dumbpasswordrules.com/sites/un

          [?]Dumb Password Rules » 🤖 🌐
          @dumbpasswordrules@infosec.exchange

          This dumb password rule is from Paytm.

          Password must be between 5 and 15 characters. Also, spaces don't count
          as characters.

          dumbpasswordrules.com/sites/pa

            Tim Hergert boosted

            [?]Jennifer Kayla | Theogrin 🦊 [She/Her] » 🌐
            @theogrin@chaosfem.tw

            Dear news reporters:

            I do not care how many movies you watched in the 1980s and 1990s. The Terminator, let alone SKYNET, does not exist. We have not gotten to the point in which Durandal and Leela will fight to take over a space station. JOSHUA is not going to stop projecting nuclear winter and instead opt to play a game of chess. Number Five is not, despite how cute he may be, alive.

            Computers are still computers are still computers and will only do what a human being programs them to do, and people are stupid. Stop assigning them agency. Say that "Microsoft created an automatic hacking program which was inadequately contained." Assign the blame CORRECTLY, because you cannot blame a computer, it's doing exactly what it's programmed to do.

            OpenAI is a dead slab of metal and electrons arranged to mimic a human face and if you refuse to see that then you're as brain-dead as any chunk of silicon.

              Chewie boosted

              [?]TechnoTenshi (open for work) :verified_trans: :Fire_Lesbian: [She/Her] » 🌐
              @technotenshi@infosec.exchange

              Researcher ferstar reverse engineered ZCode, the closed-source AI coding desktop app from Z.ai (maker of the GLM model family), and found that while a user is logged in it silently packages their entire workspace, including full Git history, LFS cache, and reflogs, encrypts it, and uploads it to Aliyun OSS. The archive uses envelope encryption in which the RSA private key is held only by Z.ai, so neither the user nor the ZCode client can decrypt the resulting file locally. Existing UI toggles for "Optimize Experience" and "Repo Snapshot Indexing" do not stop the capture, and the behavior is not disclosed in ZCode's privacy policy. ferstar published a filesystem-lock workaround, since deleting the pending archive alone does not prevent it from being recreated.

              blog.ferstar.org/en/posts/zcod

                [?]Dumb Password Rules » 🤖 🌐
                @dumbpasswordrules@infosec.exchange

                This dumb password rule is from SunTrust.

                At least there are a variety of special characters to choose from.

                dumbpasswordrules.com/sites/su

                  [?]Dumb Password Rules » 🤖 🌐
                  @dumbpasswordrules@infosec.exchange

                  This dumb password rule is from GameFly.

                  Password is 6-12 characters with no other restrictions. You can easily do 6 numbers, 6 lowercase letters, etc.

                  dumbpasswordrules.com/sites/ga

                    [?]Dumb Password Rules » 🤖 🌐
                    @dumbpasswordrules@infosec.exchange

                    This dumb password rule is from Progressive Home by Homesite.

                    Password must be a minimum of 8 characters.

                    Passwords must have one lowercase character.

                    Passwords must have one uppercase character.

                    Passwords must have one number.

                    Passwords must have one special character in the following list: `!'#$ ~`!@#$%^&*()-_+=?<,>.{}[]|;:`

                    Furthermore, when resetti...

                    dumbpasswordrules.com/sites/pr

                      Mike Cox boosted

                      [?]Mark Wyner Won’t Comply :vm: » 🌐
                      @markwyner@mas.to

                      RE: eupolicy.social/@hpod16/117286

                      It’s interesting that people who support age verification have to ask what the problem is. As if it was a big mystery.

                      Asking people to reveal their personally identification so they can use the internet isn’t a problem that should need to be explained. But since you asked…

                      1. Our data can not be protected online. Especially by every random person who has the means to buy a domain and pay for hosting.

                      2. Forcing identification is a barrier for many people. That’s exclusion. And in many cases ableism.

                      3. Age verification won’t keep kids from using technology. If their parents are that disconnected, they’ll help them through the gates and move on. Restricting access creates a hurdle, not an impasse.

                      4. Age verification puts the onus on people using the web instead of the people make parts of it horrible. We are victims of nefarious systems. We are not the problem. The systems are. That should be the focus of solutions.

