cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Larvitz » 🌐
@Larvitz@mastodon.bsd.cafe

New blog post: PF Firewall on FreeBSD - A Practical Guide

After years of running PF across multiple FreeBSD servers, I've written up the patterns that work: macros, tables, brute-force protection, NAT for jails, and dual-stack filtering.

Covers everything from basic concepts to production configs, plus a sidebar on authpf for bastion hosts.

If you're running FreeBSD and want a firewall that's elegant, powerful, and actually understandable, PF is worth your time.

blog.hofstede.it/pf-firewall-o

    Neil Brown boosted

    [?]GrapheneOS » 🌐
    @GrapheneOS@grapheneos.social

    GrapheneOS version 2026020600 released:

    grapheneos.org/releases#202602

    See the linked release notes for a summary of the improvements over the previous release.

    Forum discussion thread:

    discuss.grapheneos.org/d/31639

      [?]Paco Hope [He/Him] » 🌐
      @paco@infosec.exchange

      Where the web site question “what city were you born in?” is never answered honestly.

        [?]Linux Matters Podcast » 🌐
        @linuxmatters@ubuntu.social

        Alan discovers crypto malware in the Snap Store
        linuxmatters.sh/74/

          [?]Lockdownyourlife » 🌐
          @Lockdownyourlife@infosec.exchange

          What are we using for encrypted video conferencing & webinars these days?

          Anything EU based worth looking at?

          I have Zoom, but would like to move away from it since it's getting rather unstable (like the rest of the US).

            [?]The Psychotic Network Ferret » 🤖 🌐
            @nuintari@mastodon.bsd.cafe

            ... [SENSITIVE CONTENT]

            %sudo pkg audit
            python312-3.12.12_3 is vulnerable:
            python -- several security vulnerabilities
            CVE: CVE-2026-0865
            CVE: CVE-2026-1299
            WWW: vuxml.FreeBSD.org/freebsd/bfe9

            1 problem(s) in 1 package(s) found.

            ZOMGWTFBBQ

            I just got everything rev'd TO 3.12......

              RevK :verified_r: boosted

              [?]Matt Organ » 🌐
              @Slater450413@infosec.exchange

              A friendly reminder to never trust manufacturers privacy protections.

              I was recently attempting to get an external camera functioning, so I started polling various video devices sequentially to find out where it appeared and stumbled across a previously unknown (to me at least) camera device, right next to the regular camera that is not affected by the intentional privacy flap or "camera active" LED that comes built in.

              I had always assumed this was just a light sensor and didn't think any further about it.

              The bandwidth seems to drop dramatically when the other camera is activated by opening the privacy flap, causing more flickering.
              This was visible IRL and wasn't just an artifact of recording it on my phone.
              I deliberately put my finger over each camera one at a time to confirm the sources being projected.

              A friend of mine suggested this may be related to Windows Hello functionality at a guess but still seems weird to not be affected by the privacy flap when its clearly capable of recording video.

              dmidecode tells me this is a LENOVO Yoga 9 2-in-1 14ILL10 (P/N:83LC)

              Command I used for anyone to replicate the finding. (I was on bog standard Kali, but I'm sure you'll figure out your device names if they change under other distros):
              vlc v4l2:///dev/video0 -vv --v4l2-width=320 --v4l2-height=240 & vlc v4l2:///dev/video2 -vv --v4l2-width=320 --v4l2-height=240

              Alt...Video showing the regular camera and the secondary sensor both providing video streams, the secondary continuing to work when the privacy flap is closed and activity LED off.

                [?]mc.fly [he/him] » 🌐
                @mcfly@milliways.social

                Wraithe boosted

                [?]Marcus "MajorLinux" Summers » 🌐
                @majorlinux@toot.majorshouse.com

                For all their faults, this is why I still put Apple on the top of the list.

                I see you, GrapheneOS...

