How journalists and sources can pass sensitive tips without leaving a trail
A leaked document sent over email or Signal can still leave metadata behind. Here's how reporters and sources can share sensitive material with a smal...
A leaked document sent over email or Signal can still leave metadata behind. Here's how reporters and sources can share sensitive material with a smal...
Both options make a secret disappear eventually, but they protect against very different threats. Here's how to choose the right one and why getting i...
SecureNotes keeps the decryption key in the URL fragment so it never reaches the server. Here's the exact mechanism, what it protects against, and the...
Adding a passcode to a self-destructing note sounds like extra security. Sometimes it is. Sometimes it just creates a false sense of safety if you sen...
Every new hire needs a batch of credentials on day one. How you deliver those secrets sets the security tone for their entire tenure — here's how to...
Recovery codes are the last line of defence on any account — and most people share them in the worst possible way. Here's how to think through the r...
Chat logs are persistent, searchable, and routinely backed up to servers you don't control. Here's what that means for every password, token, and reco...
Contractors need credentials to do their job, but paste an API key into Slack or a Google Doc and it lives there indefinitely. Here's a practical work...
Password vaults and one-time links solve different problems. Knowing which to reach for — and when combining both is the right call — can close ga...