When a screenshot ruins everything: designing secret-sharing workflows that survive human error
End-to-end encryption protects secrets in transit, but it can't stop a recipient from screenshotting a one-time note before it vanishes. Here's how to...
End-to-end encryption protects secrets in transit, but it can't stop a recipient from screenshotting a one-time note before it vanishes. Here's how to...
Not every sensitive secret deserves the same delivery method. Here is a practical framework for matching the right channel to the risk level of what y...
Chat platforms log almost everything, and those logs surface in audits, breaches, and legal discovery. Here is what auditors actually find, and a simp...
A leaked document sent over email or Signal can still leave metadata behind. Here's how reporters and sources can share sensitive material with a smal...
Both options make a secret disappear eventually, but they protect against very different threats. Here's how to choose the right one and why getting i...
SecureNotes keeps the decryption key in the URL fragment so it never reaches the server. Here's the exact mechanism, what it protects against, and the...
Adding a passcode to a self-destructing note sounds like extra security. Sometimes it is. Sometimes it just creates a false sense of safety if you sen...
Every new hire needs a batch of credentials on day one. How you deliver those secrets sets the security tone for their entire tenure — here's how to...
Recovery codes are the last line of defence on any account — and most people share them in the worst possible way. Here's how to think through the r...