Haven Blog

Privacy, encryption,
and secure communication.

Practical writing on the tools, protocols, and trade-offs behind private communication — without the marketing spin.

Supply Chain

Git Commit Signing: Proving Who Wrote the Code

The author name on a git commit is a text field anyone can set to your name and email, with no check at all. Commit signing turns that unenforced label into a cryptographic claim. GPG, SSH, and Sigstore signing compared, plus the gap between signed and verified.

July 23, 202610 min read
Cryptography

Web Key Directory: PGP Key Discovery That Actually Works

PGP's real failure was never the math, it was finding the right key. Web Key Directory ties a key to the domain that serves it, over HTTPS, with no keyserver spam. How the hashed-localpart lookup works, and exactly what it does and does not prove.

July 23, 20269 min read
Network Privacy

DNSCrypt: The Encrypted DNS Protocol That Predates DoH

Before DNS over HTTPS, DNSCrypt made different choices: it authenticates your resolver with a pinned public key instead of the web CA system, and its relay mode splits who you are from what you ask. A look at the older protocol on its own terms.

July 23, 20269 min read
Privacy Tools

Syncthing: File Sync With No Cloud in the Middle

Dropbox and Google Drive keep a readable copy of your files on someone else's server. Syncthing syncs your devices directly over authenticated TLS, with no account and no provider holding your data. Device IDs, the Block Exchange Protocol, and the real trade-offs.

July 23, 20269 min read
Identity

Keyoxide: Proving Your Accounts Are Yours, Without a Middleman

Keybase linked your online identities to a cryptographic key, then sold itself to Zoom. Keyoxide does the same job with no company at the center: bidirectional proofs that live in your key and on the platforms, verifiable by any tool that implements the open spec.

July 23, 20269 min read
Privacy & Law

Carpenter v. United States and the Cracks in the Third-Party Doctrine

In 2018 the Supreme Court ruled that police generally need a warrant for your cell-site location history. The first real crack in the doctrine that let the state treat anything you hand a company as fair game, and the data-broker workaround that survived it.

July 22, 202610 min read
Cryptography

Schnorr Signatures: A Cleaner Path Than ECDSA

A patent kept one of the simplest signature schemes out of the mainstream for 20 years, so the industry built ECDSA to route around it. How Schnorr signing works, why linearity enables key aggregation and threshold signing, and why the nonce decides everything.

July 22, 202610 min read
Cryptography

Garbled Circuits: Computing on Data Nobody Reveals

Two people compute a function of their private inputs and learn only the result. From Yao's 1982 millionaires' problem to the optimizations that make secure two-party computation practical today.

July 22, 202611 min read
Supply Chain

Binary Transparency: Making Software Updates Auditable

A signed update is only as safe as the signer. Logging every released build in a public append-only record makes a backdoor shipped to one target detectable, the way Certificate Transparency did for the web.

July 22, 20269 min read
Emerging Threats

Data Poisoning: Fighting Back Against AI Scraping

Opting out of AI training does nothing once the weights have absorbed your data. How Glaze and Nightshade corrupt a scraper's training set, and why it is an arms race rather than a permanent fix.

July 22, 20269 min read
Encryption Protocols

The Terrapin Attack: How a Few Deleted Packets Weaken SSH

A network attacker can trim messages off the start of an SSH session without breaking the encryption. How prefix truncation works, which ciphers were affected, and why the fix is a lesson in authenticating the whole conversation.

July 21, 20269 min read
Cryptography & Policy

Dual_EC_DRBG: The Random Number Generator With a Trapdoor

A standardized random number generator built on a structure that could hide a master key for whoever chose its constants. How it was flagged in 2007, shipped in defaults anyway, and later found altered in production firewalls.

July 21, 202610 min read
Cryptography

The Dining Cryptographers Problem: Anonymity Without a Trusted Middleman

Chaum's 1988 puzzle shows how a group can broadcast a message so that nobody, not even the other participants, can tell who sent it, with no trusted server and no assumption that any hard math problem stays hard.

July 21, 20269 min read
Cryptography

BLAKE3: The Hash Function Built Like a Tree

A modern cryptographic hash that is fast, parallel, and versatile. How its Merkle-tree structure lets it use every CPU core, verify streams as they arrive, and serve as a hash, MAC, and key derivation function in one.

July 21, 20268 min read
Cryptography

Honey Encryption: Making Every Wrong Guess Look Right

A technique that defeats offline brute force by producing a plausible fake plaintext for every wrong password an attacker tries. How the distribution-transforming encoder works, where it fits, and its real limits.

July 21, 20268 min read
AI & Privacy

Private Cloud Compute: Apple's Attempt at Server-Side AI You Can Verify

Apple built cloud AI servers designed so that even Apple cannot read the requests. How attestation, transparency logs, and stateless nodes replace "trust us" with "check us," and where the trust still lands.

July 19, 20268 min read
Secure Messaging

Linked Devices: The Quiet Weak Point in Encrypted Messengers

Attackers targeting Signal users stopped attacking the encryption and started tricking victims into linking attacker devices instead. How QR-code linking phishing works and how to audit your own devices.

July 19, 20267 min read
Email Security

How to Read Email Headers: Tracing a Message to Its Real Origin

Every email carries a hidden travel log. How to walk the Received chain, read SPF, DKIM, and DMARC verdicts, and spot the mismatches phishers hope you never look for.

July 19, 20268 min read
Web Security

Subdomain Takeover: When Dangling DNS Hands Your Domain to Strangers

A CNAME pointing at a deleted cloud resource is an open invitation. How takeover works, why it defeats cookies and TLS, and the DNS hygiene that prevents it.

July 19, 20267 min read
Encryption

PGP Keyservers: The Broken Phone Book of Encrypted Email

The keyserver network accepted any upload from anyone, forever, until someone weaponized that in 2019. What replaced it: verified keyservers, WKD, and key transparency.

July 19, 20267 min read
Encryption

PQXDH and PQ3: How Messengers Are Going Post-Quantum

Signal and Apple shipped post-quantum key agreement to billions of phones without anyone noticing. What changed, what stayed classical, and why the deadline arrives before the quantum computer does.

July 18, 20268 min read
Privacy & Browsers

Safe Browsing: What the Malware Blocklist in Your Browser Sends to Google

Chrome, Firefox, and Safari all check the pages you visit against one Google service. The hash-prefix design keeps your browsing on your device, until you flip the one setting that changes the deal.

July 18, 20267 min read
Metadata & Privacy

Your Calendar Knows Everyone You Meet: The Privacy Gap in Calendar and Contact Sync

A calendar entry has participants, a time, a place, and a purpose stated in plain language. On every major platform's default settings, the provider can read all of it.

July 18, 20267 min read
Privacy Guides

Running AI Locally: What a Local LLM Protects, and What It Doesn't

A court has already ordered one AI company to preserve users' deleted chats. A model on your own hardware has no log to preserve. What the trade costs in capability, and when it is worth it.

July 18, 20267 min read
Email Security

Spam Filtering Reads Your Mail: The Trade-Off Nobody Mentions

Your inbox is usable because software inspects every message sent to you. Which filtering layers need to read content, which don't, and how encrypted mail squares the circle.

July 18, 20267 min read
Emerging Threats

Windows Recall: What a Computer That Screenshots Everything Means for Private Messaging

Recall photographs your screen every few seconds and files the result in a searchable archive. What that does to disappearing messages, encrypted chats, and anyone who shares a PC.

July 17, 20267 min read
Legal & Policy

The Clipper Chip: How the First Government Encryption Backdoor Fell Apart

In 1993 the US government shipped an encryption chip with a wiretap port in the silicon and asked America to trust it. A 16-bit checksum and one researcher later, the program was dead.

July 17, 20267 min read
Legal & Policy

The EU Told WhatsApp to Open Up: Where Messaging Interoperability Actually Stands

The Digital Markets Act requires WhatsApp to interoperate with smaller messengers, encryption intact. Who connected, who refused, and why the refusals are a privacy argument too.

July 17, 20268 min read
Protocols

JMAP Explained: The Protocol Built to Replace IMAP

IMAP was designed in 1986 and it shows. JMAP rebuilds mail sync as JSON over HTTPS: one round trip, real push, sane state. Why the better protocol is still waiting for adoption.

July 17, 20267 min read
Email Security

Email Bombing: When a Flooded Inbox Is the Cover Story

Thousands of newsletter confirmations arriving at once is rarely random. Subscription bombing exists to bury one email you were supposed to see, usually while money moves.

July 17, 20266 min read
Legal & Policy

EncroChat, Sky ECC, ANOM: What the Crypto Phone Takedowns Proved

Three encrypted phone networks fell between 2020 and 2021, and investigators never broke the encryption once. What the takedowns prove about closed networks and verifiable security.

July 16, 20268 min read
Encryption Protocols

Off-the-Record Messaging: Where Deniable Encryption Started

OTR brought forward secrecy and deniability to instant messaging in 2004, two decades before they were table stakes. How the protocol worked, and what Signal inherited from it.

July 16, 20267 min read
Account Security

Recycled Phone Numbers: The Account Takeover Nobody Plans For

Carriers reassign tens of millions of numbers a year, and the new owner inherits your SMS codes, password resets, and messaging identity. What to do before you give up a number.

July 16, 20267 min read
Privacy Guides

Who Can See Who Owns Your Domain: WHOIS, RDAP, and Registration Privacy

Registering a domain used to publish your home address to anyone who asked. GDPR and RDAP changed the defaults, but the archives never forgot and the exceptions matter.

July 16, 20267 min read
Web Security

The Padlock Ends at the CDN: Who Actually Reads Your HTTPS Traffic

For a large share of the web, the encrypted tunnel ends at a CDN edge server that decrypts everything, by design. What TLS termination means for the padlock's promise.

July 16, 20267 min read
Fraud Prevention

The Phone Call Isn't Always Who It Says It Is: Digital Security for Older Adults

Caller ID can be faked in seconds, and voice cloning is closing the gap on "I'd know it's not really them." A practical guide to the defenses that actually work.

July 15, 20267 min read
Travel Security

Working From Everywhere: The Device Security Habits That Actually Matter

Living out of a bag across borders changes your device threat model in ways a home office never tests. Encryption, backup redundancy, and identity recovery when you lose a device far from home.

July 15, 20268 min read
Legal & Policy

What Bar Ethics Rules Actually Require of Encrypted Client Communication

ABA Formal Opinion 477R replaced a blanket rule with a fact-based standard. Here's what "reasonable efforts" actually means for firms choosing email tools.

July 15, 20268 min read
Networking & Security

The Hotel Wifi Problem: What Actually Changes on a Shared Network

Hotel and cafe wifi puts every device on the same broadcast segment as strangers. What TLS and DNS encryption do and don't cover, and where a VPN actually helps.

July 15, 20268 min read
Privacy & Security Hygiene

What's Hiding in Your Photos: EXIF Metadata and Who Can Read It

Every photo your phone takes carries a metadata block most apps never show you, including GPS coordinates precise enough to name a building. What's in it, who strips it, and how to check.

July 15, 20267 min read
Protocols & Architecture

SecureDrop and the Architecture of Anonymous Whistleblowing

A contact form on a newsroom website is not an anonymous submission system, even with HTTPS. How onion services, air-gapped viewing stations, and codename logins are built to survive the server itself being seized.

July 14, 20268 min read
AI & Privacy

AI Training Data Scraping and What Opt-Out Actually Covers

Robots.txt was built in 1994 to keep search bots out of the wrong folders, not to govern AI training. How crawler opt-out actually works, and what it doesn't stop.

July 14, 20267 min read
Safety & Security Hygiene

Digital Safety Planning for Domestic Violence Survivors

Most of the access an abuser has to a survivor's digital life isn't hacking, it's a shared iCloud account or an old family location plan. A practical guide to closing the common ones off.

July 14, 20267 min read
Mobile Security

GPS Spoofing and the Location Data Apps Assume Is Real

Civilian GPS has no authentication built in, from a developer's mock-location toggle to signal interference reported over the Baltic Sea and Eastern Mediterranean. How spoofing actually works, and why it cuts both ways.

July 14, 20267 min read
Policy & Law

Why Some Encryption Apps Geofence Certain Countries

Cryptography was once classified as a munition under US export law. The Crypto Wars ended decades ago, but the regulatory scaffolding they left behind still shapes what privacy apps ship where.

July 14, 20268 min read
Surveillance & Policy

Mail Covers: The Postal Surveillance Program Older Than Email

A law enforcement agency does not need a warrant to find out who you correspond with by mail, only a form. How USPS mail covers work, the 2013 disclosure that surfaced them, and what the exterior of an envelope actually reveals.

July 13, 20267 min read
Policy & Law

Why Your Library Card Has Better Privacy Law Than Your Email

Nearly every U.S. state has a specific statute protecting library reading records, and four Connecticut librarians fought a gag order to prove it mattered. How library privacy law works, and where the protection stops.

July 13, 20266 min read
Security Hygiene

What's Actually Left on the Hard Drive You Sold

Deleting a file and formatting a drive both leave the data recoverable. Researchers have spent two decades buying used drives at resale markets and finding exactly that. What NIST 800-88 recommends instead.

July 13, 20267 min read
Consumer Privacy

Your E-Reader Knows Where You Stopped Reading

E-readers can log furthest page read, time spent per page, and which passages you highlighted, then aggregate that across millions of readers. What's actually collected, and how to turn it off.

July 13, 20266 min read
Privacy How-To

The Digital Accounts Nobody Thinks to Untangle After a Breakup

Shared streaming logins, family location sharing, and a smart doorbell on a joint account can quietly outlast a relationship. A practical checklist for re-partitioning your digital life.

July 13, 20267 min read
Surveillance

Shadow Profiles: The File Platforms Keep on People Who Never Signed Up

Delete Instagram, never sign up for Facebook, refuse every contact sync prompt, and the platform can still hold a working file on you, built entirely from other people's address books. Where the data comes from, and why a 2018 congressional exchange confirmed the mechanism without ever using the term.