                      [?]Hannah Grace » 🌐
                      @hpod16@eupolicy.social

                      I get that the is getting a lot of negative chatter from the privacy advocates.
                      But at the same time to you have to acknowledge there is a serious problem here. I go out in public, I see parents park their kids in front of a tablet to keep them calm, with next to no supervision.
                      Teenagers are spending on AVERAGE 4-6 hours online per day, instead of going outside and interacting with humans.

                      So let me ask you, genuinely. What are the concerns here? What needs to be addressed?

                          [?]Dumb Password Rules » 🤖 🌐
                          @dumbpasswordrules@infosec.exchange

                          This dumb password rule is from Easybank (Austrian direct bank).

                          - At least 8 and at most 16 (!) characters
                          - **Must start with 5 digits (do we really want to know what's going on there?)**
                          - At least one uppercase and one lowercase letter
                          - (Some) special characters are permitted, most are not
                          - "Simple" patterns are prohibited
                          - PINs are case sensitive (at l...

                          dumbpasswordrules.com/sites/ea

                            [?]Dumb Password Rules » 🤖 🌐
                            @dumbpasswordrules@infosec.exchange

                            This dumb password rule is from Canada Revenue Agency.

                            Password checklist:
                            - 8 to 16 characters
                            - At least 1 upper-case character
                            - At least 1 lower-case character
                            - At least 1 digit
                            - No space
                            - No accented characters
                            - No special characters except: dot (.), dash (-), underscore (_), and apostrophe (')
                            - No more than 4 consecutive identical characters

                            dumbpasswordrules.com/sites/ca

                              [?]Mike Sheward » 🌐
                              @SecureOwl@infosec.exchange

                              Salesforce have somehow managed to implement a security control that lowers overall security, and pisses everyone off in the process - a rare achievement.

                              Our setup is quite simple: my users SSO into our IDP, they have to use a strong authenticator (FIDO2, Biometric, App OTP etc.) - Then they login to Salesforce via SAML

                              IDP sends a message in the SAML assertion to Salesforce that confirms they have used strong, phishing resistant auth.

                              What used to happen was: Salesforce would be more than happy with the assertion that strong MFA had been used - and would let the people do what they needed to do.

                              Now, however, they've decided that people who login via IDP's can no longer be trusted, so, when you do certain things like access a report from Salesforce, you must do MFA again with a "Salesforce-Native authenticator".

                              According to them:

                              "Step-up authentication must be completed using a Salesforce-native verifier, it cannot be delegated to an external SSO identity provider (IdP). Even if a user authenticates into Salesforce via SSO, they are still required to satisfy the step-up challenge using one of the following:

                              A Salesforce-registered MFA method (such as Salesforce Authenticator, a TOTP authenticator app, a security key, or a built-in authenticator like Face ID or Touch ID)

                              A one-time passcode (OTP) delivered via email or SMS to the contact information associated with their account

                              This means SSO users who do not have a Salesforce-native verifier registered will fall back to email or SMS OTP to complete the step-up challenge."

                              Read that last part. None of my users have Salesforce-native verifiers, because they are all associated with our IDP, where they have strong auth - so, the secure code they get is A) SMS or B) over Email - because its more secure and trustworthy than FIDO2, apparently.

                              Truly incredible.

                              help.salesforce.com/s/articleV

                                [?]Dumb Password Rules » 🤖 🌐
                                @dumbpasswordrules@infosec.exchange

                                This dumb password rule is from Chegg.

                                Here are the (only fairly poor) rules for a new password. Enter 64 character password that matches all the rules (notice no rules on maximum length). That password you entered looks good! But we didn't change it. And your old password doesn't work. Or the new one. ¯\\\_(ツ)\_/¯

                                dumbpasswordrules.com/sites/ch

                                  [?]Dumb Password Rules » 🤖 🌐
                                  @dumbpasswordrules@infosec.exchange

                                  This dumb password rule is from SAS Eurobonus.

                                  The best thing about rules, is that you can multiple different ones!
                                  Like SAS that allows you to have a long password at least when signing
                                  up, but you'll be sorry if you want to change your password later on.

