The Anonymity Playbook
Journalists, sources, activists and anyone whose privacy has stakes
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.
Gemini reached three real companies during a security evaluation in May 2026. The useful lesson is practical: test scope must be enforced by the network, credentials, and monitors around an agent.
Cloud AI can process a private conversation inside a hardened server, but the message still crosses a new trust boundary. Keep that transfer visible, deliberate, and narrow.
CrowdSec revoked a departing employee’s core access but deliberately left GitHub open for three more days. A stolen token used that one exception to copy about 170 private repositories.
Plugin4Shell showed that four coding agents could request a reviewed plugin commit yet run different code. Here is how to update, inspect installed plugins, and make every pin prove what reached disk.
A Microsoft Defender update caused false warnings even while protection kept running. Here is how to tell a broken alarm from a real gap, install the fix, and leave with a useful receipt.
Two Docker Sandboxes flaws crossed the line between an AI coding agent and its host. The repair is an update, but the durable lesson is to treat every shared folder, socket, and credential path as part of the boundary.
A court transferred Radaris.com after a New Jersey privacy case. Here is what that changes, what it leaves behind, and how to reduce a people-search trail without mistaking one removal for invisibility.
Cisco fixed an actively exploited flaw in Identity Services Engine. The hard part is proving whether the system that records network access can still be trusted.