July 12, 20267 min read
Cryptography

Hybrid Post-Quantum TLS: How Your Browser Is Already Defending Against a Computer That Doesn't Exist Yet

Chrome, Cloudflare, Signal, and OpenSSH have all quietly shipped post-quantum key exchange, and none of them dropped classical cryptography to do it. What hybrid key exchange means, why "harvest now, decrypt later" makes this urgent today, and what's still unsolved.

July 12, 20268 min read
Law & Policy

Call Recording Laws: Why "This Call May Be Recorded" Means Different Things in Different States

US federal law lets one person on a call record it without telling anyone. About a dozen states disagree, and the Linda Tripp case shows exactly how seriously they mean it. What one-party and all-party consent actually require.

July 12, 20267 min read
Health Data

Your Prescription History Has More Readers Than Your Doctor

Pharmacy benefit managers, data aggregators, and discount-card apps all see what medications you take, and HIPAA covers less of that chain than most people assume. What Sorrell v. IMS Health and the GoodRx settlement actually established.

July 12, 20267 min read
Browser Privacy

Browser Compartmentalization: Splitting Your Identities Without Splitting Your Workflow

Containers, browser profiles, and separate browsers all isolate cookies differently, and none of them stop fingerprinting on their own. What each layer actually contains, and a setup that doesn't get in your way.

July 12, 20267 min read
Mobile Security

The Baseband Processor: The Other Operating System in Your Phone

Your phone runs a second computer with its own CPU, its own closed firmware, and a direct line to every cell tower. In 2023, Google found bugs in it that could be exploited knowing only a victim's phone number. What the baseband is, and what actually reduces the risk.

July 11, 20268 min read
Encryption

The One-Time Pad: Provably Unbreakable, Almost Never Used

Exactly one encryption scheme carries a mathematical proof that it cannot be broken, and modern cryptography deliberately walked away from it. Why the proof is real, what VENONA did to the Soviets who cut corners, and why "one-time pad" in a product pitch is a red flag.

July 11, 20268 min read
Encryption

Kerckhoffs's Principle: Why Good Security Assumes the Enemy Has the Blueprints

An 1883 rule still sorts working cryptography from theater: a system must stay secure even when everything about it except the key is public. What the principle says, the Crypto AG case that shows what secrecy can hide, and how to apply it when evaluating products.

July 11, 20268 min read
Consumer Privacy

What You Give Up When You Sign In With Google

The social login button saves thirty seconds and appoints an identity provider as the doorman for that account: one who logs every visit and can decline to open the door. What the provider learns, what happens when the main account is suspended, and the alternatives.

July 11, 20267 min read
Data Privacy

Voter Files: The Public Record Almost Nobody Knows They Are In

Register to vote in most US states and your name, home address, and turnout history become an obtainable record. Twice in a decade, databases covering nearly every American voter sat exposed online. How voter files circulate, and what registrants can do.

July 11, 20267 min read
Consumer Privacy

Loyalty Programs: What Your Grocery Store Does With Your Purchase History

The phone number at checkout ties every basket to a profile that persists for years, feeds a retail advertising business, and answers subpoenas. What the record contains, and how to shrink it without giving up the discount.

July 10, 20268 min read
Web Security

Web Skimming: How Magecart Attacks Steal Card Numbers From Real Checkout Pages

The British Airways checkout page was genuine, the certificate valid, and every card typed into it was copied to an attacker. Why the padlock cannot see a skimmer, and what actually stops one.

July 10, 20267 min read
Phishing

Browser-in-the-Browser Attacks: The Login Popup That Is Part of the Page

A fake OAuth popup drawn in HTML, URL bar included, defeats the one check users were taught to run. The drag test that exposes it, and the two defenses that work without your vigilance.

July 10, 20267 min read
Network Privacy

TLS Session Resumption: The Cookie Built Into the Handshake

Session tickets speed up reconnection and double as a tracking identifier that survives cookie clearing. The 2018 research that measured it, the partitioning that contained it, and the forward secrecy cost nobody advertises.

July 10, 20267 min read
Surveillance

Police Drones: How Drone-as-First-Responder Programs Normalize Aerial Surveillance

Police drones now answer 911 calls, recording everything along the route. The Chula Vista model, the Baltimore case that set a constitutional limit, and what Remote ID broadcasts about every drone in the sky.

July 10, 20268 min read
Network Security

TLS Interception: How Corporate Proxies Read Your Encrypted Traffic

The padlock says the connection is encrypted. It does not say to whom. On managed devices, a middlebox decrypts and re-encrypts every HTTPS request, and the measured result is weaker security, not stronger.

July 9, 20268 min read
Web Tracking

Session Replay Scripts: The Websites Recording Your Screen

Thousands of sites record your mouse movements, scrolling, and keystrokes, including text you typed and deleted, and ship the recording to analytics vendors. What leaks, and how to block the scripts.

July 9, 20267 min read
Infrastructure Security

Domain Hijacking: Stealing the Name Instead of the Server

Control the domain and you control the website, the email, and the TLS certificates, without touching a single server. How registrar-level attacks work and the locks most owners have never heard of.

July 9, 20267 min read
Consumer Privacy

Dating App Privacy: What You Share Before the First Date

Orientation, religion, HIV status, live location: dating apps hold the most sensitive profile you will ever write, under advertising economics. The documented failures, and how to date online with less exposure.

July 9, 20267 min read
Practical Guide

Your Phone at a Protest: What It Reveals and How to Limit It

Tower dumps, geofence data, IMSI catchers, and a seizable device in your pocket. A practical guide to attending a lawful demonstration without adding yourself to databases that outlive the afternoon.

July 9, 20268 min read
Privacy How-To

How to Check a Rental for Hidden Cameras

Airbnb banned indoor cameras because guests kept finding them. A sweep takes fifteen minutes with tools you already carry: the flashlight lens test, an infrared scan, and knowing what each method misses.

July 8, 20268 min read
Privacy

Who Can Read Your Browser Sync Data? Chrome, Firefox, Safari, and Brave Compared

Turn on sync and your history, bookmarks, and passwords become records on a company's server. Whether anyone can read them there depends on who holds the keys, and the four major browsers answer differently.

July 8, 20268 min read
Emerging Threats

MFA Fatigue Attacks: How Push Notification Spam Defeats Two-Factor Authentication

An attacker with your password triggers approval prompts until you tap yes: to make it stop, or because "IT support" just told you to. It breached Uber and Cisco, and number matching only partly fixes it.

July 8, 20267 min read
Legal & Policy

HIPAA Does Not Cover Your Health App: Where Medical Privacy Law Actually Stops

HIPAA regulates who holds health data, not the data itself. Fitness trackers, period apps, DNA kits, and most health apps sit entirely outside it, and the FTC is patching the gap one case at a time.

July 8, 20267 min read
Web Security

eIDAS Article 45: When Governments Decide What Your Browser Trusts

The EU's digital identity regulation tells browsers which certificate authorities they must accept. Hundreds of security researchers objected. The fight is a compact education in how web trust works.

July 8, 20268 min read
Encryption

The Sesame Algorithm: How Encrypted Chat Stays in Sync Across Your Devices

The Double Ratchet encrypts a conversation between two devices. But you message a person, and a person has a phone, a laptop, a tablet. Sesame is the quiet layer that makes multi-device encrypted messaging actually work.

July 7, 20268 min read
Anonymity

Tor Guard Nodes: Why Tor Trusts a Few Relays More Than the Rest

Tor picks one entry relay and keeps it for weeks instead of choosing fresh every time. That looks like a weakness. It is the opposite, and the reasoning is one of the more elegant risk trades in anonymity design.

July 7, 20267 min read
Security Engineering

Fuzzing: How Throwing Garbage at Code Finds the Bugs Reviews Miss

Attackers never send the input you expected. Fuzzing finds the dangerous ones first, by having a machine generate millions of malformed inputs and watching for the moment something breaks.

July 7, 20268 min read
Supply Chain

SLSA Explained: The Levels That Prove Where Your Software Came From

SolarWinds proved that signed, trusted software can still be poisoned at the build step. SLSA is the framework that grades how much you can trust an artifact's origin. Here is what its levels mean.

July 7, 20268 min read
Wireless Security

Enhanced Open and OWE: Encryption for Password-Free Wi-Fi

Open Wi-Fi with no password sends your traffic in the clear to anyone nearby. Opportunistic Wireless Encryption changes that without adding a password. Here is how OWE works and what it does not fix.

July 7, 20267 min read
Surveillance

The Yellow Dots Your Printer Hides on Every Page

Most color laser printers stamp every page with a near-invisible grid encoding the machine's serial number and a timestamp. Researchers decoded it in 2005, and one famous leak case showed how faithfully scans preserve it.

July 6, 20267 min read
Emerging Threats

Prompt Injection: The Attack AI Assistants Still Cannot Stop

A language model cannot reliably tell content from commands, so any text an assistant reads is a potential command channel. Why filters cannot fix it, and what safe assistant design looks like.

July 6, 20268 min read
Browser Privacy

Manifest V3 and What Your Ad Blocker Is No Longer Allowed to Do

Chrome retired the API that powerful content blockers were built on. What the declarative replacement allows, what uBlock Origin lost, and where blocking still works at full strength.

July 6, 20267 min read
Protocols Explained

What Is Actually on Your Passport Chip, and Who Can Read It

The contactless chip in a biometric passport carries signed identity data behind protocols that were broken and repaired: BAC, PACE, and the authentication alphabet. Skimming is a smaller threat than the sleeve marketing suggests.

July 6, 20268 min read
Security Hygiene

Credit Freezes: The Strongest Identity Theft Defense Most People Skip

Freezing your credit blocks the most damaging form of identity theft, costs nothing, and takes about half an hour. How freezes differ from locks and fraud alerts, and which doors stay open.

July 6, 20267 min read
Emerging Threats

Wi-Fi Sensing: Your Router Is Becoming a Motion Detector

Your router can detect movement through walls by reading how bodies distort the radio signal. No camera, no wearable, no consent mechanism, and encryption cannot help.

July 5, 20267 min read
Mobile Privacy

Third-Party Keyboard Apps: The Middleman Reading Everything You Type

A keyboard sees every message, search, and password before encryption exists. The category's track record includes a 31-million-user leak and keyboards that phoned home.

July 5, 20267 min read
Legal & Policy

Reproductive Health Apps and the Data Trail They Leave

Cycle trackers hold some of the most sensitive data you generate, and most of it sits outside HIPAA. The enforcement record shows where the real risk lives.

July 5, 20267 min read
Tools Compared

Encrypted Note Apps Compared: Who Can Read Your Notes?

Most note apps encrypt in transit and at rest, and the provider can still read every word. A comparison of the apps that actually lock the provider out.

July 5, 20268 min read
Surveillance

Your Smart Meter Knows When You Sleep

Fifteen-minute electricity readings reveal occupancy, sleep schedules, and which appliances you run. Courts recognized how intimate the data is, then allowed collection anyway.

July 5, 20267 min read
Emerging Threats

What Happens When You Let an AI Agent Read Your Inbox

Agentic browsers now read your email, click links, and take actions on your behalf. That turns every message you receive into a potential instruction to your own assistant.

July 4, 20268 min read
Emerging Threats

What Your Doorbell Camera Tells the Police

Ring, Flock Safety, and Fusus built a pipeline that moves footage from your porch to a police database, often without a warrant. Here's how it actually works.

July 4, 20269 min read
Policy & Law

Britain's Online Safety Act and the Fight Over Client-Side Scanning

The UK's Online Safety Act gives Ofcom power to demand message scanning that no encrypted app can comply with while staying encrypted. Here's the actual mechanism.

July 4, 20268 min read
Emerging Threats

Smart Glasses and the Bystander Who Never Consented

Camera glasses put recording capability on someone's face instead of in their hand. The privacy problem that creates belongs to the person standing next to them, not the wearer.

July 4, 20267 min read
Security Hygiene

The Privacy Tradeoffs Hiding in Family Locator Apps

Life360, Find My, and Family Link solve a real problem for parents. They also create a location database that has been sold to data brokers and misused for control, not safety.

July 4, 20268 min read
Emerging Threats

What Smart Speakers Actually Send Home

Wake-word detection, human review programs, and what a "mute" button really does. A clear look at what voice assistants collect and how to reduce it.

July 3, 20269 min read
Security Hygiene

A Practical Doxxing Protection Checklist

Where doxxers actually get their information, and the specific steps that close each source. A working checklist, not a general warning to "be careful online."

July 3, 202610 min read
Legal & Policy

Data Localization Laws: What "Your Data Must Stay Here" Actually Means

Russia, China, India, and the EU each require data to stay within borders for different reasons and with different enforcement. A clear breakdown of what data localization actually requires.

July 3, 20269 min read
Encryption & Protocols

IPv6 Privacy Extensions: Why Your Address Used To Be a Tracking Number

Early IPv6 addresses baked your network card's hardware ID into every connection you made. RFC 4941 fixed it. Here's how the fix works and where it still falls short.

July 3, 20268 min read
Architecture & Privacy

Local-First Software: The Architecture Choice That's Also a Privacy Choice

Local-first software keeps your data on your device by default and treats the server as a sync relay, not the source of truth. What that means for privacy, and where the trade-offs actually are.

July 3, 20269 min read
Emerging Threats

Keystroke Dynamics: How Your Typing Rhythm Became a Fingerprint

Clear your cookies, spoof your device fingerprint, switch browsers. The timing between your keystrokes stays the same. How typing biometrics work, who's actually deploying them, and where the technique breaks down.

July 2, 20268 min read
Security Hygiene

What School-Issued Laptops Are Actually Watching

District Chromebooks run monitoring software most parents have never seen a log from. What these tools actually capture, why the legal framework is thinner than it looks, and what documented false positives have already cost students.

July 2, 20269 min read
Encryption Protocols

Cloud KMS and Bring-Your-Own-Key: What You're Actually Trusting

Every major cloud platform sells a key management service, and most sell a bring-your-own-key option on top. What BYOK actually changes about who can read your data, and what it doesn't.

