cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]LWN.net » 🌐
@lwn@fedi.lwn.net

[?]Peter N. M. Hansteen » 🌐
@pitrh@mastodon.social

[?]nixCraft 🐧 » 🌐
@nixCraft@mastodon.social

Google now support account recovery with AI and your face. What could possibly go wrong? Google having my face is not just bad enough but chances are high that selfie video may not work in edge cases or network down etc.

blog.google/innovation-and-ai/

The tweet from Google offical account reads:

Forgot your password? Lost your phone? Can’t get into your account? 

You can now use a selfie video to log into your Google Account. 

The new feature is easy to use and lets you sign in — even if you forget your password or don’t have your usual phone or laptop — with a quick selfie.

There is a short video showing how to use a selfie video to log into your Google Account and link to https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/

Alt...The tweet from Google offical account reads: Forgot your password? Lost your phone? Can’t get into your account? You can now use a selfie video to log into your Google Account. The new feature is easy to use and lets you sign in — even if you forget your password or don’t have your usual phone or laptop — with a quick selfie. There is a short video showing how to use a selfie video to log into your Google Account and link to https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/

    [?]BobDaHacker 🏳️‍⚧️ [She/They] » 🌐
    @bobdahacker@infosec.exchange

    🙏 New Blog Post

    The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

    What's exposed:

    • Email addresses
    • Names
    • Country
    • Date of birth (they call it "borned_date" lol)
    • Account role (it's "PRAYER" for everyone, obviously)

    Also found:

    • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
    • Their verification emails fail their own domain's authentication requirements

    Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

    Full writeup: bobdahacker.com/blog/click-to-

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      [?]LWN.net » 🌐
      @lwn@fedi.lwn.net

      PyPI now rejects new files after 14 days

      lwn.net/Articles/1084218/

        [?]LWN.net » 🌐
        @lwn@fedi.lwn.net

        [?]PrivacyDigest » 🌐
        @PrivacyDigest@mas.to

        A Device Hidden in Across the US Leaves Them to and Paralysis. Patch It Now

        installed alarms in millions of vehicles—and left them in even if the buyer didn’t want them. Now researchers warn they can be hacked to unlock, track, and disable cars.

        wired.com/story/a-device-hidde

          [?]Python Package Index » 🌐
          @pypi@fosstodon.org

          The Python Package Index now rejects new files published to releases older than 14 days. This mitigation prevents long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects are compromised.

          blog.pypi.org/posts/2026-07-22

            [?]BrianKrebs » 🌐
            @briankrebs@infosec.exchange

            New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps

            The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

            krebsonsecurity.com/2026/07/lg

            A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. The image features a picture of Pac-Man celebrating, and some ghosts on the right. It says: Play Pac-Man without ads! For an ad free experience, please allow web indexing by Bright Data to use your device's free resources and IP address to download web data from the Internet. None of your personal information is collected, except your IP address. Bright Data does not track you. Bright Data may continue running in the background even after you close the app. Scan the QR code to learn more about Bright Data policy and ethical usage. Image: Spur.us.

            Alt...A Pac-Man smart TV app from Bright Data offers users the choice between viewing ads in the game or agreeing to allow their TV to serve as a residential proxy node. The image features a picture of Pac-Man celebrating, and some ghosts on the right. It says: Play Pac-Man without ads! For an ad free experience, please allow web indexing by Bright Data to use your device's free resources and IP address to download web data from the Internet. None of your personal information is collected, except your IP address. Bright Data does not track you. Bright Data may continue running in the background even after you close the app. Scan the QR code to learn more about Bright Data policy and ethical usage. Image: Spur.us.

              [?]h3artbl33d :openbsd: :antifa: [Try/Me] » 🌐
              @h3artbl33d@exquisite.social

              Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special.

              That is, until I noticed what machine was listed. Introduced late 2015/early 2016 :flan_awe:

              I have never purchased whatever support. Both Supermicro and Dell work this way.

              HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you :flan_nooo:

              In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer.

              However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash :flan_molotov:

                [?]Peter N. M. Hansteen » 🌐
                @pitrh@mastodon.social

                [?]LWN.net » 🌐
                @lwn@fedi.lwn.net

                🗳

                [?]Aaron Toponce ⚛️:debian: » 🌐
                @atoponce@fosstodon.org

                When building a multi-factor authentication system for clients, backups codes should be generated just in case the user does not have their second factor with them.

                The backup codes should all be one-time use of course, but how do you store them on the backend? What is best practice here? What is a real-world threat model?

