cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
its good wider community (mostly older folk/seniors?) came out in support after this Islamic Centre in #Cornwall was attacked (including funding upgraded #CCTV and #security equipment!) but offenders need to be caught
After ramming gates, they poured used engine oil around the grounds from what appears to be a 20/25 litre container + maybe a smaller 5l one.
Not stuff you generally have lying around, unless you do your own oil changes or work in a repair garage!
Also to bust the gates they needed access to a large vehicle they didn't mind putting a few (more?) dents/cracks in the bumper, suggesting lads from local rural community (building not obviously Islamic from outside) with an interest in vehicles (but also with history of reckless driving)
...
- #Surveillance
- Controlling content we see
- Making unaccountable life-changing decisions
The #Labour manifesto promised it would regulate AI. But #Starmer succumbed to pressure from #BigTech and pursued ‘growth’ over our rights
It’s time for our new Prime Minister & Minister for AI, Narayan, to introduce legislation that will #regulate AI and ensure that works for all of us and does not harm our #HumanRights
https://action.openrightsgroup.org/tell-andy-burnham-regulate-ai
#safety #security #privacy #DigitalAlert
[2/2]
✍️ New post on serving the change password well-known URL in Django
Add this one redirect and two tests (you won't believe #2) to make your site more user-friendly for users with compromised passwords.
https://adamj.eu/tech/2026/09/16/django-change-password-url/
EuroBSDCon 2026 talks online https://undeadly.org/cgi?action=article;sid=20260916093106 #openbsd #eurobsdcon #conference #development #security
@MichalBryxi Security people don’t do things like timeout, forced password rotation, and OTP 2FA to make systems safer.
They do them to assert their dominance over those they call “normies” by making them miserable.
Adamsdesk Bans Font Squirrel Over Privacy Concerns?
Find out what lead to the discovery of privacy concerns, complications whether to ban linking to certain websites and what decision was made.
https://www.adamsdesk.com/posts/font-squirrel-privacy-concern/
Security through obscurity - the last days
The traditional approach to ‘if no one knows then they won’t find out’ that has been adopted by many companies and organisations to protect their systems is finally on it’s way out - and in part we have AI attacks to thank for it.
We had a big wave of automated Mastodon signups with very predictable usernames.
I first tried the sledgehammer approach and blocked known VPN ranges at the firewall.
It (partially) worked.
It also blocked legitimate ProtonVPN users. 😬
So I replaced that with a tiny custom Mastodon validator that rejects the actual abusive username pattern instead.
Much cleaner: block the abuse, not the transport.
How-to + code:
https://gist.github.com/chofstede/a422427570004719196cde948521dd04
#Mastodon #Mastoadmin #Fediverse #SysAdmin #Ruby #Rails #Security @tux @AlienJay @aping
Imagine you're having a remote appointment with your doctor for a very personal health issue.
Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.
You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.
The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.
"What about all the privacy laws protecting me?", you claim in distress.
Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"
The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.
Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.
This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.
Brace yourself.
The Open Source Security Summit is less than a week away! Featuring insights on cyber policy and geopolitics, the ethics and culture shaping the #security community, and more, this free virtual event is one you won’t want to miss.
Save your spot now: https://bitwarden.com/open-source-security-summit/
The #ColdWar is over. " #PaxAmericana" is over
It's regional powers abusing their neighbors now
#Ukraine, #Georgia etc near #Russia
#Canada, #Venezuela etc near #USA
#Taiwan, #Philippines etc near #China
Here's an amazing bit of #diplomacy #drama on the point
Philippine #Defense Secretary #GilbertoTeodoro at a #SouthKorea #security forum is handed a note apparently from a Chinese #military attaché
And ad libs this witty, dignified reaction
🆕 blog! “ActivityPub - Is it worth defending against replay attacks and message/signature time skew?”
Here's a problem that I've found with ActivityBot - my little ActivityPub server. Sometimes it receives messages which were originally sent months ago. Why does that happen and is it risky to accept and…
👀 Read more: https://shkspr.mobi/blog/2026/09/activitypub-is-it-worth-defending-against-replay-attacks-and-message-signature-time-skew/
⸻
#ActivityBot #ActivityPub #http #security
Ad tracking. Those pesky trackers that allow people to be tracked through (generally) their mobile telephones are proving irksome to the US military. Want to know where a group of targets are congregating - just buy the data from your friendly broker.
How about instead of only solving the problem for the military, you solve the problem for ALL citizens by making such tracking illegal?
Ahh - too obvious.
IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
----
For everyone:
If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.
A hacker is stealing accounts using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.
You can check if your email is in a data breach elsewhere:
Create a new strong password:
1. 12+ characters
2. Capital/lowercase letters
3. At least one special character
For admins:
The hacker is using the same unique user agent.
Go-http-client/1.1
We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.
#Mastodon #Password #InfoSec #OpSec #Security #Privacy #Hacked #Hacker
There will be a PF tutorial at EuroBSDCon 2026 in Brussels:
Network Management with the PF Packet Filter Toolset on OpenBSD and FreeBSD
Featuring Tom Smyth and Peter Hansteen, 2026-09-11, 10:30, full day
See https://events.eurobsdcon.org/2026/talk/RKCHRW/
To register: https://tickets.eurobsdcon.org/eurobsdcon/brussels/
#eurobsdcon #bsd #openbsd #freebsd #networking #firewall #security
If you want a password manager that you can keep local-only, KeePassXC is a great option 🔐
It's free,
Open-source,
Easy to install and use,
Doesn't require an account,
Works on Linux, macOS, and Windows,
And the team is here! 👉 @keepassxc
Here's how to set up KeePassXC with a YubiKey: https://www.privacyguides.org/articles/2025/03/18/installing-keepassxc-and-yubikey/
#PasswordManager #KeePassXC #Privacy #Security #Passwords #FOSS
Waiting Years to Review a Shelly… Then They Sent a Camera #Tech #SmartHome #Frigate #Security #HomeAssistant
Hey fedi hackers, what's your approach to running untrusted code from the internet? Let's say you find a niche lil repo on GitHub and want to try out the thing. Any suggestions on how to securely sandbox the code?