July 2, 20269 min read
Policy & Law

COPPA in 2026: What US Children's Privacy Law Actually Covers

COPPA regulates data collection from kids under 13, and almost nothing else. What the law actually requires, what the 2025 FTC update changed, and where the coverage gap actually sits.

July 2, 20268 min read
Policy & Law

Your Boarding Pass Data Trail: How PNR Records Actually Work

Every flight generates a Passenger Name Record with more fields than most travelers would guess, shared with governments before boarding and retained for years. What's actually in the file, and who gets to see it.

July 2, 20268 min read
Surveillance & Policy

Facial Recognition Surveillance: How It Works and Who's Using It

Clearview AI built a facial database by scraping billions of public photos, no court order, no consent, then sold search access to police departments. How facial recognition surveillance actually works, and the regulatory patchwork trying to catch up.

July 1, 20268 min read
AI & Privacy

What Happens to Your Conversations With AI Chatbots

Chat logs get retained by default, reviewed by human contractors, and in one major case, preserved indefinitely by a federal court order despite users' own deletion settings. What actually happens to what you type.

July 1, 20268 min read
Health Data Privacy

What Your Fitness Tracker Actually Knows About You

In 2018, a Strava heatmap built from users' own GPS data revealed the running routes on classified military bases. What your wearable actually tracks, and why most of it isn't protected the way you'd assume.

July 1, 20267 min read
Physical Security

RFID Skimming: How Real Is the Threat to Your Contactless Cards

Faraday wallets are a booming product category built to stop an attack that's harder to pull off than the marketing suggests. What contactless card and passport skimming can and can't actually do.

July 1, 20267 min read
Workplace Privacy

Bossware: What Employee Monitoring Software Actually Sees

Screenshots every few minutes, keystroke logging, algorithmic productivity scores. What workplace monitoring software actually captures, and where the legal line between your device and your employer's actually sits.

July 1, 20268 min read
Tracking

Link Decoration: The Tracking IDs Hidden in Your URLs

Copy almost any link and look past the question mark. That trailing payload of campaign tags and click identifiers is how a tracker carries identity across a click the browser was supposed to keep separate. How link decoration and bounce tracking work, and what now strips them.

June 30, 20267 min read
Tracking

CNAME Cloaking: How Trackers Disguise Themselves as First-Party

A single DNS record lets a third-party tracker pose as a subdomain of the site you are visiting, inheriting first-party trust: your cookies flow to it and blocklists miss it. How the trick works and what actually unmasks it.

June 30, 20267 min read
Hardware Security

Memory Tagging (MTE): Hardware That Catches Memory Bugs

Roughly 70 percent of serious vulnerabilities are memory-safety bugs in C and C++. ARM Memory Tagging gives every chunk of memory a colored label and checks it in hardware on every access, cheaply enough to leave on in production. How lock-and-key tagging catches use-after-free and overflows.

June 30, 20268 min read
Censorship

Refraction Networking: Censorship Circumvention Inside the Network

Every proxy has an address a censor can eventually find and block. Refraction networking removes the endpoint entirely, placing circumvention at a participating internet provider on the path to ordinary sites. How decoy routing works, and why the censor is stuck.

June 30, 20268 min read
Policy

Schrems II: Why Your Data's Legal Path Across Borders Matters

A 2020 EU court ruling struck down the framework companies used to move personal data from Europe to the US, and named strong encryption as one of the few safeguards that actually works. A ruling, at bottom, about who holds the keys.

June 30, 20268 min read
Policy

Key Disclosure Laws: When the State Can Compel Your Password

Strong encryption cannot answer one question: what happens when someone with legal authority orders you to unlock it? How the UK, France, Australia, and the US differ, and why the answer changes every time you cross a border.

June 28, 20268 min read
Protocols

The Tox Protocol: Serverless Encrypted Messaging, and Its Trade-offs

Tox has no server, no account, and no phone number. Your identity is a public key and messages travel directly between devices. How its DHT, NaCl crypto, and onion routing work, and the real costs the design carries.

June 28, 20268 min read
Cryptography

Oblivious Pseudorandom Functions: The Quiet Workhorse of Modern Privacy

A keyed function neither party can compute alone: the client supplies the input but never sees the key, the server holds the key but never sees the input. The primitive behind Privacy Pass, OPAQUE login, and private breach checks.

June 28, 20269 min read
Cryptography

Verifiable Delay Functions: Proving That Time Passed

A function slow to compute by design, impossible to speed up with more cores, yet verifiable in an instant. That odd pairing is the missing ingredient for public randomness nobody can rig. How repeated squaring makes it work.

June 28, 20268 min read
Privacy

What Private Browsing Mode Actually Does (and the Myths It Carries)

Incognito hides your activity from the next person on your device. It does not hide it from websites, your network, or your ISP. A precise account of where the line sits, and the lawsuit that proved how widely it is misread.

June 28, 20267 min read
Threats

Mercenary Spyware: How Pegasus-Class Tools Actually Work

Commercial spyware is sold to governments to break into a phone with zero clicks and read everything on it. How the exploit chains work, what the implants steal, why it defeats encryption, and what realistically reduces exposure.

June 27, 20269 min read
Threats

Adversary-in-the-Middle Phishing: How MFA Gets Bypassed

Reverse-proxy phishing kits sit between you and the real login page, relaying every step including your one-time code, then steal the session cookie. Why most MFA does not stop it, and the one defense that does.

June 27, 20268 min read
Threats

The Zero-Day Exploit Market: Who Buys Bugs and Why

An unpatched vulnerability can be worth more than a house. How the market for zero-day exploits works, who the buyers and brokers are, and why bug bounties cannot outbid governments.

June 27, 20268 min read
Protocols

5G Subscriber Privacy: How SUCI Concealment Fights IMSI-Catchers

For decades cell networks broadcast your permanent subscriber ID in the clear, which is how IMSI-catchers worked. 5G encrypts it. How SUPI, SUCI, and the concealment scheme change the picture, and what they still leave exposed.

June 27, 20269 min read
Privacy

Fediverse Privacy: What ActivityPub Does and Does Not Protect

Mastodon and the wider fediverse trade one company's control for many small operators. That reshapes the privacy model rather than fixing it. What your instance admin sees, why there are no private posts, and where the metadata goes.

June 27, 20268 min read
Protocols

MASQUE: The Proxying Protocol Behind Modern Relay Privacy

MASQUE tunnels UDP and full IP packets inside HTTP/3, and it is what makes two-hop relay networks like iCloud Private Relay work. How CONNECT-UDP and CONNECT-IP function, and why the privacy depends on who runs the hops.

June 26, 20269 min read
Encryption

Secure Value Recovery: How a PIN Can Unlock an Encrypted Backup

If only you can decrypt a backup, forgetting your key loses everything. Signal's SVR lets a short PIN recover a strong secret using hardware enclaves and a guess limit the operator provably cannot raise.

June 26, 20269 min read
Cryptography

BBS Signatures and Anonymous Credentials: Proving Less to Show More

BBS lets you reveal one field of a digital ID and prove the rest exists without showing it, with presentations that two verifiers cannot link together. How unlinkable selective disclosure beats salted-hash schemes.

June 26, 20269 min read
Identity

Zooko's Triangle: Why Secure Names Are Hard to Make Human

Names want to be human-readable, secure, and decentralized at once, and you can usually pick two. The trilemma, and how onion addresses, Namecoin, key transparency, and petnames each resolve it.

June 26, 20268 min read
Cryptography

Trusted Timestamping: Proving a File Existed Before a Certain Moment

A trusted timestamp proves data existed at a point in time without revealing the data itself. How RFC 3161 authorities, hash linking, and Merkle-tree schemes work, and where each one places its trust.

June 26, 20268 min read
Privacy

Your Smart TV Is Watching You Back: How ACR Tracking Works

Automatic Content Recognition fingerprints what is on your screen, including content from your console and cable box, and ships it to advertisers. How it works, what Vizio paid to settle, and where the off switch is hidden on every major brand.

June 25, 20268 min read
Cryptography

SHA-3 and the Sponge: Why Keccak Looks Nothing Like SHA-2

SHA-3 is not a stronger SHA-2, it is a different construction. A look at the sponge, the Keccak permutation, and why it shrugs off the length-extension attacks that force SHA-2 to lean on HMAC.

June 25, 20269 min read
Encryption

SFrame: End-to-End Encryption for Group Video Calls (RFC 9605)

Add a third person to an encrypted call and the routing server usually gets to decrypt every frame. SFrame encrypts the media frame itself, so the conferencing server forwards ciphertext it cannot read.

June 25, 20269 min read
Email

Sender Rewriting Scheme (SRS): Why Email Forwarding Breaks SPF

Set up a simple forwarding alias and legitimate mail starts landing in spam. The cause is a clash between SPF and forwarding, and SRS is the workaround quietly running on nearly every forwarder you use.

June 25, 20268 min read
Cryptography

Oblivious RAM: Hiding Which Data You Touch, Not Just What It Says

Encryption hides the contents of your data, not which records you read and write. The access pattern alone can rebuild what you were looking for. Oblivious RAM closes that gap, at a cost that cannot be engineered away.

June 25, 20269 min read
Cryptography

The Cryptographic Doom Principle: Why Order Matters in Encrypt-and-MAC

If you decrypt a message before you check whether it is authentic, you have handed the attacker a tool. One sentence explains a decade of TLS vulnerabilities, the reason padding oracles exist, and why modern protocols stopped letting engineers choose the order.

June 24, 20268 min read
Digital Identity

SD-JWT: Proving One Fact From a Credential Without Revealing the Rest

Showing a digital ID to prove you are over 21 should not hand over your name, address, and exact birthdate. SD-JWT is how selective disclosure works, and where its privacy honestly ends.

June 24, 20268 min read
SSH & Access

SSH Certificate Authorities: Past the authorized_keys Sprawl

Managing SSH access with authorized_keys files does not scale and leaves you with no real revocation. SSH certificates fix both, plus the host-key trust-on-first-use prompt nobody reads.

June 24, 20268 min read
Web Security

Username Enumeration: How Login Forms Quietly Confirm Who Has an Account

A login page that says "no such user" is leaking. Username enumeration turns small differences in error messages and timing into a confirmed list of valid accounts, and it is the setup for the attack that follows.

June 24, 20267 min read
Security Hygiene

Why NIST Told Organizations to Stop Forcing Password Changes

The 90-day password change felt like basic hygiene. The agency that wrote the rulebook now recommends against it, because forced rotation measurably pushed users toward weaker, more guessable passwords.

June 24, 20267 min read
Encryption

Sender Keys: How Encrypted Group Chats Avoid Sending Every Message N Times

Two-person encrypted chat is solved. Group chat is where the math gets awkward. Sender Keys is the trick most large secure messengers reached for to make groups scale, and it trades a real piece of security to get there.

June 23, 20268 min read
Cryptography

Private Set Intersection: Finding What Two Parties Share Without Revealing the Rest

An app offers to find which of your contacts already use it. The lazy version uploads your whole address book. PSI is the cryptographic version: both sides learn exactly the overlap and nothing else.

June 23, 20268 min read
DNS & Privacy

QNAME Minimization: Why DNS Resolvers Stopped Telling Every Server Everything

For most of DNS history, looking up one hostname told every server in the chain the full name you wanted, even though almost none of them needed it. QNAME minimization closed a leak built into the protocol since 1987.

June 23, 20267 min read
Protocols

Roughtime: Getting the Time From Servers You Don't Have to Trust

A surprising amount of security depends on your device knowing roughly what time it is. Roughtime gets accurate time from servers that keep each other honest, and can prove it when one of them lies.

June 23, 20267 min read
Encryption

The OpenPGP Crypto Refresh: What RFC 9580 Actually Changed

OpenPGP spent two decades carrying 1990s defaults. RFC 9580 finally modernized it with AEAD, v6 keys, and SHA-256 fingerprints, and it also split the ecosystem. What changed and why it was contentious.

June 23, 20268 min read
Surveillance

TEMPEST and Van Eck Phreaking: Reading a Screen From the Radio It Leaks

In 1985 a researcher reconstructed the text on a computer monitor from a van parked outside, using the faint radio energy the screen was broadcasting. Flat panels did not kill the technique. How emanation surveillance works, and the narrow set of people it actually threatens.

June 22, 20269 min read
Cryptography

Post-Compromise Security: How Encryption Heals After a Key Is Stolen

Forward secrecy protects your past messages if a key leaks. Its mirror image, post-compromise security, asks the harder question: if an attacker steals your key today, can the conversation ever become secret again? How a ratchet heals on its own.

June 22, 20268 min read
Cryptography

HMAC Explained: Why a Hash Alone Cannot Prove Who Sent a Message

A SHA-256 sum tells you a file was not corrupted. It says nothing about who produced it. HMAC adds a shared key, and the specific way it nests two hashes is a direct response to an attack that breaks the obvious design.

June 22, 20268 min read
Cryptography

Verifiable Random Functions: Randomness You Can Check But Not Predict

How do you trust a random draw made in private by a party who could profit from rigging it? A VRF produces an output that is unpredictable to everyone else plus a proof it was computed honestly. The quiet machinery behind key transparency and private DNSSEC.

June 22, 20269 min read
Security Hygiene

OpenPGP Smartcards: Keeping a Private Key Off the Computer Entirely

A PGP key in a file is only as safe as the laptop holding it. An OpenPGP smartcard generates the key on a chip that will not export it and does every operation inside the card. Steal the laptop and you still do not have the key.

June 22, 20268 min read
Surveillance

Ultrasonic Beacon Tracking: The Sounds You Can't Hear That Follow You

Inaudible tones pitched above human hearing can link your phone to your TV, your location, and other devices, using nothing but the microphone in your pocket. It sounds like fiction. It has shipped in real advertising software for years, and a VPN does nothing to stop it.

June 21, 20268 min read
Protocols

Oblivious HTTP Explained: Separating Who You Are From What You Ask

Most privacy tools encrypt a request's contents. OHTTP (RFC 9458) attacks a different problem: making sure the server that learns your IP address is never the same one that reads your request. How the relay-and-gateway split works.