                Store plaintext to be viewed later:1
                Encrypt with key in TPM to be viewed later:3
                Hash with a password hashing function (bcrypt):17

                Closed

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  Catanzaro: Some changes to GNOME security tracking

                  lwn.net/Articles/1083754/

                    [?]Robert Kingett » 🌐
                    @WeirdWriter@caneandable.social

                    ... [SENSITIVE CONTENT]

                    The best compliment I could’ve ever received! Why don’t you artist types ever describe technology in technical terms? How do I know if you are correct or not! My reply? That’s the whole point! Here’s a little hint! I did that on purpose to make all the tech nerds squirm ! How to make portable Passkeys, Sightless Scribbles sightlessscribbles.com/posts/h

                      [?]LWN.net » 🌐
                      @lwn@fedi.lwn.net

                      [?]Mitex Leo » 🌐
                      @ml@social.mitexleo.one

                      [?]h3artbl33d :openbsd: :antifa: [Try/Me] » 🌐
                      @h3artbl33d@exquisite.social

                      🚨 Actively abused vulnerability in WP 🚨

                      WordPress has an actively abused SQL injection in the core in versions =<7.0.1. You should update to 7.0.2 as soon as humanly possible. Sites are already exploited.

                      Check whether the site has admin users that you don't recognize :flan_hacker:

                      More info: patchstack

                      Note: it has been a long time since there was a nasty vuln like this in the WP core.

                        [?]Shawn Hooper » 🌐
                        @shooper@shawnhooper.ca

                        RFC 9116: security.txt

                        Does your website have a security.txt file to let security researchers know how to responsibly contact you regarding security vulnerabilities on your site?

                        shawnhooper.ca/2026/07/18/rfc-

                        a red security sign and a blue security sign

                        Alt...a red security sign and a blue security sign

                          [?]LWN.net » 🌐
                          @lwn@fedi.lwn.net

                          "Half a Second" — a book on the XZ backdoor

                          lwn.net/Articles/1083466/

                            [?]LWN.net » 🌐
                            @lwn@fedi.lwn.net

                            [?]Aaron Toponce ⚛️:debian: » 🌐
                            @atoponce@fosstodon.org

                            Asking various bots to generate 10 , then using syntax highlighting to match different character classes to visually identify patterns.

                            The prompt is exactly "Generate 10 passwords". I did not elaborate further or otherwise restrict the bot in what to generate.

                            Aside from the risks of servers generating secrets for you, I think it's obvious that these lack quality entropy.

                            Just use the password generator that ships with your password manager.

                            Screenshot of passwords generated from 8 different LLMs using view(1) in Konsole

                            Alt...Screenshot of passwords generated from 8 different LLMs using view(1) in Konsole

                              [?]GrapheneOS » 🌐
                              @GrapheneOS@grapheneos.social

                              GrapheneOS version 2026071500 released:

                              grapheneos.org/releases#202607

                              See the linked release notes for a summary of the improvements over the previous release.

                              Forum discussion thread:

                              discuss.grapheneos.org/d/40416

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                Local DoS attack vectors in seunshare 3.10 (SUSE Security Team Blog)

                                lwn.net/Articles/1083076/

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  Many old shim versions are still accepted by secure boot

                                  lwn.net/Articles/1082940/

                                    [?]LWN.net » 🌐
                                    @lwn@fedi.lwn.net

                                    [?]Peter N. M. Hansteen » 🌐
                                    @pitrh@mastodon.social

                                    [?]LWN.net » 🌐
                                    @lwn@fedi.lwn.net

                                    Chewie boosted

                                    [?]PrivacyDigest » 🌐
                                    @PrivacyDigest@mas.to

                                    [?]Wen » 🌐
                                    @Wen@mastodon.scot

                                    For those who have been following the Israeli company’s Pegasus product being used to spy on journalists and politicians around the world, this might amuse. A podcast from Australia’s ABC. I might disagree with some of their conclusions, but it is a very fun listen.

                                    abc.net.au/listen/programs/if-

                                      [?]GrapheneOS » 🌐
                                      @GrapheneOS@grapheneos.social

                                      GrapheneOS version 2026071100 released:

                                      grapheneos.org/releases#202607

                                      See the linked release notes for a summary of the improvements over the previous release.

                                      Forum discussion thread:

                                      discuss.grapheneos.org/d/39301

                                        [?]LWN.net » 🌐
                                        @lwn@fedi.lwn.net

                                        [$] An update on the scraper situation

                                        Our article "Fighting the AI scraper bot scourge", published in early 2025, discussed the problem of widespread scraping of web sites in search of training data for large language [...]

                                        lwn.net/Articles/1080822/

                                          [?]LWN.net » 🌐
                                          @lwn@fedi.lwn.net

                                          [?]chris@strafpla.net [he/him] » 🌐
                                          @chris@mstdn.strafpla.net

                                          The state of "" :
                                          How do we keep Captain Crunch from phreaking by inventing elaborate melodies?

                                          en.wikipedia.org/wiki/John_Dra

                                            [?]LWN.net » 🌐
                                            @lwn@fedi.lwn.net

                                            [?]Aaron Toponce ⚛️:debian: » 🌐
                                            @atoponce@fosstodon.org

                                            A few implementations of collecting mouse entropy for secure randomness generation.

                                            gist.github.com/atoponce/aab15

                                              [?]LWN.net » 🌐
                                              @lwn@fedi.lwn.net

                                              [?]Liam @ GamingOnLinux 🐧🎮 » 🌐
                                              @gamingonlinux@mastodon.social

                                              Back to top - More...