cablespaghetti.dev is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
Cablespaghetti's personal snac instance
Admin email
sam@cablespaghetti.dev
Admin account
@sam@cablespaghetti.dev

Search results for tag #security

[?]Alex@rtnVFRmedia Suffolk UK » 🌐
@vfrmedia@social.tchncs.de

its good wider community (mostly older folk/seniors?) came out in support after this Islamic Centre in was attacked (including funding upgraded and equipment!) but offenders need to be caught

After ramming gates, they poured used engine oil around the grounds from what appears to be a 20/25 litre container + maybe a smaller 5l one.

Not stuff you generally have lying around, unless you do your own oil changes or work in a repair garage!

Also to bust the gates they needed access to a large vehicle they didn't mind putting a few (more?) dents/cracks in the bumper, suggesting lads from local rural community (building not obviously Islamic from outside) with an interest in vehicles (but also with history of reckless driving)

bbc.co.uk/news/articles/cm62ex

    Tim Hergert boosted

    [?]Geo Bountalakis :cyberverified_pink: » 🌐
    @geobountalakis@defcon.social

    Told me I need to use "cat" on terminal to see the logs. OK, now what? Where's the logs?

      Wen boosted

      [?]Mark » 🌐
      @paka@mastodon.scot

      ...

      -
      - Controlling content we see
      - Making unaccountable life-changing decisions

      The manifesto promised it would regulate AI. But succumbed to pressure from and pursued ‘growth’ over our rights

      It’s time for our new Prime Minister & Minister for AI, Narayan, to introduce legislation that will AI and ensure that works for all of us and does not harm our

      action.openrightsgroup.org/tel

      [2/2]

        [?]🅰🅻🅸🅲🅴 (🌈🦄) [they/them] » 🌐
        @alice@lgbtqia.space

        : Looking for good smartlock recommendations for a house in the US, in a neighborhood where forced entry isn't too much of a concern.

        My friend's current one is in need of retirement, and I'm a lock person (but the "smart" part isn't really my thing 😋).

        @deviantollam ?

          [?]LWN.net » 🌐
          @lwn@fedi.lwn.net

          [?]LWN.net » 🌐
          @lwn@fedi.lwn.net

          [?]Adam Johnson :django: :python: » 🌐
          @adamchainz@fosstodon.org

          ✍️ New post on serving the change password well-known URL in Django

          Add this one redirect and two tests (you won't believe #2) to make your site more user-friendly for users with compromised passwords.

          adamj.eu/tech/2026/09/16/djang

            [?]LWN.net » 🌐
            @lwn@fedi.lwn.net

            [$] Ways to encrypt data on servers

            At the 2026 edition of FOSSY, Romeo Solano gave a fast-paced, humorous presentation on what could have been a rather boring topic: server encryption. There are a number of threats [...]

            lwn.net/Articles/1092553/

              [?]LWN.net » 🌐
              @lwn@fedi.lwn.net

              [?]Peter N. M. Hansteen » 🌐
              @pitrh@mastodon.social

              [?]Ölbaum » 🌐
              @oscherler@tooting.ch

              @MichalBryxi Security people don’t do things like timeout, forced password rotation, and OTP 2FA to make systems safer.

              They do them to assert their dominance over those they call “normies” by making them miserable.

                [?]Adam » 🌐
                @adamsdesk@fosstodon.org

                Adamsdesk Bans Font Squirrel Over Privacy Concerns?

                Find out what lead to the discovery of privacy concerns, complications whether to ban linking to certain websites and what decision was made.

                adamsdesk.com/posts/font-squir

                A squirrel sitting in an opening covered in grass with a row of tall trees stand in the background around bushes. Above is bold title that reads, 'Adamsdesk Bans Font Squirrel?' with a red no symbol over top of the squirrel.

                Alt...A squirrel sitting in an opening covered in grass with a row of tall trees stand in the background around bushes. Above is bold title that reads, 'Adamsdesk Bans Font Squirrel?' with a red no symbol over top of the squirrel.

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  [?]LWN.net » 🌐
                  @lwn@fedi.lwn.net

                  Emacs arbitrary code execution flaw

                  lwn.net/Articles/1094224/

                    [?]LWN.net » 🌐
                    @lwn@fedi.lwn.net

                    [?]Michal Bryxí [he/him] » 🌐
                    @MichalBryxi@mastodon.world

                    This one goes close to my heart.

