> articles
Articles
How systems are attacked and how they are built, in plain terms. No vendor language and no scare stories — the mechanics, and what to do about them.
Which security certifications are actually worth it
Three different problems: learning something, passing a recruiter's filter, satisfying a bank's procurement. What the exams are, and who really requires them.
How a phishing attack is actually built
Most phishing advice describes the symptoms. Here is the construction, from the attacker's side — and the two defences that survive it.
What happens to your password after a breach
Follow one password from a leaked database to somebody else's account being taken over. The mechanics explain why reuse is the only fact that matters.
What an attacker learns about you before touching anything
Before anyone touches a system they read what you already published: certificate logs, job adverts, document metadata. Audit your own the same way.
Now check your own
Reading about how systems come apart is useful. Watching it happen to yours is more useful. Describe what you have built and the tool will run the same first pass on it.