June 21, 20269 min read
Infrastructure

Data Diodes: Hardware That Only Lets Data Flow One Way

A firewall decides what to allow based on rules, and rules can be misconfigured. A data diode makes a different promise: data can physically travel in only one direction, because the return path does not exist as hardware. One of the few controls an attacker cannot reconfigure remotely.

June 21, 20268 min read
Threats

Clipboard Hijacking: When Copy-Paste Becomes an Attack Surface

You copy something, you paste it, and you assume the two are identical. A whole category of malware lives in that gap, silently swapping the address you copied for the attacker's. Clipper malware, pastejacking, and apps reading your clipboard in the background.

June 21, 20268 min read
Cryptography

Cryptographic Commitments: Sealing a Value Before You Reveal It

How do you prove you predicted something correctly without revealing your prediction in advance? A commitment scheme lets you lock in a value now, keep it secret, and prove later you never changed it. Hiding versus binding, hash versus Pedersen.

June 21, 20269 min read
Censorship

Domain Fronting: How It Hid Censored Traffic, and Why It Mostly Died

For a few years, blocked apps could make their traffic look like an ordinary connection to Google or Amazon, and a censor would have had to block half the internet to stop it. Then the cloud providers turned it off. The SNI-versus-Host trick, why it worked, and what replaced it.

June 20, 20269 min read
Authentication

SCRAM: How to Prove a Password Without Sending It

When you log in to PostgreSQL, MongoDB, or an XMPP server, your password usually never crosses the wire. Instead the two sides run a short challenge-response dance, and each proves something to the other without revealing what it knows. How the handshake works, and where it stops protecting you.

June 20, 20269 min read
Key Management

Envelope Encryption: Why You Don't Encrypt Data With Your Master Key

Almost every system that encrypts data at scale uses the same trick: encrypt the data with a fresh key, then encrypt that key with another key. It sounds like pointless indirection until you try to rotate a key or encrypt a petabyte. What the pattern buys you, and where it stops protecting you.

June 20, 20268 min read
Encryption

How Web Push Notifications Stay Encrypted End to End

When a website pushes a notification to your browser, it passes through a relay run by your browser vendor that should never read it. RFC 8291 makes the relay a blind courier. The mechanism, and the metadata it still cannot hide.

June 20, 20268 min read
Encryption

Format-Preserving Encryption: When Ciphertext Has to Look Like a Credit Card

Standard encryption turns a 16-digit card number into a block of random bytes that no longer fits its database column. Format-preserving encryption keeps the shape: 16 digits in, 16 different digits out. A narrow tool built for a specific legacy problem, and why it exists.

June 20, 20268 min read
Cryptography

PASETO vs JWT: A Token Format That Removes the Footguns

Most of JWT's famous vulnerabilities trace to one design choice: the token tells the verifier which algorithm to use. PASETO refuses to negotiate — one safe suite per version, no "alg: none", no algorithm confusion. How it works and when to reach for it.

June 19, 20268 min read
Web Security

SameSite Cookies: The Quiet Default That Killed a Lot of CSRF

Around 2020 browsers flipped a cookie default almost nobody noticed, and a whole class of cross-site request forgery quietly stopped working. What SameSite, Secure, HttpOnly, and the __Host- prefix each do — and exactly where the protection stops.

June 19, 20267 min read
Privacy Tools

OnionShare: Sending Files With No Server in the Middle

Instead of uploading your file to a company's cloud, OnionShare turns your own laptop into a temporary, anonymous Tor onion service the recipient downloads from directly. How the no-middle-server model works, and what it does and doesn't protect.

June 19, 20267 min read
Messaging

Delta Chat: A Messenger That Rides on Email

It looks like an ordinary chat app, but every message is an encrypted email — no phone number, no central server, no new account. Why building on email buys real decentralization, and the metadata trade-off you can't escape when you do.

June 19, 20268 min read
Web Privacy

The Referer Header: How Your URLs Leak to Everyone You Link To

Every click can tell the destination exactly which page you came from — query strings, tokens, and all. How the Referrer-Policy header controls the leak, why secrets never belong in a URL, and the controls beyond the page default.

June 19, 20267 min read
Authentication

WebAuthn Attestation: How a Site Knows What Made Your Passkey

When you create a passkey, your authenticator can hand the website a signed statement proving which hardware made it. That's attestation — invaluable for high-assurance enterprises, and one of the easiest ways to quietly deanonymize a consumer. How it works and when not to use it.

June 18, 20269 min read
Data Protection

Tokenization vs Encryption: Two Different Ways to Hide Sensitive Data

The terms get used interchangeably and describe fundamentally different mechanisms — one reversible math with a key, one a meaningless substitute backed by a vault. Why payment systems lean on tokens, and where your real risk lives.

June 18, 20268 min read
Cryptography

Threshold Signatures and FROST: One Signature, No Single Signer

A threshold scheme lets any t-of-n participants jointly produce one ordinary-looking signature, with the full private key never assembled anywhere — not even for a moment. How FROST made it fast enough to deploy, and why it beats both multisig and secret sharing.

June 18, 20269 min read
Authentication

The Security Model of Magic Links: Passwordless, But Not Free of Trade-offs

A magic link doesn't eliminate the secret — it relocates it into your inbox and makes that the master key to everything. What the model genuinely fixes, the threats it doesn't, and how to build one that doesn't bite you.

June 18, 20268 min read
Privacy

State Partitioning: How Browsers Quietly Broke Cross-Site Tracking

The death of the third-party cookie got the press, but the deeper fix was state partitioning — keying every cache, storage bucket, and network connection to the top-level site. The change that actually closed the side doors, and the gaps that remain.

June 18, 20268 min read
Cryptography

Blind Signatures: Getting Something Signed Without Revealing It

An authority can stamp a document it never reads. That paradox — verifiable but unlinkable — is the cryptographic foundation for anonymous tokens, untraceable digital cash, and credentials that prove you are authorized without revealing who you are.

June 17, 20269 min read
Web Security

Cross-Site Scripting (XSS): How Injected JavaScript Steals Your Session

Once attacker-controlled script runs in your origin, the same-origin policy and the TLS padlock offer no protection — the injected code is the trusted site. Reflected, stored, and DOM-based XSS, and the layered defenses that actually stop them.

June 17, 20268 min read
Web Security

SQL Injection: The Vulnerability That Still Breaches Databases

First described in 1998 and still behind major breaches today. How a single quote turns a login query into a master key, the blind and time-based variants tools automate, and why parameterized queries — not escaping — are the real fix.

June 17, 20268 min read
Web Security

Server-Side Request Forgery (SSRF): When Your Server Becomes the Attacker

SSRF tricks your server into making requests on an attacker's behalf — reaching internal admin panels and cloud metadata endpoints firewalls were built to hide. The bug behind the Capital One breach, and the layered defenses that hold up.

June 17, 20268 min read
Authentication

Kerberos: How Tickets Replace Passwords on the Network

The protocol behind enterprise single sign-on proves who you are without ever sending your password. A walk through the KDC, ticket-granting tickets, and service tickets — and the Golden Ticket and Kerberoasting attacks that exploit them.

June 17, 20269 min read
Cryptography

Lattice-Based Cryptography: The Math Behind Post-Quantum Security

The encryption standards meant to outlast quantum computers rest on a deceptively simple idea: finding the nearest point in a high-dimensional grid is brutally hard. A walk through lattices, Learning With Errors, and the new NIST standards — without the heavy machinery.

June 16, 20269 min read
Email Security

DKIM Replay: How Spammers Borrow Your Good Reputation

A valid DKIM signature proves origin and integrity — but says nothing about intended audience or send count. Attackers capture one genuinely-signed message and replay it to thousands, riding a reputable domain's reputation straight past the spam filter.

June 16, 20268 min read
Network Security

DNS Tunneling: Smuggling Data Through the Internet's Phone Book

DNS is the one protocol almost no firewall dares to block — so attackers stuff stolen data into the subdomain labels of ordinary-looking lookups. A slow, resilient covert channel for exfiltration and command-and-control, and how it gets caught.

June 16, 20268 min read
Authentication

Password Spraying: The Quiet Cousin of Credential Stuffing

Brute force hammers one account with many passwords. Spraying inverts it — one common password against thousands of accounts — generating a single failure per account that sails straight past every lockout policy ever written.

June 16, 20267 min read
Security Hygiene

Ransomware Defense: A Practical Guide to Not Paying

Modern ransomware steals a copy of your data before it encrypts the original, so even a flawless restore leaves them holding a threat to leak everything. A layered, realistic defense that assumes backups alone won't save you.

June 16, 20268 min read
TLS Security

CRIME and BREACH: How Compression Leaks Encrypted Secrets

Encryption hides what your data says, not how long it is. CRIME and BREACH turn that one unhidden fact into a key — recovering session cookies and CSRF tokens one byte at a time by watching the compressed size of encrypted traffic wobble. The cipher stays perfect; the length is the leak.

June 15, 20268 min read
Anonymity Networks

I2P Explained: The Anonymity Network That Isn't Trying to Be Tor

The Invisible Internet Project made a different bet than Tor: a fully distributed network where every user is also a relay, built for services that live inside it. Garlic routing, unidirectional tunnels, and a distributed netDb instead of directory authorities — a short course in the design space of anonymity itself.

June 15, 20268 min read
Cryptography

Hash-Based Signatures: The Most Conservative Path to Post-Quantum

Nearly every signature in use today rests on a number-theory problem a quantum computer would break. Hash-based signatures need only a secure hash function. How Lamport, Merkle trees, XMSS, and SPHINCS+/SLH-DSA build a full signature scheme from the smallest possible assumption.

June 15, 20269 min read
Email Encryption

Autocrypt: Making PGP Email Encryption Happen by Itself

PGP email failed not because the math was weak but because nobody could use it. Autocrypt smuggles key exchange into headers people never see and encrypts opportunistically — trading strong verification for automatic, frictionless protection. How it works, and what it deliberately gives up.

June 15, 20268 min read
Cryptography

Proxy Re-Encryption: Sharing Encrypted Data Without Handing Over the Keys

How do you let a server forward your encrypted data to someone else without ever giving it the power to read it? A re-encryption key transforms ciphertext from one recipient to another while the proxy learns nothing — relocating trust from "can read my data" to "can transform but never read it."

June 15, 20268 min read
Security Hygiene

Account Recovery Is the Weakest Link: How to Get It Right

The strongest password and best 2FA are only as strong as the "forgot password" flow behind them. A clear-eyed guide to recovery methods — from security questions to seed phrases — ranked by how attackers actually beat them.

June 13, 20268 min read
Security Architecture

Zero Trust Architecture: "Never Trust, Always Verify" Explained

For decades, network security worked like a castle: hard perimeter, free movement once inside. Zero Trust throws that out — location grants nothing, every request gets verified. What NIST SP 800-207 actually requires, and what it can't fix.

June 13, 20268 min read
Distributed Systems

Sybil Attacks: When One Adversary Wears a Thousand Faces

Most online systems quietly assume one account equals one person. Sybil attacks break that at the root: a single adversary forges thousands of identities to outvote, out-route, or out-rate everyone. One of the deepest unsolved problems in open systems.

June 13, 20268 min read
Web Privacy

The Privacy Cost of CAPTCHA — and the Cryptography Replacing It

Clicking traffic lights to "prove you're human" is also a data-collection event. The quietest, most invisible CAPTCHAs do the most watching. How reCAPTCHA, hCaptcha, and Turnstile differ — and how Privacy Pass aims to kill the puzzle.

June 13, 20267 min read
Privacy & Machine Learning

Federated Learning: Training AI Without Collecting Your Data — Mostly

"The data never leaves your device" is appealing — and federated learning really does change where your data goes. But "the data stays put" and "nothing about you is revealed" are not the same statement. What it protects, what leaks, and what closes the gap.

June 13, 20268 min read
Surveillance

Salt Typhoon: When the Wiretap System Became the Target

Chinese state hackers spent months inside the systems US telecoms built for court-ordered wiretaps — and the FBI responded by telling Americans to use end-to-end encryption. Thirty years of backdoor hypotheticals just became an empirical result.

June 12, 20268 min read
Email Authentication

BIMI Explained: The Logo in Your Inbox Is Really a DMARC Enforcement Program

The verified brand logos in Gmail and Apple Mail look cosmetic. They're a deliberately engineered incentive: the logo is the carrot, strict DMARC is the price. How the DNS record, the locked-down SVG profile, and VMC certificates fit together.

June 12, 20267 min read
Physical Surveillance

Automated License Plate Readers: The Dragnet You Drive Past Every Day

Cameras on poles and cruisers photograph every passing plate and file it — place, time, photo — into databases searchable for years. How ALPR networks became one of the densest location-tracking systems in existence, and why retention policy is the whole game.

June 12, 20268 min read
Law & Policy

The CLOUD Act: Why "Our Servers Are Overseas" Doesn't Protect You

Since 2018, US legal process reaches any data a US-jurisdiction provider can touch, on any continent — and executive agreements let foreign governments demand data directly. Server location is a detail; key location is the decision.

June 12, 20267 min read
Data Privacy

Genetic Privacy After 23andMe: Your DNA Is a Shared Document

A breach amplified through relative-matching, a bankruptcy auction for fifteen million genomes, and a killer caught through his cousins' uploads. Why genetic data breaks the consent model every other privacy decision rests on.

June 12, 20268 min read
Web PKI

The 47-Day Certificate: Why TLS Lifetimes Are Collapsing

TLS certificates that once lasted five years will soon expire in 47 days. The schedule is set: 200 days now, 100 in 2027, 47 by 2029. It's not bureaucratic churn — it's the Web PKI quietly admitting that revocation, its designed-in remedy for key compromise, never actually worked.

June 11, 20268 min read
Attack Surface

Invisible Characters: How Unicode Breaks Security Assumptions

A character can be invisible, can reverse the text around it, or can look identical to a different code point. Trojan Source, homoglyph attacks, normalization collisions, and zero-width injection all share one root cause: the gap between how text is displayed and how it's interpreted.

