Writing about security
Five write-ups on what the standard security advice is actually worth: how long a password really holds, why a passphrase beats a word with symbols jammed into it, what a hash is and is not, how a 2FA code can be right on two devices at once.
What a Hash Function Is, and What It Is Not
A fixed-length fingerprint for any amount of data — useful for exactly three things, and quietly useless for a fourth that people keep trying.
Read SecurityPassword vs Passphrase: Which Is Actually Safer?
Four random words beat a short scrambled password. Four words you chose yourself beat almost nothing.
Read SecurityHow to Send Someone a Password Securely
Never send the secret and the key to it down the same wire. What that looks like in practice, and what it still does not protect you from.
Read SecurityHow Long Would It Take to Crack Your Password?
The honest answer is "it depends who is attacking", and the spread between the best and worst case is about sixteen orders of magnitude.
Read SecurityHow Authenticator App Codes Work (6-Digit TOTP)
Your authenticator app never receives anything. It does the same arithmetic the server does, and the numbers happen to match.
ReadAll categories
Images 6Text 10Design 8Calculators 9Developer 12Everyday 3Time 4