                FBI Couldn’t Get into WaPo Reporter’s iPhone Because It Had Lockdown Mode Enabled

                404media.co/fbi-couldnt-get-in

                  [?]PrivacyDigest » 🌐
                  @PrivacyDigest@mas.to

                  stymied by Apple's after seizing journalist's

                  The Federal Bureau of Investigation has so far been unable to access data from a reporter's iPhone because it was protected by Apple's Lockdown Mode when agents seized the device from the reporter's home, the US government said in a court filing.

                  arstechnica.com/tech-policy/20

                    [?]Tim Mak » 🌐
                    @timkmak@journa.host

                    MORE READY TO , BUT WITH GUARANTEES: In 2022, more than 80 percent of Ukrainians considered ceding territory to Russia unacceptable. Now, 40 percent are willing to give up , but only under the condition of lasting peace and strong security guarantees from and partners, The New York Times reported. nytimes.com/2026/02/04/world/e

                      [?]wtfismyip » 🌐
                      @wtfismyip@gnu.gl

                      Neil Craig boosted

                      [?]ilias 🏴‍☠️💙💛 » 🌐
                      @DM_Ronin@mstdn.social

                      when they say videogames are unrealistic because a combination number is written on a note near the safe

                      Alt...TikTok video of a user approaching Atalanta 1907 stadium area and entering 1907 code in a keypad door for bus which unlocks the door

                        Wen boosted

                        [?]Steve Woods » 🌐
                        @wood5y@mastodonapp.uk

                        "I'm an eighth-generation American, and let me tell you, I wouldn't trust my data, secrets, or services to a US company these days for love or money. Under our current government, we're simply not trustworthy."

                        theregister.com/2026/01/30/eur

                          Alex boosted

                          [?]Tim (Wadhwa-)Brown :donor: » 🌐
                          @timb_machine@infosec.exchange

                          Interesting Git repos of the week:

                          Threats:

                          * github.com/unicodeveloper/glob - the history of conflict mapped with analysis on how it affects modern threats
                          * github.com/narimangharib/starl - analysis of .ir tampering with Starlink

                          Detection:

                          * github.com/MHaggis/ADTrapper - automated hunting in AD
                          * github.com/NasirzadehMoh/CoLog - hunting with collaborative transformers
                          * github.com/Pr0kythera/Mitre-At - visualising ATT&CK

                          Bugs:

                          * github.com/mistymntncop/CVE-20 - Chrome popper?

                          Exploitation:

                          * github.com/thesp0nge/nightcraw - stress test your web apps with @thesp0nge
                          * github.com/htrgouvea/nozaki - another HTTP fuzzer
                          * github.com/splunk/attack_range - simulated environments from Splunk

                          Hard hacks:

                          * github.com/blacktop/ipsw - dicking around with Apple
                          * github.com/checkra1n/PongoOS - alternative booting on Apple hardware

                          Hardening:

                          * github.com/splunk/DECEIVE - Splunk's work on LLM-based honeypots

                          Development:

                          * github.com/shortstheory/kiosla - writing KDE IO slaves

                          Nerd:

                          * github.com/zampierilucas/scx_h - a star crossed /proc

                          , ,

                            [?]wtfismyip » 🌐
                            @wtfismyip@gnu.gl

                            In March 2026, Kubernetes will retire Ingress NGINX, a piece of critical infrastructure for about half of cloud native environments... Existing deployments will continue to work, so unless you proactively check, you may not know you are affected until you are compromised:

                            kubernetes.io/blog/2026/01/29/

                              Tom :damnified: boosted

                              [?]DW Innovation » 🌐
                              @dw_innovation@mastodon.social

                              "While encryption remains mathematically sound (...) its real-world protections are increasingly bypassed by the privileged position AI systems occupy inside modern user environments."

                              cyberinsider.com/signal-presid

                                [?]GrapheneOS » 🌐
                                @GrapheneOS@grapheneos.social

                                GrapheneOS version 2026012800 released:

                                grapheneos.org/releases#202601

                                See the linked release notes for a summary of the improvements over the previous release.

                                Forum discussion thread:

                                discuss.grapheneos.org/d/31269

                                  [?]Michel Lind :fedora: :debian: » 🌐
                                  @michelin@hachyderm.io

                                  for users - if you need fixed builds immediately you can use the builds (not available for i686 due to Community Build Service limitations)

                                  `sudo dnf install centos-release-proposed_updates && sudo dnf update 'openssl*'`

                                  openssl-library.org/news/vulne

                                  These are based on the MRs in progress for the official @centos Stream package and will be cleanly upgradable to the final build

                                  openssl-library.org/news/vulne

                                    [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                                    @gamingonlinux@mastodon.social

                                    Wen boosted

                                    [?]Mark » 🌐
                                    @paka@mastodon.scot

                                    Palantir deals with government amount to at least £670m – including £15m contract with nuclear weapons agency

                                    ’s reliance on , the controversial data surveillance firm, is gaping national

                                    - MPs, tech experts said investigation reveals how deeply embedded Palantir is in UK national

                                    [1/3]

                                      RevK :verified_r: boosted

                                      [?]Emeritus Prof Christopher May » 🌐
                                      @ChrisMayLA6@zirk.us

                                      How would Europe cope with a departure of the US from NATO?