June 11, 20269 min read
Authentication

Passkeys You Can Actually Move: The Credential Exchange Protocol

Passkeys made phishing structurally impossible — then trapped your credentials in one vendor's keychain by design. The FIDO Alliance's Credential Exchange Protocol aims to fix portability without reopening the phishing hole. How it works, and what's still missing.

June 11, 20268 min read
Privacy & Identity

Digital ID Wallets: The Privacy Stakes of Showing Your License

Mobile driver's licenses and EU identity wallets are arriving fast. Whether they become a privacy win or a surveillance machine comes down to two properties most people have never heard of: selective disclosure and unlinkability.

June 11, 20269 min read
Cryptography

Message Franking: Reporting Abuse Without Breaking Encryption

How can an end-to-end encrypted app verify a user's abuse report when the server can't read messages? Message franking is the cryptographic answer — verifiable reporting that doesn't hand the platform a master key — and it has real limits worth understanding.

June 11, 20269 min read
Hardware Security

BadUSB: When the Firmware Is the Attack

BadUSB attacks reprogram a USB device's firmware to impersonate a keyboard. Here's how it works and what defends against it.

June 11, 20267 min read
Protocols

STIR/SHAKEN: Why Your Phone Says "Caller Verified" — and Why Robocalls Still Get Through

How carriers cryptographically sign caller ID with PASSporT tokens and attestation levels — and the gaps that let scam calls keep coming.

June 10, 20269 min read
Supply Chain

SBOMs Explained: The Ingredient List for Software

When the next Log4Shell hits, 'are we affected?' has to be answerable in minutes. A Software Bill of Materials is how.

June 9, 20268 min read
Messaging Reviews

Threema, Honestly Reviewed: No Phone Number, Swiss, Paid

What Threema gets right, what the 2023 academic audit found, and who it's actually for.

June 9, 20268 min read
Cryptography

Searchable Encryption: How You Search Data You Can't Read

A server that can't decrypt your data still needs to find things in it. How searchable encryption works — and what every scheme leaks.

June 9, 20269 min read
Protocols

Nostr Explained: Identity Is a Key, Servers Are Dumb

Your identity is a cryptographic key you own; servers are interchangeable relays. How Nostr works, and where its encryption still falls short.

June 9, 20268 min read
Threats

Infostealers and Stolen Sessions: Why Your Password Wasn't the Point

You did everything right — long password, 2FA, a password manager — and an attacker still logged in as you, without a password or a 2FA prompt. A whole class of commodity malware skips your login entirely and steals the cookie that proves you already logged in. How pass-the-cookie defeats MFA, and what actually stops it.

June 8, 20269 min read
Network Security

TLS Fingerprinting: How JA3 and JA4 Identify You Before You Send a Byte

Encryption hides your connection's contents, but the handshake that sets it up happens in the clear — and its exact shape identifies your software. JA3 and JA4 turn that shape into a fingerprint that can route, throttle, or block you on the spot. How it works, why JA3 broke, and what the redesign fixed.

June 8, 20269 min read
Email Security

SMTP Smuggling: How a Disagreement Over One Line Let Attackers Forge Email

SPF, DKIM, and DMARC are supposed to make sender spoofing impossible. In late 2023 a researcher slipped past all three at once — not by breaking any of them, but by exploiting a quiet disagreement between mail servers about where one message ends and the next begins.

June 8, 20269 min read
Cryptography

Hardware Security Modules: Where the Keys That Protect Everything Actually Live

The keys behind TLS certificates, payment networks, and code signing don't sit in a file. They live inside tamper-resistant hardware engineered to erase its own contents rather than reveal them. A practical look at HSMs, FIPS levels, and the same idea shrunk into your phone.

June 8, 20268 min read
Privacy Protocols

Privacy Pass: Proving You're Human Without Being Tracked

Use Tor, a VPN, or a privacy browser and you get punished with endless CAPTCHAs — because the traits that protect you also make you look like a bot. Privacy Pass uses blind signatures to let you prove you earned trust, without the verifier ever learning who you are or linking your visits together.

June 8, 20268 min read
Web Tracking

The Privacy Sandbox and the Topics API: How the Browser Itself Became the Ad Profiler

The third-party cookie had to die — everyone agreed. Google's answer was to move ad profiling out of external trackers and into the one piece of software that sees everything you do online: your own browser. Whether that's a privacy win or a more efficient surveillance machine depends entirely on what you measure.

June 7, 202610 min read
Privacy & Law

Global Privacy Control: The One-Setting Opt-Out That Actually Has Legal Teeth

Most privacy toggles are theater. GPC is the rare exception: a single browser signal that tells every site "do not sell or share my data" — and in California and a growing list of states, a business that ignores it is breaking the law. How it works, and exactly where it stops.

June 7, 20268 min read
Security Hygiene

How Password Breach Checkers Look You Up Without Learning Your Password

"Type your password here and we'll tell you if it leaked" sounds like the worst security advice imaginable. Yet password managers do this check constantly without ever learning your password. The trick is a beautifully simple protocol called a k-anonymity range query.

June 7, 20268 min read
Messenger Review

Cwtch: The Messenger That Tries to Hide the Metadata, Not Just the Message

E2E encryption hides what you say but usually leaks who you talked to, when, and how often — and that pattern is often the more dangerous exposure. Cwtch is built on Tor onion services and untrusted servers to attack the metadata problem directly. An honest look at how, and what it costs.

June 7, 20269 min read
Email Authentication

ARC Explained: How Email Survives Mailing Lists Without Failing DMARC

You set up SPF, DKIM, and strict DMARC. Then a mailing list rewrites your subject and adds a footer, and your own rules bounce mail everyone wanted delivered. The Authenticated Received Chain is the standard built to fix exactly this — in a way that quietly runs on trust.

June 7, 20269 min read
Hardware Security

Evil Maid Attacks: When Full-Disk Encryption Isn't Enough

You encrypt your laptop, power it off, and leave it in a hotel room. The disk is unreadable — so the data is safe, right? Not against an attacker who can touch the powered-off machine, hand it back, and wait for you to type your passphrase into tampered boot code. Why two visits break the whole model, and what measured boot actually buys you.

June 6, 20269 min read
Cryptography

ChaCha20-Poly1305 vs AES-GCM: Two Ways to Encrypt Everything

Every TLS connection picks one of two authenticated ciphers. Both are secure — so why does the internet need both, and why might your phone reach for one while your laptop reaches for the other? A small, instructive lesson in how cryptography meets hardware.

June 6, 202610 min read
Messenger Review

Session Messenger: No Phone Number, Onion Routing, Real Trade-offs

Session throws the phone number away entirely, gives you a random anonymous ID, and routes every message through an onion network. An honest look at what that buys you, what it costs, and who it's actually for.

June 6, 20269 min read
Network Security

RPKI: Putting Cryptographic Locks on Internet Routing

BGP runs the internet on blind trust — any network can claim to own any address block. RPKI adds a cryptographic check on who's allowed to. How Route Origin Validation works, and the path-forgery attacks it still can't stop.

June 6, 202610 min read
Privacy How-To

Pi-hole: Network-Wide Tracker Blocking at the DNS Layer

A browser ad blocker protects one browser. A Pi-hole protects everything on your network — including the smart TV and IoT gadgets you can't install software on. How DNS sinkholing works, what it can't do, and where it fits in a privacy stack.

June 6, 20269 min read
Hardware Security

Spectre and Meltdown: When CPUs Leak Secrets by Guessing

Modern processors run ahead of themselves, executing instructions before they know the results are needed — then quietly discarding the work. The discarded work leaves a fingerprint in the cache, and that fingerprint can be read. How a speed trick became a way to read memory across security boundaries.

June 5, 202610 min read
Network Security

DNS Cache Poisoning: Forging the Internet's Phone Book

Slip a forged answer into a resolver's cache and every user of that resolver is silently sent to the wrong server. The 16-bit guessing game behind the attack, Kaminsky's unlimited-retries insight, and the layered defenses that finally raised the cost.

June 5, 20269 min read
Cryptography

CSPRNGs: Why Secure Randomness Is Harder Than It Looks

Every key, nonce, and token your security depends on starts as a random number. Get the randomness wrong and the strongest cipher collapses. What "secure random" really means — and the production failures that prove how easy it is to get wrong.

June 5, 20269 min read
Hardware Security

Rowhammer: Flipping Bits You Were Never Allowed to Touch

By hammering one region of memory fast enough, an attacker can flip bits in a neighboring region they have no permission to write. How a physics quirk in DRAM became a real privilege-escalation weapon — and a decade-long defense arms race.

June 5, 20269 min read
Policy & Privacy

The Privacy Cost of Online Age Verification

Laws requiring sites to verify your age sound reasonable until you ask: verify it how? Most methods prove who you are and infer age from identity — building honeypots of the most sensitive data imaginable. The privacy math, and the cryptography that could fix it.

June 5, 20269 min read
Web Security

QUIC and HTTP/3: Encryption Baked Into the Transport

TCP predates the idea that the network might be hostile, so it encrypted nothing itself. QUIC rebuilds the transport with encryption woven through — hiding things from the network that have leaked since the 1980s, and opening a few new questions.

June 4, 202610 min read
Authentication

SRP: The Password Protocol That Never Sends Your Password

A server can verify you know your password without the password — or anything that could replay as it — ever crossing the wire. And a stolen database can't be used to log in. Here's how augmented PAKE works.

June 4, 20269 min read
Encryption Protocols

OMEMO: How XMPP Got Modern End-to-End Encryption

OMEMO ended the old choice between OpenPGP and OTR by porting Signal's Double Ratchet onto a federated, multi-device protocol. How it works — and where its limits still bite.

June 4, 20269 min read
Cryptography Engineering

Cryptographic Agility: Designing to Replace Your Own Crypto

Every algorithm eventually breaks — you just don't know when. Agility is the discipline of building systems that can retire a broken primitive without a rewrite. The post-quantum transition is making it urgent.

June 4, 20269 min read
Network Security

WPA3: What Actually Changed in Wi-Fi Security

WPA3 killed the handshake that let anyone in radio range crack your password offline, and added encryption to open networks. How SAE works, what Dragonblood taught us, and what WPA3 still doesn't protect.

June 4, 20269 min read
Anonymity

Tor Onion Services: How .onion Sites Actually Work

A .onion address connects two parties who never learn each other's IP — no DNS, no certificate authority, no exit node. The address is the public key. Here's the rendezvous protocol behind a connection to nowhere-in-particular.

June 3, 202610 min read
Web Security

ACME: How Let's Encrypt Issues Certificates Without a Human

A decade ago, HTTPS meant a form, a fee, and a yearly file-copying chore. Now a server obtains and renews a trusted certificate in seconds with no human involved. The protocol that made the padlock free — and what it deliberately leaves out.

June 3, 20269 min read
Cryptography

Constant-Time Programming: Why Crypto Code Can't Branch on Secrets

The most dangerous bug in cryptographic code isn't a wrong answer — it's a correct answer that arrives a few nanoseconds early. How timing leaks recover keys, and why secure crypto code is written so strangely.

June 3, 20269 min read
Security

CVE and CVSS: How Vulnerability Scoring Actually Works

A "9.8 critical" headline tells you less than you think. How vulnerabilities get their CVE identifiers, how the CVSS number is computed, and why the score is the start of triage — not the verdict.

June 3, 20268 min read
Privacy How-To

Faraday Bags: Physical Privacy When Software Isn't Enough

Airplane mode is a software setting your phone can be made to lie about. A Faraday bag is physics — it blocks the radio waves themselves. When that distinction matters, how the bags work, and where they fail.

June 3, 20268 min read
Threats & Defense

SS7 Attacks: How Your Phone Number Betrays You

Underneath the apps sits a signaling network from the 1970s, built for a closed club of national telecoms who trusted each other completely. That club is gone — but the trust assumption was never removed, and your SMS codes pay the price.

June 2, 20269 min read
Web Security

Content Security Policy: The Header That Defangs XSS

Input sanitization alone has never fully closed cross-site scripting. CSP takes a different bet: assume a script eventually slips through, and make the browser refuse to run it anyway. Nonces, hashes, strict-dynamic, and the one mistake that ruins most policies.

June 2, 20268 min read
Encryption & Email

S/MIME vs PGP: Two Ways to Encrypt Email, Two Trust Models

Both bolt public-key crypto onto a 1980s message format. Where they part ways is the question that actually decides email security: how do you know a public key really belongs to the person you think it does? CA hierarchy versus web of trust — and what neither one fixes.

June 2, 20269 min read
Identity & Privacy

Decentralized Identifiers: Identity Without a Gatekeeper

Nearly every login you use is rented — an account in someone else's database, revocable and observable on their terms. DIDs and verifiable credentials sketch a different arrangement: identity anchored in a key you hold, proof that doesn't phone the issuer home.

June 2, 20269 min read
Threats & Defense

ARP Spoofing: How an Attacker Becomes the Middle of Your Network

On a local network, machines find each other by shouting a question and trusting whoever answers. ARP spoofing is the attack built entirely out of answering dishonestly — why it only works on your segment, and why HTTPS makes the attacker's seat nearly worthless.

June 2, 20268 min read
Cryptography & Protocols

Merkle Trees: One Hash to Vouch for Everything

Prove a single record belongs to a million-item dataset by checking a couple dozen hashes. The deceptively simple structure underneath Git, Bitcoin, and Certificate Transparency — built from first principles, with the logarithmic proof that makes it scale.

June 1, 20269 min read
Web Security

CSRF Explained: How One Forged Request Can Act As You

Cross-Site Request Forgery skips the login entirely and rides the session you already have open. Why cookies make it possible, what an attack actually looks like, and the three defenses — anti-CSRF tokens, SameSite cookies, Origin checks — that close the gap.

June 1, 20268 min read
Web Security

Clickjacking: When the Button You Click Isn't the One You See

A UI redress attack floats an invisible real page over a decoy so your genuine clicks land somewhere you never intended. How the two-layer trick works, the likejacking and cursorjacking variants, and why frame-ancestors shuts it down.

June 1, 20267 min read
Threats & Defense

Juice Jacking: Should You Fear the Public Charging Port?

