Security, Privacy & Scams
Passwords, phishing, breaches, and how attacks actually work
-
Reuse Is the Real Risk
A reused password turns any one site's breach into access to every account sharing it.
-
Not All Second Factors Are Equal
A second factor sent over SMS can be intercepted or moved to another SIM, while an app code or hardware key cannot.
-
Phishing Targets Urgency
Phishing works by creating time pressure so the recipient acts before verifying.
-
People Are the Attack Surface
Attackers usually persuade someone with access rather than defeat the technology protecting it.
-
Updates Close Known Doors
Most successful attacks use flaws that were fixed some time ago and never applied.
-
Backups Are the Ransomware Answer
A tested, offline backup makes ransomware an inconvenience rather than a decision about paying.
-
What Public Wi-Fi Can See
Encrypted connections hide the content of your traffic, while the sites you visit can still be visible.
-
The Data You Hand Over
Every optional field, permission and connected app widens what is held about you and who holds it.
-
What a Breach Exposes
The damage from a breach depends on what was stored and how, not on the number of records.
-
The Recovery Path Is the Weak Link
An account is only as secure as the process for getting back in when you lose access.
-
Guaranteed Returns Are the Tell
Returns come from taking risk, so a guaranteed high return is a claim that cannot be true.
-
Verify Out of Band
Confirm an unexpected request through a different channel than the one that made it.