Every connection on the internet starts with a DNS lookup, and for most of the internet’s history those lookups have been completely unencrypted. The shift to encrypted DNS — DoH, DoT, ECH — is one of the quieter but most consequential privacy upgrades of the decade.
Jesse William McGraw
Virtual Private Networks are aggressively marketed as solving privacy and security problems they often do not solve. Here is what a VPN actually does, the realistic threat model where it helps, and how to evaluate which providers are credible in 2026.
Even with all cookies blocked and all trackers disabled, the browser leaks enough information to be uniquely identified across the web. Browser fingerprinting is the surveillance technology that makes “private browsing” much less private than the name suggests.
The Right to Be Forgotten gives EU residents a real and unevenly applied power to remove search-engine results about themselves. Here is what the law actually allows, what Google approves and rejects, and the practical steps for filing a delisting request.
The web tracks you in ways that have outgrown the simple cookie. Tracking pixels, postback URLs, server-side conversion APIs, identity graphs, and CNAME cloaking all live alongside browser fingerprinting and the dying third-party cookie. A field guide.
End-to-end encryption is the most important consumer-facing privacy technology of the past decade. It is also widely misunderstood: what it protects, what it does not, how the major messaging apps actually implement it, and where the metadata still leaks.
There are roughly 4,000 data brokers in the United States holding detailed dossiers on virtually every adult. They are largely unregulated, mostly invisible, and surprisingly hard to remove yourself from. Here is how the industry works and the realistic playbook for opting out.
The General Data Protection Regulation took effect in May 2018. Eight years and several billion euros in fines later, the regulation has reshaped the global privacy landscape — though not always in the ways its drafters intended.
Active Directory turns 26 this year, runs identity for nearly every enterprise on the planet, and is the single most-targeted system in modern intrusions. Here is how attackers exploit it and the controls that meaningfully change the equation.
CVSS scores tell you how bad a vulnerability could be in theory. EPSS scores tell you how likely it is to be exploited. KEV tells you it already is. Combining them is how mature security teams prioritise patching.