A USB cable carries data as well as power — the entire premise of juice jacking. The honest version: what the attack can do, why modern phones quietly engineered most of the risk away, and the cheap data blocker that makes it a non-issue.

June 1, 20267 min read
Threats & Defense

Evil Twin Attacks: The Fake Wi-Fi That Looks Exactly Like the Real One

A rogue access point clones a network name your device already trusts, and your device connects on its own. Why the SSID proves nothing, what an evil twin can and can't see in the HTTPS era, and the defenses that actually hold.

June 1, 20268 min read
Cryptography & Protocols

Quantum Key Distribution: Encryption Secured by Physics

QKD secures a key with the laws of physics instead of the hardness of math — and guarantees any eavesdropper leaves fingerprints. How BB84 works, why it isn't the same as post-quantum crypto, and the practical reasons it isn't replacing the internet's cryptography.

May 31, 20269 min read
Cryptography & Protocols

Ring Signatures: Signing as a Group Without Revealing Who

Prove that someone in a group signed a message without revealing which member — no setup, no manager, no permission. The cryptography behind "How to Leak a Secret," how it differs from group signatures, and how it powers Monero.

May 31, 20268 min read
Privacy Tools

Qubes OS: Security Through Compartmentalization

Most operating systems assume they can stay trustworthy. Qubes assumes the opposite and contains the damage. How its security-by-isolation model uses disposable VMs, what it protects against, and who actually needs it.

May 31, 20268 min read
Cryptography & Protocols

Private Information Retrieval: Querying Without Revealing the Query

Encryption protects the data in a database, but the query you send leaks just as much. PIR lets you fetch a record without the server learning which one. The two families of schemes, and where it's quietly shipping in real products.

May 31, 20269 min read
Cryptography & Protocols

Steganography: Hiding Messages in Plain Sight

Encryption hides a message's contents; steganography hides that there's a message at all. How data gets tucked into images and audio, how steganalysis finds it, and why it's a layer on top of encryption — never a replacement.

May 31, 20268 min read
Cryptography & Protocols

Zero-Knowledge Proofs: Proving You Know a Secret Without Revealing It

Prove you're over 18 without showing your birthdate, or that you know a password without sending it. A practical walk through the math — completeness, soundness, the cave analogy — plus zk-SNARKs vs zk-STARKs and where they actually ship.

May 29, 20269 min read
Cryptography & Protocols

Homomorphic Encryption: Computing on Data You Can't Read

Almost every cipher makes you decrypt before you can compute. Homomorphic encryption breaks that rule — add and multiply over numbers a server can't read. How it works, the schemes that matter, and the products quietly shipping it.

May 29, 20268 min read
Emerging Threats

Voice Cloning and Deepfake Fraud: The Scam That Sounds Like Family

AI can clone a voice from seconds of audio and fake a video call well enough to move millions. How synthetic-media fraud works, the cases that made it real, and the low-tech defenses — a family safe word, call-backs — that actually stop it.

May 29, 20267 min read
Legal & Policy

Geofence Warrants: When Police Ask Who Was Near a Crime

A traditional warrant names a suspect. A geofence warrant names a place and a time, then demands every device that was there. How they work, the court split over their constitutionality, and the engineering change that quietly defanged them.

May 29, 20268 min read
Security Hygiene

Diceware: A Password You Can Remember and a Computer Can't Guess

Most strong passwords are unmemorable; most memorable ones are weak. Diceware breaks the trade-off with a pair of dice and a word list — a passphrase you can hold in your head, with strength you can calculate to the bit.

May 29, 20267 min read
Comparison

Haven vs Proton, Tuta & Signal: An Honest Comparison

Proton, Tuta, and Signal are all good tools run by people who care. Here's a fair look at what each does well — and where Haven differs: encrypted email and chat under one identity, no phone number, a free tier that's actually free.

May 28, 202610 min read
Cryptography & Protocols

X3DH: How Signal Agrees on a Secret Key Before You're Online

Classic Diffie-Hellman needs both parties online at once. Messaging doesn't work that way. Here's the handshake that lets you derive a shared secret with someone whose phone is in a drawer.

May 28, 20269 min read
Cryptography & Protocols

The Noise Protocol Framework: The Crypto Behind WireGuard

WireGuard, WhatsApp's transport, and the Lightning Network share a foundation. A practical guide to how Noise builds secure handshakes from a few simple tokens.

May 28, 20269 min read
Cryptography

Nonce Reuse: The Catastrophic Crypto Mistake

Reuse a nonce once and you can hand an attacker your plaintext, your forgery key, or your private signing key. The bug that sank WEP, a game console, and more than one TLS library.

May 28, 20268 min read
Encryption & Email

DANE: Pinning TLS Certificates in DNS

DANE lets a domain owner declare which TLS certificate is legitimate using DNSSEC-signed records — bypassing the CA system entirely. It lost the browser fight but quietly secures email.

May 28, 20268 min read
Messaging & Privacy

SimpleX Chat: Messaging Without User Identifiers

Signal needs your phone number. Most messengers assign a permanent account ID. SimpleX does neither — no user identifiers at all. An honest look at how that works and what it costs.

May 28, 20269 min read
Security Engineering

Memory Safety and the C/C++ CVE Crisis

Microsoft, Google, and the NSA all reached the same conclusion: roughly 70 percent of critical security bugs are memory safety bugs, and the cure is changing languages.

May 27, 202610 min read
Encryption & PKI

Certificate Revocation Is Broken (And What Replaced It)

CRLs were too big. OCSP leaked your browsing history. Soft-fail made revocation advisory. The web finally gave up and shortened certificate lifetimes instead.

May 27, 20269 min read
Network Security

DNS Rebinding: When Your Browser Attacks Your Router

A 30-year-old web attack that turns any browser tab into a beachhead inside your home network. Why it still works, and what actually stops it.

May 27, 20268 min read
Supply Chain Security

Typosquatting: How One Mistyped Package Owns Your Project

Malicious packages with names one keystroke away from popular libraries are a permanent fixture of npm, PyPI, and crates.io. Here's how the attack works and what blocks it.

May 27, 20268 min read
Encryption & Tools

age vs GPG: The Modern File Encryption Tool

GPG is powerful and ancient. age is a small, modern file encryption tool with one job and no legacy. Here's an honest look at when each fits.

May 27, 20268 min read
Networking & Encryption

Encrypted DNS Compared: DoH vs DoT vs DNSCrypt vs Oblivious DoH

Four protocols encrypt DNS queries, and they make very different trade-offs. A technical comparison of what each protects against, and what it doesn't.

May 26, 20269 min read
Mobile & Privacy

Burner Phone Numbers in 2026: An Honest Guide

Disposable phone numbers used to be cheap and private. Both have changed. A practical comparison of MySudo, Hushed, Google Voice, prepaid SIMs, and data-only eSIMs.

May 26, 20268 min read
Tracking & Privacy

Find My Networks: The Privacy Properties of Crowd-Sourced Tracking

Apple's Find My and Google's Find My Device network turn every iPhone and Android into a tracker for nearby objects. The cryptography is real — the residual risks are non-trivial.

May 26, 20268 min read
IoT & Privacy

Your Car Is a Privacy Nightmare: What Connected Vehicles Actually Collect

Modern cars collect more personal data than most apps, with fewer constraints. What connected vehicles actually track, who sees the data, and what you can do about it.

May 26, 20268 min read
Security & Self-Hosting

Self-Hosted Password Managers Compared: Vaultwarden, KeePassXC, Pass

Three serious self-hosted password managers compared honestly. Each takes a different approach. None is universally right.

May 26, 20269 min read
Cryptography

HPKE Explained: Hybrid Public Key Encryption (RFC 9180)

HPKE is the modern, standardized way to encrypt to a public key — the building block under MLS, TLS Encrypted Client Hello, and Oblivious DoH. Here's what it does and why it replaces twenty-five years of ad-hoc KEM+AEAD glue.

May 25, 202610 min read
DNS & Cryptography

DNSSEC Explained: How DNS Cryptographic Signatures Actually Work

DNSSEC adds signatures to DNS responses so resolvers can detect forgery. Twenty years on, it's still under-deployed and mildly controversial — and structurally important to the protocols that depend on it.

May 25, 20269 min read
Cryptography

Padding Oracle Attacks Explained: When Decryption Errors Leak Plaintext

One bit of leaked information — "valid padding or not" — is enough to recover an entire plaintext, byte by byte. The attack class that brought down POODLE, Lucky 13, and a generation of CBC-mode protocols.

May 25, 20269 min read
Mobile Privacy

eSIM Privacy and Security: What Changes When the SIM Is Software

eSIM trades a removable chip for a remotely-provisioned profile. The cryptography is solid; the privacy surface shifts. What you actually gain, and what quietly goes away.

May 25, 20268 min read
Security & DevOps

Encrypted Git Repositories Compared: git-crypt, git-secret, SOPS, and age

Four ways to keep secrets inside a git repo without leaking them. An honest comparison of git-crypt, git-secret, SOPS, and age — and which to reach for in 2026.

May 25, 20269 min read
Security

JWT Security Pitfalls: The Mistakes That Keep Breaking Tokens

JSON Web Tokens look simple. Three base64 chunks and a signature. The problem is that the format hands authors enough rope to hang an entire application — and the same handful of mistakes keep showing up in CVE feeds.

May 24, 202610 min read
Cryptography

mTLS Explained: How Mutual TLS Authenticates Both Sides

Standard TLS proves the server. Mutual TLS proves the client, too. The mechanism is older than most people realize, and it's quietly become the backbone of zero-trust networking.

May 24, 20269 min read
Hardware Security

Secure Enclaves Compared: SGX, Secure Enclave, and TrustZone

Three names, three architectures, three threat models. A clear-eyed walk through how Intel SGX, Apple's Secure Enclave, and ARM TrustZone actually differ — and where each one breaks.

May 24, 202611 min read
Linux Security

Sandboxing Desktop Linux: Firejail, Bubblewrap, and Flatpak

The Linux desktop has three serious sandboxing options, and they overlap in confusing ways. What each one actually isolates, where they fall short, and how to choose.

May 24, 202610 min read
Web Privacy

Privacy-Respecting Analytics: Beyond Google Analytics

Plausible, Fathom, Umami, and GoatCounter promise web analytics without surveillance. What they actually do, what they don't track, and where the trade-offs live.

May 24, 20269 min read
Emerging Threats

Quishing: When a QR Code Is the Attack

A QR code is a link you can't read. Quishing exploits that blind trust, slipping past email filters built for clickable links and pivoting you onto your least-protected device — your phone.

May 22, 20268 min read
Networking

BGP Hijacking Explained: How Internet Traffic Gets Stolen

The protocol that routes the entire internet runs on trust, with almost no way to tell a true claim from a false one. How hijacks reroute your traffic — and why encryption is your only real defense.

May 22, 202610 min read
Privacy & Email

Email Tracking Pixels: The Invisible Spies in Your Inbox

A single transparent pixel reports the moment you opened an email, roughly where you were, and what device you used. How tracking pixels work — and the one toggle that shuts them off.

May 22, 20268 min read
Security Hygiene

Why "Delete" Doesn't Delete: Data Remanence and Secure Erasure

Sending a file to the trash removes a pointer, not the data. Why SSDs broke the old wiping tools, why crypto-shredding is the modern answer, and how to actually erase a drive.

May 22, 20269 min read
Law & Policy

Data Retention Laws: How Long You Stay in the Logs

Governments often don't need to read your messages — they just need the logs to still exist. What mandatory data retention laws keep, and why encryption doesn't close the gap.

May 22, 20269 min read
Anonymity Networks

Mix Networks Explained: Why Tor Isn't the Last Word on Anonymity

Tor hides who you are from the websites you visit. It does not protect you from someone watching both ends of the network. Mix networks like Loopix and Nym were designed for that threat — and the price is latency.

May 21, 202610 min read
Privacy & Statistics

Differential Privacy Explained: The Math That Lets Apple and Google Watch You Less

The only privacy definition that survives unbounded adversaries with unlimited side information. The math, the ε-budget, and what Apple's and Google's deployments actually buy you.

May 21, 202610 min read
Phishing & Account Security

OAuth Consent Phishing: Stealing Your Account Without Your Password

An attacker doesn't need your Google password if they can convince you to click Allow on a fake app. Consent phishing bypasses 2FA, hardware keys, and password managers — and it has been actively exploited since 2017.

May 21, 20269 min read
Hardware Security

TPM 2.0 Explained: What the Trusted Platform Module Actually Does

The tiny chip on your motherboard that anchors disk encryption, secure boot, and hardware-backed keys. What it does, what it does not, and why Microsoft made it mandatory for Windows 11.

May 21, 202610 min read
Wireless & Privacy

MAC Address Randomization: How Phones Try (and Often Fail) to Hide on Wi-Fi

Every Wi-Fi device broadcasts a hardware address that retailers and ad networks built tracking businesses on top of. iOS and Android now randomize it — and academic research has poked holes in the randomization.

May 21, 20269 min read
Privacy & Surveillance

Bluetooth Tracker Stalking: How AirTags Get Misused and How to Detect Them

A coin-sized disc that finds your keys can also follow a person without their knowledge. How crowd-sourced finding networks work, the cross-platform detection standard, and concrete steps to find a tracker on you.

May 20, 20269 min read
Cryptography

Elliptic Curve Cryptography Explained: Why Smaller Keys Win

A 256-bit elliptic curve key matches a 3072-bit RSA key. That ratio is why TLS, Signal, and SSH all migrated to curves. The geometry behind it, why Curve25519 became the default, and the quantum caveat.

May 20, 20269 min read
Cryptography

Diffie-Hellman Key Exchange Explained: Sharing a Secret in Public

Two strangers talking over a line everyone can hear can still agree on a secret no eavesdropper can recover. The paint-mixing intuition, the real math, the man-in-the-middle catch, and how ephemeral DH gives forward secrecy.

May 20, 20269 min read
Cryptography

Authenticated Encryption (AEAD) Explained: Why Encryption Alone Isn't Enough

Encryption hides your data; it does not stop an attacker from tampering with it. AES-GCM and ChaCha20-Poly1305 deliver secrecy and integrity in one operation — and why nonce reuse is the cardinal sin.

