secure-os.org
All guidesQubes OSTailsWhonixHardened LinuxDisk encryptionThreat model
A red onion cut in half standing upright on a white plate against a dark grey wall, its concentric purple and white rings lit from the side, the plate resting on a pale blue green surface

secure-os wrote

Signal vs Session: The Phone Number Is the Whole Argument

Sep 4, 2026 in messaging, anonymity, metadata - Session drops phone numbers and central servers, Signal keeps both and encrypts everything else. What each one hides from whom, what Session gives up to get anonymity, and the single question that decides which of the two you actually need.

Read more…
📅 4 min read🛡️ Threat-model-first

secure-os wrote

Adversary in the Middle Phishing: Why 2FA Does Not Stop It (2026)

Sep 3, 2026 in phishing, 2fa, mfa - Adversary in the middle phishing proxies the real login page in real time, so the code from your authenticator app lands in the attacker's hands and the stolen session cookie keeps working after you close the tab. How AiTM works, why one factor type survives it, and what to check.

Read more…
📅 5 min read🛡️ Threat-model-first

secure-os wrote

License Plate Reader Surveillance: What ALPR Records (2026)

Sep 3, 2026 in surveillance, privacy, alpr - Automatic license plate readers photograph every car that passes, not only wanted ones, and keep the plate, the time, the place and often the image. What ALPR collects, how long networks retain it, why a retention period is the real privacy setting, and what you can and cannot do about it.

Read more…
📅 4 min read🛡️ Threat-model-first

Operating systems

Qubes, Tails & Whonix

Which secure OS fits which threat model - compartmentalisation vs amnesic vs Tor-routed.

Read the guides →

Encryption

Full disk encryption

LUKS, BitLocker, FileVault and VeraCrypt - what each protects, and what it does not.

Read the guide →

Hardening

Threat-model-first Linux

Practical hardening built around the adversary you actually face.

Read the guide →