shakedown.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A community for live music fans with roots in the jam scene. Shakedown Social is run by a team of volunteers (led by @clifff and @sethadam1) and funded by donations.

Administered by:

Server stats:

259
active users

#websecurity

2 posts2 participants0 posts today

»HTTP/1.1 Must Die – It's time to acknowledge HTTP/1.1 is insecure«

Admittedly, I know pers. not how seriously you have to take this but I am only developing web servers set to HTTP/2.0, because HTTP/3 is not yet extensively supported.

🪦 http1mustdie.com

HTTP/1.1 Must Die - The Desync Endgame Begins
http1mustdie.comHTTP/1.1 Must DieUpstream HTTP/1.1 is inherently insecure, and routinely exposes millions of websites to hostile takeover. Join the mission to kill HTTP/1.1 now
#http#web#internet

Semrush ist eines der bekanntesten SEO-Analyse-Tools auf dem Markt. Es durchsucht Websites regelmäßig mit seinem Bot (SemrushBot), um Daten wie Keywords, Backlinks, Rankings und vieles mehr von deiner Website zu erfassen und zu analysieren. Hier sind 5 effektive, schnell umzusetzende Methoden, wie du Semrush von deiner Website aussperren kannst. 👇

teufelswerk.net/semrushbot-blo

Crawler, Scraper, Bots und KI von der Website aussperren
teufelswerk | IT-Sicherheit & Cybersecurity · SemrushBot blockieren – So schützt du jede Website, egal ob WordPress, Joomla, Typo3 oder HTMLSemrush ist eines der bekanntesten SEO-Analyse-Tools auf dem Markt. Wir zeigen dir, wie du den SemrushBot blockieren kannst.

I no longer rely on Jetpack Protect. Instead, I’ve built a lean, hardened WordPress security stack using mod_security, Fail2Ban, WPScan, and a few carefully configured rules. No black boxes. No bloat. Just tools I trust.

#WordPress #Infosec #SelfHosting #WebSecurity #JetpackProtect #Fail2Ban #modSecurity #WPScan

islandinthenet.com/building-my

Island in the Net · Building My Own WordPress Security Stack - Island in the Net
More from Khürt Williams

Important work happening around HTTP Signatures in the Fediverse. Stronger key validation, better digest handling, clearer test vectors—all steps toward more secure and trustworthy ActivityPub communication.
HTTP Signature Upgrades Coming Soon

activitypub.blog/2025/07/03/ht

ActivityPub for WordPress · HTTP Signature Upgrades Coming Soon
More from ActivityPub for WordPress

Durch eine absurde Erfahrung mit der #Sparkasse suche ich nach #BullshitBingo Karten zum Thema #Security (#WebSecurity)

Bisher:
- Einmalcodes per #SMS
- Proprietäre #TOTP App statt offener Standards
- Support nur per Telefon
- Username und Passwort laut durchsagen
- Apps nach 5 Minuten von selber sperren
- Apps nach 3 Monaten ohne Login sperren, ohne Errorcode oder auffindbare Onlinehilfe ("90 Tage")
- App neu installieren, um Problem zu lösen (#TOFU)

Fällt euch noch was ein?

New on WebPerformance Report: HTTP Observatory 🎉
Check your site's HTTP security headers and get clear, actionable results in your inbox.
Thanks to the @MDN team for their technical guidance. 🙌
Because great UX should also be secure.
👉 webperformancereport.com/httpo
#WebPerf #WebSecurity #CyberSecurity

webperformancereport.comHTTP Observatory Report | WebPerformance ReportHTTP Header Security report every week in your inbox. Reports, Decisions, Results...

I had a scary experience with my website that I want to share as a warning. I asked for help making my WordPress site look better in a LinkedIn group, and someone offered to assist, saying it wasn’t responsive. I gave them admin access, but after just one day, I found changes I didn’t make. New pages I didn’t recognize had been created, my menus were altered, and my logo was removed. Thankfully, they didn’t delete anything! They’d only hidden my pages and menus, so I was able to restore everything. I’ve now removed their access. I think this person may have been trying to take over my site.

This was after only 1 day—who knows what they might have done with more time? Please, be extremely cautious about who you trust with admin access to your site, even if they seem helpful. Lesson learned the hard way!

Continued thread

In these dangerous days, you have a special duty to protect your children from online mishaps. This can't start early enough!

Therefore, only give your kids web-safe names! This basically guarantees a good start into privacy & security, especially during a time when they can't take care of themselves.

Good names include: Sienna, Coral, Olive, Goldenrod, Misty Rose, Gainsboro, Peachpuff, Burlywood and Lavender Blush.

#April2023 monthly #Introduction refresh

My name is #Josh. I like having complete control of my data on the #InterWebs, so I host my own single user #Mastodon instance.

I am a level 3 #TechSupport #Engineer at #Forcepoint. I provide #enterprise #support for our #WebSecurity products.

I am a new-ish #dad with a just-turned-2-year-old boy who was a #CovidBaby 🤣

My interests include: #DoctorWho #StarWars #StarTrek #Bluey #Tech #HomeLab #Hardware #FOSS #Marvel #DC #Texas

#Proud to be #Texan

Ok, my turn to write an #introduction full of as many hashtags as I can think of.

I am in #infosec for as long as I can remember. My main interests in the subject are #networksecurity, #websecurity, #codereview, and secure #systemdesign. Unfortunately for you (and probably for me too, I don't know at this point) I also have a Ph.D. and I am a huge fan of "The Logic of Scientific Discovery" by Karl Popper.

I also like #movies, I watch a lot of them and I make way too many references, like the one below.

While waiting for my letter from #Hogwarts, I practice my dark arts with #computerscience the only other thing close to magical spells that I know how to cast. 🧙