May 20, 20268 min read
Cryptography

Shamir's Secret Sharing Explained: Splitting a Key So No One Holds It

Split a secret into shares so any threshold rebuilds it and any fewer reveal nothing — provably, not just computationally. The line-through-points algebra behind it and where threshold schemes are used.

May 20, 20268 min read
Cryptography & Authentication

OPAQUE: Password Authentication That Never Sends the Password

The standard login model — type a password, send it, hope — has a structural flaw nobody has been able to fix without changing the protocol. OPAQUE changes the protocol. Here's the cryptography behind it.

May 18, 202611 min read
Cryptography & SSH

Ed25519 vs RSA vs ECDSA: SSH Key Types Compared

Every SSH client supports at least three key algorithms. The differences aren't cosmetic — they touch the assumptions your keys rely on, the failure modes, and the size of the artifact you'll carry for the next decade.

May 18, 202610 min read
Email Security

MTA-STS and TLS-RPT: Forcing Encrypted Email Delivery

SMTP's STARTTLS is opportunistic by design — any on-path attacker can strip it. MTA-STS and TLS-RPT close that gap by letting domains advertise TLS as required, with reporting to detect when it fails.

May 18, 20269 min read
Web Security

HSTS and the Preload List: How Browsers Force HTTPS

Type bank.com into a browser and the first request leaves your machine in cleartext. HSTS closes that window — and the preload list closes it even before your browser has ever talked to the site. Getting on the list is a one-way door.

May 18, 20269 min read
DNS & TLS

CAA Records: Telling CAs Who Can Issue for Your Domain

The WebPKI has roughly 70 trusted CAs. Without a CAA record, every one of them is allowed to issue a valid TLS certificate for your hostname. CAA reduces that set to whoever you've actually authorized.

May 18, 20268 min read
Cryptography & Protocols

The Signal Double Ratchet Algorithm, Explained

The algorithm behind Signal, WhatsApp, and Matrix Olm. How it delivers forward secrecy and post-compromise security in one protocol — and why it became the standard for 1:1 encrypted messaging.

May 15, 202611 min read
Encryption & TLS

TLS 1.3 vs TLS 1.2: What Actually Changed

TLS 1.3 dropped a decade of legacy ciphers, halved the handshake, and made forward secrecy mandatory. A clear look at the security and performance differences — and where deployments still fall back.

May 15, 20269 min read
Cryptography

Argon2 vs bcrypt vs scrypt: Password Hashing Compared

Three serious password hash functions, three design philosophies. A pragmatic comparison of what each resists, where they differ in tuning, and what to actually pick in 2026.

May 15, 202610 min read
Browser Security

WebRTC IP Leaks and How to Block Them

WebRTC needs your real IP to function — and any website can ask for it without permission. How the leak works, what your VPN does and doesn't fix, and the configurations that actually stop it.

May 15, 20268 min read
Censorship Resistance

Tor Bridges and Pluggable Transports: How Censorship Circumvention Works

Tor's relay directory is public, which makes it trivial to block. Bridges and pluggable transports — obfs4, meek, snowflake, webtunnel — are the architectural answer. Here's what each disguises and where each still works.

May 15, 202610 min read
Censorship Resistance

Messaging Without the Internet: Briar and the Case for Mesh

When infrastructure is hostile, mesh networking lets phones talk to each other directly over Bluetooth, WiFi, or Tor. Here's how Briar works and where mesh genuinely matters.

May 13, 202610 min read
Encryption & Metadata

Sealed Sender: How Signal Hides Who's Messaging Whom

End-to-end encryption protects message contents, not metadata. Sealed sender is Signal's attempt to hide the "from" field — here's how it works and what it doesn't cover.

May 13, 20269 min read
Phishing & DNS

The Domain You Saw Wasn't the Domain You Got: Homograph Attacks Explained

Internationalized domain names let attackers register domains that look identical to real ones using non-Latin characters. Here's how Punycode phishing works and what stops it.

May 13, 20269 min read
Cryptography

HKDF: Turning One Secret Into Many, Correctly

HKDF (RFC 5869) is the standard way modern protocols derive multiple keys from a single shared secret. Here's how extract-then-expand works and where it fits versus PBKDF2 and Argon2.

May 13, 202610 min read
Web Security

Subresource Integrity: The Hash Tag That Protects Web Apps

SRI lets browsers refuse to execute third-party scripts that don't match a known hash. It's a small attribute with outsized impact — but it doesn't cover what most people think.

May 13, 20268 min read
Policy & Surveillance

EU Chat Control: What Client-Side Scanning Actually Means for Encryption

The EU proposes scanning your messages on-device before they're encrypted and sent. Here's the technical reality — and why cryptographers say it breaks end-to-end encryption by design.

May 12, 20269 min read
Encryption & Hardware

Secure Enclaves and Trusted Execution Environments, Explained

Your phone's private keys live in hardware-isolated enclaves the main OS can't read. Here's how Secure Enclaves, TEEs, and TPMs actually work — and what attacks they can and can't stop.

May 12, 20268 min read
Privacy & Security

Tails OS and Amnesic Computing: How to Leave No Trace

Tails boots from a USB stick, routes all traffic through Tor, and forgets every session on shutdown. For journalists and activists whose hardware could be seized, this changes the forensic calculus entirely.

May 12, 20268 min read
Encryption & TLS

Certificate Transparency Logs: What Your TLS Certificates Reveal

Every TLS certificate you issue is logged publicly and permanently. CT logs catch rogue certificate issuance — and expose your infrastructure to anyone who knows where to look.

May 12, 20267 min read
Security Fundamentals

Why Your Clock Is a Cryptographic Attack Surface

TLS certificate validation depends on accurate time. NTP is unauthenticated by default and can be spoofed. Here's how time attacks work and how NTS (RFC 8915) fixes them.

May 12, 20267 min read
Mobile Surveillance

IMSI Catchers and Stingray Surveillance: What Your Phone Leaks to Fake Cell Towers

Cell site simulators are deployed by hundreds of law enforcement agencies worldwide. Here's what they actually capture, what 5G SA changes, and what application-layer encryption protects against.

May 11, 20269 min read
Security Architecture

Air-Gapped Computers: When and How to Use Offline Systems for High-Value Secrets

An air-gapped machine has never touched a network and never will. For PGP master keys, cryptocurrency seeds, and classified document handling, this is the only architecture that works — if done right.

May 11, 20268 min read
Financial Privacy

Privacy-Preserving Payments: What Actually Works in 2026

Every credit card swipe is a surveillance event retained by banks, merchants, and data brokers. An honest comparison of cash, virtual cards, prepaid cards, and cryptocurrency — what each protects and against what.

May 11, 20268 min read
Cryptography & Security

Code Signing and Sigstore: How Software Supply Chain Integrity Works

SolarWinds was signed with a valid certificate. Signing proves the software came from a key — Sigstore's transparency log approach is what proves the key was used legitimately. A technical deep dive.

May 11, 20269 min read
Encryption

VeraCrypt and Encrypted Containers: Plausible Deniability and Hidden Volumes Explained

Two passwords, two entirely different decrypted contents — cryptographically, no forensic tool can prove a hidden volume exists. Here's how it works, when it matters, and its real operational limits.

May 11, 20269 min read
Legal & Policy

National Security Letters: The Surveillance Tool That Comes with a Built-In Gag Order

NSLs are issued by the FBI without judicial review, with a statutory gag order attached. Here's what they can compel, how they appear in transparency reports, and what they mean for your privacy model.

May 10, 20269 min read
Protocols

Matrix: The Open Protocol for Federated Encrypted Messaging

Signal works well when everyone trusts the same company. Matrix is built for when they don't. A technical deep dive into federation, Olm/Megolm encryption, and the honest trade-offs.

May 10, 202610 min read
Security & Protocols

Why Voice Calls Are Still Mostly Plaintext (And the Protocols That Fix It)

SS7, SRTP, ZRTP, and how Signal voice calls actually work. The phone system was designed without privacy; here's what end-to-end encrypted calls actually require.

May 10, 20269 min read
Digital Safety

Stalkerware: How Surveillance Apps Hide on Your Device

Commercial spyware sold legally, marketed as parental monitoring, and used overwhelmingly by abusers. How it works, how to detect it, and why removal requires a safety plan before anything else.

May 10, 20269 min read
Privacy Tools

Private Search Engines Compared: DuckDuckGo, Brave, Kagi, and SearXNG

Search engines build detailed profiles from your queries. Here's an honest comparison of the serious private search options — what they actually protect and where each falls short.

May 10, 20268 min read
Legal & Policy

Five Eyes and Your Privacy: What the Intelligence Alliance Actually Means

Five Eyes lets member nations share surveillance data on each other's citizens. Here's what the alliance actually does, how it differs from what marketing claims, and how to reason about it when choosing privacy tools.

May 9, 20269 min read
Security Research

Cold Boot Attacks: Why Disk Encryption Doesn't Protect a Running Computer

Full-disk encryption protects powered-off devices — but your keys live in RAM while the computer is running. Cold boot attacks exploit RAM data remanence to extract those keys. Here's how the attack works and what actually mitigates it.

May 9, 20268 min read
Security Hygiene

Canary Tokens: How to Know When Your Files Have Been Accessed

Canary tokens are tracked decoys — files, URLs, and credentials that alert you the moment an attacker touches them. They work best precisely when other defenses have already failed.

May 9, 20267 min read
Privacy & Legal

Device Privacy at Border Crossings: What Agents Can Search and What You Can Do

Border agents in the US, UK, and Canada have broad authority to search your devices without a warrant. Here's what the law actually says and how to prepare before you travel.

May 9, 20269 min read
Legal & Policy

CCPA vs GDPR: What Your Data Rights Actually Give You

Both laws claim to put you in control of your personal data. The reality is narrower and more dependent on enforcement than either implies. Here's what you actually have — and what you don't.

May 9, 20269 min read
Encryption Deep Dive

Post-Quantum Cryptography: What Happens to Your Encrypted Data When Quantum Arrives

Quantum computers will break RSA and ECC. NIST finalized post-quantum replacement standards in 2024, and Signal, Apple, and Chrome have already started migrating. Here's what's at risk and how the transition works.

May 8, 202610 min read
Legal & Policy

The Long War Over Encryption Backdoors: From Clipper Chip to Today

Governments have tried to mandate backdoors in encryption since 1993. Every attempt has failed — not for political reasons, but mathematical ones. The history, and why it keeps repeating.

May 8, 20269 min read
Practical Guide

Secure Communication for Journalists: A Practical Guide to Source Protection

Protecting sources requires more than encrypted apps. Here's the threat model journalists face, the tools that actually help, and the operational mistakes that undermine technical security.

May 8, 20269 min read
Security & Authentication

The Problem with Biometrics: You Can't Change Your Fingerprints

Biometrics are convenient — but irrevocable. Here's what that means for device security, legal compulsion by law enforcement, database breaches, and how to use biometrics safely.

May 8, 20268 min read
Security Hygiene

DNS Leaks: The Invisible Privacy Hole in Most VPN Setups

Your VPN may be tunneling traffic while DNS queries travel in the clear to your ISP. What DNS leaks are, why they happen on every major OS, and how to actually fix them.

May 8, 20268 min read
Security & Threats

Account Takeover Attacks: How They Work and Why MFA Isn't Always Enough

Credential stuffing, adversary-in-the-middle phishing, session hijacking — account takeover attacks have evolved well past what standard MFA stops. Here's how each works and what actually defends against it.

May 7, 20269 min read
Privacy Tools

Which Browser Should You Actually Use for Privacy in 2026?

Firefox, Brave, Tor Browser, Mullvad Browser — each solves a different part of the privacy problem. An honest breakdown of tracker blocking, fingerprint resistance, and network anonymity across all four.

May 7, 20268 min read
Encryption & Security

Reproducible Builds: The Only Way to Verify Your Software Wasn't Tampered With

Open source proves reviewed code exists. It doesn't prove the binary you downloaded was compiled from that code. Reproducible builds close the gap — here's how they work and who achieves them.

May 7, 20269 min read
Privacy & Communications

Which Video Call Apps Are Actually Private?

Zoom, Signal, FaceTime, Element, Jitsi — they all claim privacy, but the details vary enormously. What gets encrypted, who holds the keys, and what metadata persists are questions with very different answers.

May 7, 20269 min read
Privacy Tools

End-to-End Encrypted Cloud Storage: What Actually Protects Your Files

Proton Drive, Tresorit, Filen, MEGA — all advertise zero-knowledge encryption. The implementations differ in audits, jurisdictions, key derivation, and sharing models in ways that matter for your threat model.

May 7, 20268 min read
Encryption & Security

Side-Channel Attacks: The Threat That Bypasses Encryption

Your encryption can be mathematically perfect and still leak secrets. Timing attacks, cache attacks, and Spectre-class vulnerabilities exploit physical computation rather than algorithmic weaknesses — here's how they work.

May 6, 20269 min read
Privacy Tools

WireGuard vs. OpenVPN: A Technical Comparison That Matters for Privacy

WireGuard's lean design and modern cryptography make it faster than OpenVPN — but it stores peer IP addresses in memory by design. An honest comparison of both protocols and the privacy trade-offs involved.

May 6, 20269 min read
Encryption & Keys

The PGP Web of Trust: Why Key Verification Is Harder Than It Looks

OpenPGP's web of trust was an elegant solution to key authenticity without central authorities. It mostly didn't work — and understanding why reveals what good key verification actually requires.

May 6, 20269 min read
Security Hygiene

How to Segment Your Home Network for Privacy and Security

A flat home network lets every device reach every other. VLANs and firewall rules create walls between your work laptop, your IoT devices, and your guests — here's a practical guide to doing it right.

May 6, 20268 min read
Privacy Planning

What Happens to Your Encrypted Data When You Die?

Strong encryption is unforgiving — a lost passphrase means the data is gone, permanently. Digital estate planning for security-conscious people requires thinking carefully about the trade-off most privacy guides skip.

