Sep 5, 2026 in encryption, windows, threat-model - On most consumer Windows PCs the BitLocker recovery key is uploaded to the Microsoft account used at setup. That is why people find it, and it is also the part of the threat model most users never agreed to. Where it lives, how to check, and what changes if you remove it.
Sep 5, 2026 in windows, privacy, telemetry - The settings that reduce Windows 11 telemetry are real, and the tools that promise to remove it entirely are mostly not. What Required diagnostic data covers, which switches change something measurable, and where the honest limit sits.
Sep 5, 2026 in linux, forensics, incident-response - Every checklist gives you the same commands. Almost none of them tell you that running those commands on the suspect machine is exactly what an attacker prepared for. Here is what to look at, in the order that still tells you something.
Sep 5, 2026 in wifi, privacy, network - A rogue hotspot looks exactly like the real one, because it is allowed to. The name, the signal and the captive portal can all be copied in minutes. Here are the signals that actually distinguish them, and the one habit that makes the question stop mattering.
Sep 5, 2026 in linux, logging, auditd - journalctl, ausearch, aureport, last, lastb and auditctl cover almost everything you will ever need to ask a Linux system about its own past. What each one sees, what none of them see, and why a log on the machine is evidence of a different quality than a log shipped off it.
Sep 4, 2026 in vpn, anonymity, threat-model - A double VPN sends your traffic through two servers instead of one. What that genuinely protects against, what it costs in speed and latency, and the common cases where it changes nothing at all because the weak link is somewhere else entirely.
Sep 4, 2026 in surveillance, privacy, travel - A hidden camera is found by systematic inspection, not by a gadget. Which objects actually host them, why the lens reflection trick works and when it does not, what a network scan can and cannot tell you, and what to do if you find one.
Sep 4, 2026 in vpn, privacy, isp - Your provider stops seeing which sites you visit the moment a VPN is on. It still sees that you are using one, how much you send and when. And browsing history is a separate thing entirely, because it lives on your device, not at the provider.
Sep 4, 2026 in messaging, anonymity, metadata - Session drops phone numbers and central servers, Signal keeps both and encrypts everything else. What each one hides from whom, what Session gives up to get anonymity, and the single question that decides which of the two you actually need.
Sep 4, 2026 in mobile, 2fa, account-security - A SIM swap moves your number to someone else's card, and every code sent by text follows it. What actually stops the attack at the carrier, why SMS two-factor is the wrong lock, and the ten minutes that decide whether you keep your accounts.
Sep 4, 2026 in vpn, privacy, network - A kill switch cuts your internet the moment the VPN tunnel drops, so nothing leaves in the clear. What it protects, the gap between blocking one application and blocking the whole device, and how to test yours in two minutes instead of trusting the label.
Sep 4, 2026 in vpn, privacy, network - Split tunneling sends some applications through the VPN and lets the rest use your ordinary connection. What it fixes, the three ways it quietly leaks, and the one question that tells you whether to turn it on.