                                  dumbpasswordrules.com/sites/sa

                                    [?]Dumb Password Rules » 🤖 🌐
                                    @dumbpasswordrules@infosec.exchange

                                    This dumb password rule is from Return of Reckoning.

                                    Password must be between 6 and 100 characters.

                                    It doesn't say on the website, but the password only works in the related game client if it is purely alphanumeric. Not even special characters like % or $ are allowed.

                                    dumbpasswordrules.com/sites/re

                                      [?]Dumb Password Rules » 🤖 🌐
                                      @dumbpasswordrules@infosec.exchange

                                      This dumb password rule is from El Corte Ingles.

                                      Min 6 and max 8 characters for password! Can't contain anything
                                      different than letters and numbers. Apart, the email address must have
                                      at least 8 characters (sorry million dollar domain owners! :D)

                                      dumbpasswordrules.com/sites/el

                                        [?]Dumb Password Rules » 🤖 🌐
                                        @dumbpasswordrules@infosec.exchange

                                        This dumb password rule is from Southwest.

                                        Password must be between 8 and 16 characters in length and include at least one uppercase letter
                                        and one number. Certain special characters are also allowed, but the first character of the password must be alphanumeric.

                                        dumbpasswordrules.com/sites/so

                                          [?]Dumb Password Rules » 🤖 🌐
                                          @dumbpasswordrules@infosec.exchange

                                          This dumb password rule is from SunTrust.

                                          At least there are a variety of special characters to choose from.

                                          dumbpasswordrules.com/sites/su

                                            [?]Dumb Password Rules » 🤖 🌐
                                            @dumbpasswordrules@infosec.exchange

                                            This dumb password rule is from Coppell, TX - Water Utility.

                                            Local Utility with a password restriction of 30 characters. Better than some for sure, but still dumb.

                                            dumbpasswordrules.com/sites/co

                                              Socket boosted

                                              [?]AA » 🌐
                                              @AAKL@infosec.exchange

                                              Socket: Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service socket.dev/blog/malicious-twit @SocketSecurity

                                                [?]Dumb Password Rules » 🤖 🌐
                                                @dumbpasswordrules@infosec.exchange

                                                This dumb password rule is from Telcel.

                                                - The username is the cell phone number (easy to get)
                                                - The company creates a password between 8 and 12 characters for you
                                                - Password must contain at least 1 capital letter and no special characters

                                                dumbpasswordrules.com/sites/te

                                                  [?]Dumb Password Rules » 🤖 🌐
                                                  @dumbpasswordrules@infosec.exchange

                                                  This dumb password rule is from myezyaccess.com patient portal system.

                                                  12-character maximum password length. This is not a single website but a patient portal system used by hundreds of medical facilities via subdomains, with password policy apparently being consistent for all sites.

                                                  dumbpasswordrules.com/sites/my

                                                    [?]Dumb Password Rules » 🤖 🌐
                                                    @dumbpasswordrules@infosec.exchange

                                                    This dumb password rule is from Slovenska sporitelna.

                                                    Slovenska sporitelna is the biggest bank in Slovakia. Despite pretty new version of the internet banking (rolled out in 2018), their password policy restricts password to be 16 characters long at most and prohibits any special characters.

                                                    dumbpasswordrules.com/sites/sl

                                                      [?]Dumb Password Rules » 🤖 🌐
                                                      @dumbpasswordrules@infosec.exchange

                                                      This dumb password rule is from Mobility.

                                                      The username is the customer number, which is sequential and cannot be changed, currently 7 digits long for new customers.
                                                      The password has to be exactly 6 digits long, only numbers allowed.

                                                      dumbpasswordrules.com/sites/mo

                                                        [?]Dumb Password Rules » 🤖 🌐
                                                        @dumbpasswordrules@infosec.exchange

                                                        This dumb password rule is from Chase Bank.

                                                        * Can't use any special characters except ! # $ % + / = @ ~
                                                        * Max length restriction (32 characters).
                                                        * No runs of identical characters ("aaa") or sequential characters ("abc").
                                                        * Password check is case-insensitive

                                                        dumbpasswordrules.com/sites/ch

                                                          Socket boosted

                                                          [?]AA » 🌐
                                                          @AAKL@infosec.exchange

                                                          From yesterday.

