Sep 5, 2026 in gpg, encryption, troubleshooting - The message is precise and almost everyone misreads it. GPG is not saying your key is wrong, it is saying the key that can open this file is not in the keyring it is looking at. Here is how to find out which key the file wants, and the four reasons yours is missing.
Sep 5, 2026 in linux, forensics, incident-response - Every checklist gives you the same commands. Almost none of them tell you that running those commands on the suspect machine is exactly what an attacker prepared for. Here is what to look at, in the order that still tells you something.
Sep 5, 2026 in usb, boot, linux - You can tell whether a stick will boot by reading its partition table, its boot flag and its EFI directory. Three commands on Linux, two on Windows, one on macOS. What each check proves, and the one it cannot.
Sep 5, 2026 in wifi, privacy, network - A rogue hotspot looks exactly like the real one, because it is allowed to. The name, the signal and the captive portal can all be copied in minutes. Here are the signals that actually distinguish them, and the one habit that makes the question stop mattering.
Sep 5, 2026 in linux, logging, auditd - journalctl, ausearch, aureport, last, lastb and auditctl cover almost everything you will ever need to ask a Linux system about its own past. What each one sees, what none of them see, and why a log on the machine is evidence of a different quality than a log shipped off it.
Sep 5, 2026 in ssh, authentication, linux - A password is a secret you send. A key is a secret you never send. That one distinction settles most of the argument, decides what a compromised server can steal from you, and explains why key authentication is not simply a stronger password.
Sep 5, 2026 in detection, intrusion, monitoring - A canary token is a file, a URL or a credential that has no legitimate use. Nothing should ever touch it, so the day something does, you learn about an intrusion your other tools missed. What they detect, where to place them, and the two ways people ruin them.
Sep 4, 2026 in privacy, browser, tracking - Fingerprinting identifies you by how your browser is configured, not by a cookie you can delete. How to check your own in two minutes, why installing more privacy extensions often backfires, and the only two approaches that genuinely work.
Sep 4, 2026 in vpn, privacy, isp - Your provider stops seeing which sites you visit the moment a VPN is on. It still sees that you are using one, how much you send and when. And browsing history is a separate thing entirely, because it lives on your device, not at the provider.
Sep 4, 2026 in vpn, anonymity, threat-model - A double VPN sends your traffic through two servers instead of one. What that genuinely protects against, what it costs in speed and latency, and the common cases where it changes nothing at all because the weak link is somewhere else entirely.
Sep 4, 2026 in encryption, windows, cloud - Password-protecting a folder, encrypting it into a container, and turning on full disk encryption solve three different problems. Which one matches your actual threat, what each leaves visible, and the mistake that makes cloud folders leak anyway.
Sep 4, 2026 in surveillance, privacy, travel - A hidden camera is found by systematic inspection, not by a gadget. Which objects actually host them, why the lens reflection trick works and when it does not, what a network scan can and cannot tell you, and what to do if you find one.