May 6, 20268 min read
Privacy Policy & Design

Privacy Dark Patterns: How Companies Design Around Your Consent

Cookie banners put "Accept All" in a large colored button and "Reject" in small grey text. That's not an accident. Here's how to recognize the design techniques companies use to collect more data than you'd willingly share.

May 5, 20268 min read
Messaging & Encryption

RCS Encryption: What Google and Apple Aren't Telling You

Both companies claim RCS is encrypted. The reality is more complicated — the encryption is real in some cases, absent in others, and architecturally different from what most people assume.

May 5, 20269 min read
Security Hygiene

How Password Managers Actually Protect Your Data

A password manager is the highest-leverage security upgrade most people can make. The LastPass breach revealed what good vault design looks like — and where weaker implementations fall short.

May 5, 20269 min read
Mobile Security

GrapheneOS: The Case for a De-Googled Android

The most rigorously hardened Android fork available — with full app compatibility via sandboxed Google Play. Here's what GrapheneOS actually changes, what it doesn't fix, and who it's right for.

May 5, 202610 min read
Privacy & Surveillance

What Your Smart Home Is Logging (And How to Limit It)

Smart speakers, doorbells, thermostats, and TVs are always-on sensors. Here's what data they actually collect, where it goes, and the network-level steps that actually reduce it.

May 5, 20269 min read
Security & Open Source

Supply Chain Attacks: When Your Privacy Tool Gets Compromised

The XZ Utils backdoor showed that even carefully audited open-source software can be infiltrated at the build layer. Here's how supply chain attacks work, why privacy tools are high-value targets, and what reproducible builds actually solve.

May 4, 20269 min read
Data Privacy

Location Data Brokers: Your Movement History Is for Sale

Weather apps and coupon apps harvest your GPS coordinates and sell them to brokers who supply advertisers, insurers, and government agencies. Here's the infrastructure and who's buying.

May 4, 20269 min read
Legal & Policy

FISA Section 702: The Legal Backdoor Into Your Communications

Section 702 allows US intelligence agencies to collect foreign communications — and then search them for Americans without a warrant. Every major US tech company is subject to it.

May 4, 202610 min read
Advertising & Privacy

Cross-Device Tracking: How Advertisers Link All Your Screens

Your phone, laptop, and smart TV are, to the ad industry, a single identity. Here's the deterministic and probabilistic infrastructure that connects them — and where each defense actually works.

May 4, 20269 min read
System Security

Secure Boot and TPM: What They Protect (and What They Don't)

Secure Boot and TPM chips address the boot integrity threat model and disk theft. They say nothing about what happens after the OS loads. Understanding the perimeter matters.

May 4, 20269 min read
Encryption Protocols

How Group Encrypted Messaging Actually Works

Secure group chats are a harder engineering problem than 1:1 messaging. Here's how Sender Keys, the Double Ratchet, and MLS each tackle the challenge — and where they fall short.

May 3, 202610 min read
Network Security

Traffic Analysis: The Threat That Encryption Can't Stop

Encrypting content protects what you say. Traffic analysis reveals who you talk to, when, how often, and how much — without decrypting a single byte.

May 3, 20269 min read
Cryptography

Proving You're Allowed In Without Revealing Who You Are

Zero-knowledge proofs let you prove you satisfy a condition without revealing your identity. Here's how anonymous credential systems work and where they're being deployed.

May 3, 20269 min read
Secure Messaging

What "Disappearing Messages" Actually Protects (and What It Doesn't)

Every major messaging app offers disappearing messages. The feature is real and useful — but it protects against a narrower set of threats than most users assume.

May 3, 20267 min read
Mobile Privacy

Your App Permissions Are a Privacy Attack Surface

Every time you tap "Allow," you're extending trust. Over years of installing apps, most users have granted far more access than they recall — to contacts, location, microphone, and more.

May 3, 20268 min read
Privacy

The Privacy Skill Nobody Teaches: Building a Personal Threat Model

Picking privacy tools without a threat model is like buying a lock without knowing what you're locking out. The five questions that make your privacy choices coherent — and why overkill is its own risk.

May 1, 20269 min read
Privacy & Security

What OSINT Researchers Can Find About You in 30 Minutes

Most privacy violations don't require hacking. Public records, data broker aggregates, and search syntax expose more than most people realize — without accessing a single system they weren't supposed to.

May 1, 20269 min read
Encryption & Privacy

Secure File Sharing: What "End-to-End Encrypted" Actually Means for Files

Where does the file live, who holds the keys, and what metadata survives the transfer? The questions that actually matter when sharing files securely.

May 1, 20268 min read
Privacy & Networking

What Your ISP Can See — And the Limits of What Can Hide It

Your ISP sits between your devices and everything else. Understanding what they observe, what HTTPS hides, and what actually helps is the starting point for network-level privacy.

May 1, 20269 min read
Security & Encryption

Encrypted Backups: How to Protect Your Data Without Trusting the Cloud

A backup that a subpoena or breach can read is a second copy of your most sensitive data in someone else's hands. Here's how client-side encryption changes that equation.

May 1, 20268 min read
Privacy

How Messaging Apps Harvest Your Social Graph Through Contact Discovery

When you grant a messaging app access to your contacts, it doesn't just find your friends — it maps who you know. The contact discovery problem, and how Signal's OPRF approach actually solves it.

April 30, 20269 min read
Security Basics

TOTP, SMS, Hardware Keys, and Passkeys: An Honest 2FA Comparison

Not all two-factor authentication is equal. SMS codes and hardware security keys are both called "2FA" — they are not remotely equivalent. Here's what each actually resists.

April 30, 202610 min read
Encryption

Full-Disk Encryption Explained: What LUKS, FileVault, and BitLocker Actually Protect

Full-disk encryption makes a stolen laptop worthless to an attacker — but only when powered off. Here's the precise threat model, the implementation differences, and what it doesn't protect against.

April 30, 20269 min read
Privacy

Tor vs. VPN: What They Actually Protect (and What They Don't)

Both are called privacy tools. They solve different problems, have different trust models, and fail in different ways. Understanding the distinction prevents over-reliance in either direction.

April 30, 20269 min read
Privacy

What AI Can Infer About You: Machine Learning and the Surveillance Problem

Encryption protects data. Machine learning infers from data. The gap between what was recorded and what can be derived has widened considerably — and changes the calculus of privacy.

April 30, 202610 min read
Encryption

Trust On First Use: The Security Gamble Built Into Most Encrypted Apps

TOFU is how Signal, WhatsApp, and most encrypted apps handle key exchange. It protects against passive eavesdropping — but has a narrow, critical weakness at the exact moment keys are first exchanged.

April 29, 20268 min read
Email Security

SPF, DKIM, and DMARC: What Email Authentication Actually Does

SMTP has no built-in sender verification — anyone can claim any address. Here's how three layered standards close most of that gap, and what they still can't prevent.

April 29, 20269 min read
Legal & Policy

The Surveillance Gap: Why U.S. Communications Law Is Still Stuck in 1986

The law governing government access to your email and cloud data was written before the commercial internet existed. Here's what that means for your data on American servers today.

April 29, 20269 min read
Privacy

Apple's iCloud Private Relay: Two-Hop Privacy and Its Limits

Private Relay ensures no single party sees both your identity and your browsing destinations. That's a meaningful property — and a narrower one than the word "relay" sometimes implies.

April 29, 20268 min read
Security Basics

What Your VPN Actually Protects (And the Long List of What It Doesn't)

A VPN shifts your traffic from your ISP to your VPN provider. That shift is real — but narrower than most VPN marketing implies. A clear-eyed threat model for a tool that's widely misunderstood.

April 29, 20268 min read
Encryption Protocols

Key Transparency: The Missing Layer That Makes E2E Encryption Trustworthy

End-to-end encryption relies on a key exchange you can't audit — key transparency closes that gap with a tamper-evident log of every key binding, making silent key substitution mathematically detectable.

April 28, 20268 min read
Legal & Policy

Warrant Canaries: What They Promise, and Where They've Failed

A warrant canary signals — without saying so — that a service hasn't received a secret government demand. It's a clever legal workaround with real limits. Here's how it works and what a dead canary actually tells you.

April 28, 20267 min read
Security Hygiene

Passkeys Explained: Why the Password's Replacement Is Worth Trusting

Passkeys use public-key cryptography to replace passwords entirely. Phishing-resistant by design, no shared secret, no server-side credential to breach. Here's how they actually work.

April 28, 20268 min read
Privacy How-To

How to Remove Yourself from Data Broker Databases (And Why It's an Ongoing Job)

Data brokers aggregate and sell your address history, relatives, phone numbers, and more — assembled without your knowledge. Opting out is possible, but it requires a systematic and repeating approach.

April 28, 20269 min read
Encryption & Privacy

DNS-over-HTTPS: What It Actually Protects (and What It Doesn't)

DNS-over-HTTPS encrypts your domain lookups, hiding them from your ISP. But it shifts trust rather than eliminating it, and several common threats it doesn't address are worth understanding clearly.

April 28, 20268 min read
Security & Identity

SIM Swapping: The Attack That Bypasses Every Password You Own

Your password is strong and your two-factor code arrives by SMS. A criminal with a phone and a convincing story can own your accounts in under an hour. Here's how the attack works and what actually stops it.

April 28, 20268 min read
Privacy & Surveillance

Browser Fingerprinting: How You're Tracked Without Cookies or Accounts

Privacy mode blocks cookies. It does nothing to stop browser fingerprinting — a stateless technique that identifies your browser configuration with high precision and survives every session you start.

April 28, 20267 min read
Security Hygiene

Hardware Keys vs. Authenticator Apps: Which 2FA Actually Protects You?

Both are better than SMS codes. The difference between them — particularly against phishing — separates a 2FA setup that looks strong from one that actually is.

April 28, 20267 min read
Encryption & Protocol

Certificate Pinning: The Mobile Security Layer Most Apps Skip

TLS verifies that your certificate was signed by a trusted CA — not which CA. Certificate pinning fills that gap, and the apps that skip it are more vulnerable to interception than their padlock icon suggests.

April 28, 20267 min read
Policy & Law

GDPR in Practice: What European Privacy Law Actually Protects (and What It Doesn't)

GDPR is the gold standard of privacy regulation and is frequently misunderstood. Here's what the law actually does — and where it was never designed to protect you.

April 28, 20268 min read
Privacy & Industry

What Happens When a Privacy App Gets Acquired?

WhatsApp, Wickr, Skype — the pattern repeats. A privacy-forward product gets bought by a larger company, and the commitments quietly erode. Here's the history and what it means for your choice of tools.

April 28, 20269 min read
Encryption Deep Dive

Forward Secrecy Explained: Why a Data Breach Won't Expose Your Old Messages

Forward secrecy is what makes encrypted messaging resilient to future key compromise. Here's how key ratcheting works and why your message history stays protected even if keys are later exposed.

April 28, 20268 min read
Privacy & Business

The Business Model Problem: Why Free Privacy Apps Don't Exist

Every app needs revenue. When that revenue comes from advertisers instead of users, your data is the product. Here's the structural reason free and private are incompatible.

April 28, 20268 min read
Email Privacy

Email Aliases: The Privacy Feature Most People Don't Know Exist

Most people use one email address for everything. That address is your identity, your login, and your breach surface — all in one. Aliases break that dependency.

April 27, 20267 min read
Privacy & Apple

iCloud Backups Are Breaking Your iMessage Encryption

iMessage is end-to-end encrypted. But if you back up to iCloud, your messages aren't. Here's exactly what Apple can see — and what to do about it.

April 27, 20267 min read
Secure Messaging

WhatsApp vs Signal vs Haven: An Honest Comparison

All three apps claim to protect your messages. Here's what actually separates them — phone number requirements, metadata collection, business model, and audit history.

April 27, 20269 min read
Privacy & Email

The Best Gmail Alternatives in 2026 (That Actually Protect Your Privacy)

Gmail is free because your email is the product. If you're looking for an alternative in 2026 that doesn't read your mail, here's what actually works.

April 25, 20269 min read
Privacy & Security

Telegram Is Not Encrypted. Here's What That Actually Means.

Telegram is widely misunderstood as an encrypted app. Most of it isn't. Here's what's actually happening with your messages.

April 25, 20268 min read
Cryptography

What End-to-End Encryption Actually Protects (And What It Doesn't)

E2EE is the most cited and least understood concept in security. A precise breakdown of what it protects, what it misses, and what you actually need.

April 25, 20269 min read
Privacy & Security

Your Encrypted App Has a Leak. It's Called Metadata.

Encryption protects what you say. It says nothing about when, to whom, how often, or from where — and that pattern reveals more than most people are comfortable admitting.

April 24, 20268 min read
Cryptography

Encryption Is Not Privacy. Here's the Difference.

Every privacy tool encrypts something. Almost none of them guarantee privacy. Conflating the two is how security theater happens.

April 24, 20267 min read
Privacy & Email

Why Email Is Still the Most Important Thing to Encrypt

Signal and Telegram get the headlines. Meanwhile, your unencrypted inbox holds the keys to your entire digital identity.

April 24, 20268 min read
Guide

Building a Complete Privacy Stack in 2026: Email, Chat, and Files

A practical guide to replacing Gmail, iMessage, and Google Drive with genuinely private alternatives — without needing a computer science degree to set it up.

April 21, 202610 min read
Privacy & Email

The Honest Case for Leaving ProtonMail in 2026

ProtonMail earned its reputation — but its limitations are showing. Here's what power users switch to, and what to actually look for.

April 21, 20268 min read
Privacy & Identity

Signal Requires Your Phone Number. That's a Bigger Problem Than You Think.

Signal's cryptography is excellent. The weak link isn't the encryption — it's the identity model.

April 21, 20267 min read
Cryptography

Zero-Knowledge Email: What It Means, What It Doesn't

"Zero knowledge" is the most abused term in privacy marketing. Here's what it actually requires cryptographically.

April 21, 20267 min read
Cryptography

MLS: The Encryption Protocol Designed to Fix Group Chat

RFC 9420 introduces Messaging Layer Security — a standardized protocol that solves group encryption's biggest problems.

April 21, 20269 min read