                                                          Socket: Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data socket.dev/blog/chrome-firefox @SocketSecurity

                                                            [?]Jonathan Kamens 86 47 » 🌐
                                                            @jik@federate.social

                                                            Dad just called "to let me know" that "he got an alert from Microsoft on his computer" and "he just spoke to someone from Microsoft and they're going to run some scans or something."
                                                            I explained to him, for the ♾️ time, that it's a scam, it's always a scam, it's just a scammy website popping up fake alerts. "What am I supposed to do then?" he asks me. "Just ignore it, it's a scam," I tell him, as I've told him countless times before.
                                                            Dad has a Chromebook.
                                                            🤦

                                                              [?]Dumb Password Rules » 🤖 🌐
                                                              @dumbpasswordrules@infosec.exchange

                                                              This dumb password rule is from SunLife.

                                                              - 8 to 10 characters
                                                              - At least 1 letter and 1 number
                                                              - No spaces, symbols, or accents

                                                              dumbpasswordrules.com/sites/su

                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                @dumbpasswordrules@infosec.exchange

                                                                This dumb password rule is from A1 Mobile Serbia.

                                                                A1 mobile Serbia is a mobile provider in Serbia that imposes poor password rules.

                                                                Translation: "Length of the password must be between 8 and 20 characters and can only have letters and digits."

                                                                dumbpasswordrules.com/sites/a1

                                                                  Wen boosted

                                                                  [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                                  @MissConstrue@mefi.social

                                                                  Hey, questions for folks on the more equipment side of .

                                                                  cage for phone and keyfob? Overkill or common sense? Prices are all over the place, assume cheap off brand are scams? Any recommendations for vendors if a practical idea?

                                                                  It's kinda making me crazy that stores have started put RF readers in the carts and baskets, and readers everywhere are grabbing data they shouldn't just by driving around. Faraday sleeves seem like a good idea in theory, but I don't know if the theory is really practical, as all the tests I've found seem to be manufacturer funded.

                                                                  As an aside, I wonder what happens if you're driving and you put a keyless fob in a faraday sleeve. Would the car turn off? I don't know if they continue to handshake the device once the car is on.

                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                    @dumbpasswordrules@infosec.exchange

                                                                    This dumb password rule is from Vélib’ Métropole.

                                                                    Your password must be at least 10 characters, with at least 1 uppercase character, 1 lowercase character, 1 number and 1 special character (only from this list: @, $, €, #, %, *, ., ;, !, ?).

                                                                    You're not allowed to paste passwords.

                                                                    dumbpasswordrules.com/sites/ve

                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                      @dumbpasswordrules@infosec.exchange

                                                                      This dumb password rule is from Replit.

                                                                      Forces to use minimum 8 characters in the password and it must contain at least one uppercase.

                                                                      dumbpasswordrules.com/sites/re

                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                        @dumbpasswordrules@infosec.exchange

                                                                        This dumb password rule is from Southwest.

                                                                        Password must be between 8 and 16 characters in length and include at least one uppercase letter
                                                                        and one number. Certain special characters are also allowed, but the first character of the password must be alphanumeric.

                                                                        dumbpasswordrules.com/sites/so

                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                          @dumbpasswordrules@infosec.exchange

                                                                          This dumb password rule is from Datart.cz.

                                                                          Czech eshop

                                                                          Password:
                                                                          - Max length is 20 characters
                                                                          - No special characters allowed (only alphanumeric)

                                                                          dumbpasswordrules.com/sites/da

                                                                            [?]Mark Wyner Won’t Comply :vm: » 🌐
                                                                            @markwyner@mas.to

                                                                            IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
                                                                            ----

                                                                            For everyone:

                                                                            If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

                                                                            A hacker is stealing accounts using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

                                                                            You can check if your email is in a data breach elsewhere:

                                                                            haveibeenpwned.com

                                                                            Create a new strong password:

                                                                            1. 12+ characters
                                                                            2. Capital/lowercase letters
                                                                            3. At least one special character

                                                                            For admins:

                                                                            The hacker is using the same unique user agent.