                    If you work in and you think you made systems safer by implementing logout timeout, then the only thing you did is that you forced people to find “ways around”.

                    And it is yours and only yours fault if the people do something silly and insecure.

                      [?]Wen » 🌐
                      @Wen@mastodon.scot

                      Security through obscurity - the last days

                      The traditional approach to ‘if no one knows then they won’t find out’ that has been adopted by many companies and organisations to protect their systems is finally on it’s way out - and in part we have AI attacks to thank for it.

                      theregister.com/security/2026/

                        [?]Larvitz :fedora: » 🌐
                        @Larvitz@burningboard.net

                        We had a big wave of automated Mastodon signups with very predictable usernames.

                        I first tried the sledgehammer approach and blocked known VPN ranges at the firewall.

                        It (partially) worked.

                        It also blocked legitimate ProtonVPN users. 😬

                        So I replaced that with a tiny custom Mastodon validator that rejects the actual abusive username pattern instead.

                        Much cleaner: block the abuse, not the transport.

                        How-to + code:
                        gist.github.com/chofstede/a422

                        @tux @AlienJay @aping

                          [?]Em :official_verified: » 🌐
                          @Em0nM4stodon@infosec.exchange

                          Imagine you're having a remote appointment with your doctor for a very personal health issue.

                          Your doctor is a tech enthusiast, and is proudly wearing the new Apple Watch with all the recording features enabled.

                          You don't see the "Audible and visible signals for Live Rewind", because you don't see your doctor's wrist on videochat or on speakerphone.

                          The "Omitted content" safeguard fails to detect the sensitive conversation, because none of the pre-selected keywords are detected.

                          "What about all the privacy laws protecting me?", you claim in distress.

                          Sadly, your doctor is unaware and thinks "surely Apple respects all the laws by default?"

                          The medical clinic isn't informed about privacy risks related to new technologies, and hasn't implemented any training or policies about it yet.

                          Your sensitive health data is collected by Apple's new features, stored on their servers, blissfully unaware of the infringements to your consent, your privacy, and all the laws supposed to protect you.

                          This is only one scenario of the many surveillance nightmares we might hear about in the coming months and years.

                          Brace yourself.

                            [?]Bitwarden » 🌐
                            @bitwarden@fosstodon.org

                            The Open Source Security Summit is less than a week away! Featuring insights on cyber policy and geopolitics, the ethics and culture shaping the community, and more, this free virtual event is one you won’t want to miss.

                            Save your spot now: bitwarden.com/open-source-secu

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              [?]LWN.net » 🌐
                              @lwn@fedi.lwn.net

                              Forgejo 16.0.4 and 15.0.8 address critical security vulnerability

                              lwn.net/Articles/1093671/

                                [?]LWN.net » 🌐
                                @lwn@fedi.lwn.net

                                Wen boosted

                                [?]⏩︎VOTE⏪︎ ᶜʸⁿⁱᶜⁱˢᵐ⁼ᵃᶜᶜᵉᵖᵗᵃⁿᶜᵉ (Ben Royce) » 🌐
                                @benroyce@mastodon.social

                                The is over. " " is over

                                It's regional powers abusing their neighbors now

                                , etc near

                                , etc near

                                , etc near

                                Here's an amazing bit of on the point

                                Philippine Secretary at a forum is handed a note apparently from a Chinese attaché

                                And ad libs this witty, dignified reaction

                                deccanherald.com/world/asia/ha

                                Alt...Gilberto Teodoro on stage is handed a piece of paper, and improvises a reaction to it

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  [?]Wen » 🌐
                                  @Wen@mastodon.scot

                                  [?]LWN.net » 🌐
                                  @lwn@fedi.lwn.net

                                  Terence Eden boosted

                                  [?]Terence Eden » 🌐
                                  @Edent@mastodon.social

                                  🆕 blog! “ActivityPub - Is it worth defending against replay attacks and message/signature time skew?”

