The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
A proposed US copyright law would let courts order large VPN, broadband, and DNS providers to block access to foreign sites. Here is what the bill says, where collateral damage begins, and what privacy-conscious users should watch.
A China-aligned phishing campaign relayed real Microsoft sign-ins while stealing the resulting sessions. The defence starts with origin-bound authentication, independent verification, and a response plan that revokes more than a password.
An automated intruder chained two Zammad flaws and reached root in seconds at DIVD. The useful lesson is how segmentation, logs, and a fast containment decision kept speed from becoming unlimited reach.
Fortinet says attackers are exploiting a FortiMail flaw before fixed releases are available. The immediate job is to apply a supported workaround, prove the exposed route is closed, and keep watching until the fixed build is running.
GitLab fixed a critical escape from a prompt-template sandbox in its self-hosted AI Gateway. The repair should end with proof of the running image, a review of who could create custom flows, and a decision about exposed credentials.
A federal judge blocked Utah’s demand that adult websites identify every visitor physically inside the state, even behind a VPN. The narrow ruling shows why privacy tools need honest limits, precise laws, and a threat model that survives contact with the network.
MetaMask reported an infrastructure incident in its staking operation while saying it found no indication that wallets or customer funds were affected. Here is how to separate those systems, check your own position, and avoid the scams that follow security news.
OpenAI showed a prompt injection copying itself into an agent's output in simulated tests. The practical response is to stop treating agent-written messages, files, and code as trusted input for the next agent.