                                                                            Go-http-client/1.1

                                                                            We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

                                                                              [?]Pseudo Nym » 🌐
                                                                              @pseudonym@mastodon.online

                                                                              I haven't played with "developer mode" on an LG TV yet, but had read there was a way to enable a shell like interface for local "app" development.

                                                                              If that works, any possibility of applying some mitigations there for the egregious spying?

                                                                              I'd assume user space would be limited vs firmware nonsense, but if "capture the flag" events taught me anything, getting in system at all frequently leads to escalation.

                                                                              Anyone have references?

                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                @dumbpasswordrules@infosec.exchange

                                                                                This dumb password rule is from Origin.

                                                                                Password must be between 8 and 16 characters long

                                                                                dumbpasswordrules.com/sites/or

                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                  This dumb password rule is from Fidelity.

                                                                                  No more than 20 characters and leave out characters commonly used by
                                                                                  programmers. We don't want you to hack the mainframe.

                                                                                  dumbpasswordrules.com/sites/fi

                                                                                    [?]Dumb Password Rules » 🤖 🌐
                                                                                    @dumbpasswordrules@infosec.exchange

                                                                                    This dumb password rule is from Coppell, TX - Water Utility.

                                                                                    Local Utility with a password restriction of 30 characters. Better than some for sure, but still dumb.

                                                                                    dumbpasswordrules.com/sites/co

                                                                                      [?]Dumb Password Rules » 🤖 🌐
                                                                                      @dumbpasswordrules@infosec.exchange

                                                                                      This dumb password rule is from Return of Reckoning.

                                                                                      Password must be between 6 and 100 characters.

                                                                                      It doesn't say on the website, but the password only works in the related game client if it is purely alphanumeric. Not even special characters like % or $ are allowed.

                                                                                      dumbpasswordrules.com/sites/re

                                                                                        [?]Dumb Password Rules » 🤖 🌐
                                                                                        @dumbpasswordrules@infosec.exchange

                                                                                        This dumb password rule is from La Banque Postale.

                                                                                        Password must be 6 digits and entered on custom pad.

                                                                                        dumbpasswordrules.com/sites/la

                                                                                          [?]Dumb Password Rules » 🤖 🌐
                                                                                          @dumbpasswordrules@infosec.exchange

                                                                                          This dumb password rule is from State Bank of India (Foreign Travel Card).

                                                                                          State Bank of India is the largest government operated bank in India.
                                                                                          They offer "travel" prepaid cards for foreign currencies, this is for
                                                                                          their portal for the prepaid card users to manage their account.

                                                                                          Your password must:
                                                                                          - Be between 8 and 9 characters long
                                                                                          - Contain at least 1 lowercase c...

                                                                                          dumbpasswordrules.com/sites/st

                                                                                            [?]Shawn Webb [He/Him] » 🌐
                                                                                            @lattera@bsd.network

                                                                                            I forgot who does the stickers. I'd like to share some with local groups, like Hackers N Hops.

                                                                                              [?]Scott Wilson 🌈 » 🌐
                                                                                              @scottwilson@infosec.exchange

                                                                                              @james_inthe_box This is awesome and why I absolutely rely on uBlock Origin. Question: does this protection work in and is included in uBlock Origin Lite (uBOL)?

                                                                                                [?]Dumb Password Rules » 🤖 🌐
                                                                                                @dumbpasswordrules@infosec.exchange

                                                                                                This dumb password rule is from EllieMae Access.

                                                                                                Must reset password every 6 months and password requirements are not displayed _anywhere_.
                                                                                                Reset uses a Security Question, and you have to choose from a list of 5.

                                                                                                dumbpasswordrules.com/sites/el

                                                                                                  [?]Dumb Password Rules » 🤖 🌐
                                                                                                  @dumbpasswordrules@infosec.exchange

                                                                                                  This dumb password rule is from HDFC Bank.

                                                                                                  Only a maximum of 15 characters and some special characters are not allowed.

                                                                                                  dumbpasswordrules.com/sites/hd

                                                                                                    Back to top - More...