                                  Here's a problem that I've found with ActivityBot - my little ActivityPub server. Sometimes it receives messages which were originally sent months ago. Why does that happen and is it risky to accept and…

                                  👀 Read more: shkspr.mobi/blog/2026/09/activ

                                    [?]Wen » 🌐
                                    @Wen@mastodon.scot

                                    Ad tracking. Those pesky trackers that allow people to be tracked through (generally) their mobile telephones are proving irksome to the US military. Want to know where a group of targets are congregating - just buy the data from your friendly broker.

                                    How about instead of only solving the problem for the military, you solve the problem for ALL citizens by making such tracking illegal?

                                    Ahh - too obvious.

                                    theregister.com/public-sector/

                                      [?]Mark Wyner Won’t Comply :vm: » 🌐
                                      @markwyner@mas.to

                                      IMPORTANT MASTODON PASSWORD SECURITY/PRIVACY ISSUE…
                                      ----

                                      For everyone:

                                      If you are using the same password for Mastodon that you use anywhere else, CHANGE YOUR PASSWORD NOW.

                                      A hacker is stealing accounts using something called “credential stuffing.” This means they use email/password combinations stolen from other sites.

                                      You can check if your email is in a data breach elsewhere:

                                      haveibeenpwned.com

                                      Create a new strong password:

                                      1. 12+ characters
                                      2. Capital/lowercase letters
                                      3. At least one special character

                                      For admins:

                                      The hacker is using the same unique user agent.

                                      Go-http-client/1.1

                                      We’re seeing a pattern of IPs, but they’re from varying ISPs. They’re also not changing the account emails.

                                        [?]LWN.net » 🌐
                                        @lwn@fedi.lwn.net

                                        [?]Peter N. M. Hansteen » 🌐
                                        @pitrh@mastodon.social

                                        There will be a PF tutorial at EuroBSDCon 2026 in Brussels:

                                        Network Management with the PF Packet Filter Toolset on OpenBSD and FreeBSD
                                        Featuring Tom Smyth and Peter Hansteen, 2026-09-11, 10:30, full day

                                        See events.eurobsdcon.org/2026/tal
                                        To register: tickets.eurobsdcon.org/eurobsd

                                          [?]LWN.net » 🌐
                                          @lwn@fedi.lwn.net

                                          [?]Stefano Marinelli » 🌐
                                          @stefano@mastodon.bsd.cafe

                                          The Debian Security Advisory DSA-6482-1 has so many CVEs that just the assigned numbers don't fit into the 5000 character limit we have here 😆

                                            [?]LWN.net » 🌐
                                            @lwn@fedi.lwn.net

                                            [?]Em :official_verified: » 🌐
                                            @Em0nM4stodon@infosec.exchange

                                            If you want a password manager that you can keep local-only, KeePassXC is a great option 🔐

                                            It's free,
                                            Open-source,
                                            Easy to install and use,
                                            Doesn't require an account,
                                            Works on Linux, macOS, and Windows,
                                            And the team is here! 👉 @keepassxc

                                            Here's how to set up KeePassXC with a YubiKey: ‪privacyguides.org/articles/202

                                              RevK :verified_r: boosted

                                              [?]Home Is Where The Smart Is » 🌐
                                              @HomeIsWhereTheSmartIs@toot.wales

                                              [?]LWN.net » 🌐
                                              @lwn@fedi.lwn.net

                                              [$] Securely suspending LUKS-encrypted disks

                                              When a laptop is asleep, its memory is not unreadable. The right tooling can attach to the computer's memory bus and read out its contents, and cold-boot attacks can theoretically [...]

                                              lwn.net/Articles/1090568/

                                                [?]LWN.net » 🌐
                                                @lwn@fedi.lwn.net

                                                [?]iooioio » 🌐
                                                @iooioio@fosstodon.org

                                                Hey fedi hackers, what's your approach to running untrusted code from the internet? Let's say you find a niche lil repo on GitHub and want to try out the thing. Any suggestions on how to securely sandbox the code?

                                                  [?]Paul - Antifa. LGBTQ+ safe. » 🌐
                                                  @paulk@writing.exchange

                                                  I'm suddenly reconsidering a cloud solution for a password manager. Just now I had no connection to proton pass, on a moment where I needed it.
                                                  This is quite a tad annoying.
                                                  What are you using? Keepass? A notebook? Let me know!

                                                    Back to top - More...