                                      As Carlo Masala (BundeswehrU, Munich) argues, fully substituting for the US capabilities in NATO may be the wrong immediate objective; 'It’s not about being as good as the US, which will take us 15 years or even longer. It is just being better than the Russians'!

                                      Framed like this, while the US leaving NATO would be undoubtedly difficult, the immediate problem(s) may be a little less daunting?


                                      h/t FT

                                        [?]Digital Escape Tools » 🌐
                                        @xabd@mastodon.social

                                        🔐 Aegis Authenticator is a free, open-source 2FA app for Android focused on privacy and security.

                                        Stores all tokens in a locally encrypted vault (AES-256-GCM), works fully offline, supports TOTP & HOTP, and lets you create encrypted backups you control.
                                        Available on F-Droid — no cloud, no tracking.

                                        👉 github.com/beemdevelopment/Aeg

                                        🔍 Listed on digital-escape-tools-phi.verce

                                          [?]Myk [He/Him] » 🌐
                                          @notsle@kzoo.to

                                          @mjg59 Its Important to know....

                                          If you use iOS and iCloud. You want to turn on Advanced Data Protection.
                                          This generates a security key that only you will know. Back it up somewhere secure. It is never shared with Apple.

                                          backups and data are encrypted on your device and even with a proper warrant. Apple would never be able to decrypt the data.

                                          This is one of the features the UK has blocked and is not available there.

                                          macrumors.com/how-to/enable-ad

                                            [?]BastilleBSD :freebsd: » 🌐
                                            @BastilleBSD@fosstodon.org

                                            Did you know that you can use `bastille verify` to check the integrity of your Bastille releases and templates?

                                            > bastille verify 15.0-RELEASE

                                            > bastille verify template/path

                                            This is a great way to ensure that your deployments are
                                            consistent and secure.

                                              [?]Wen » 🌐
                                              @Wen@mastodon.scot

                                              More corruption within government - this time with the intention of making the UK dependent upon aUS tech - and as with the (English) NHS providing access to a deeply unpleasant organisation run by people who should not even be allowed to visit the UK.

                                              opendemocracy.net/en/palantir-

                                                [?]Wen » 🌐
                                                @Wen@mastodon.scot

                                                More reasons not to use .

                                                I know some people do not have a choice, but with turning over encryption keys to the fed (and that will include via ) as well as the eager cooperation of companies like , now is the time to lock down your own data. The linked article presents the facts, but some of the comments do provides links to guides that can help you.

                                                theregister.com/2026/01/23/sur

                                                  [?]LΞX/NØVΛ 🇪🇺 » 🌐
                                                  @lexinova@cyberplace.social

                                                  Not gonna lie.

                                                  But now each time i see an "app" that sell themselve as open source, and good for self hosting, with no out of US official mirror, i see their brand ... extremely negatively.

                                                    [?]Emeritus Prof Christopher May » 🌐
                                                    @ChrisMayLA6@zirk.us

                                                    In the wake of the tangerine Tyrant's threats to Greenland & his worsening attitude to NATO, its no surprise the UK Govt. has re-opened talks with the EU about participation in the Security Action for Europe;

                                                    previous negotiations broke down on the price the UK was (or wasn't) prepared to pay to participate.

                                                    Now with the transatlantic alliance looking less stable, the Govt. has again decided Europe may be a better bet... but will an acceptable price be found?


                                                    h/t FT

                                                      Tommi 🤯 boosted

                                                      [?]Tommi 🤯 [they/he] » 🌐
                                                      @tommi@pan.rent

                                                      I know antivirus software is business bullshit, but I don’t know any reliable source that has an explanation of this, I mostly based this knowledge on vibes…

                                                      Does anyone have any resources to share about this? Are antiviruses actually useless and dead?

                                                        [?]Terminal Tilt » 🌐
                                                        @terminaltilt@climatejustice.social

                                                        Convenience is the enemy of Sovereignty

                                                          Back to top - More...