Practical security / Original explainers
Handle secrets with less risk.
Plain-language field guides for developers and teams. Every guide focuses on decisions you can apply without buying a particular product.
Comparison hub · Reviewed 2026
Compare one-time secret sharing tools
Choose among SecretShare, OneTime Secret, Bitwarden Send, and Yopass using a sourced capability matrix.
Tool guide · 5 min
Encrypted file sharing with one-time links
Understand local file encryption, the 150 MB limit, retrieval, and the risks one-time delivery does not remove.
Tool guide · 4 min
How one-time file downloads work
See why availability checks and confirmed consumption are separate—and what happens after the first retrieval.
Comparison · Reviewed 2026
SecretShare vs OneTime Secret
Compare encryption models, expiration, APIs, branding, and team features using official sources.
Comparison · Reviewed 2026
SecretShare vs Bitwarden Send
Compare account requirements, file limits, recipient controls, and managed Send workflows.
Comparison · Reviewed 2026
SecretShare vs Yopass
Choose between a minimal hosted flow and configurable open-source self-hosting.
Team practice · 3 min
Sharing credentials with contractors
Choose the right channel, limit scope, verify receipt, and close access cleanly.
Cryptography · 3 min
Why keys belong after the URL hash
Understand what browsers send, what servers log, and what fragments do not solve.
Delivery · 3 min
Stopping preview bots from burning one-time links
Design a human-confirmation gate without weakening deletion semantics.
Incident response · 3 min
How to rotate an exposed secret
Contain, replace, verify, revoke, and learn—without causing a second outage.
Decision guide · 3 min
Password manager, vault, or one-time link?
Match the tool to repeat access, automation, audit, and recipient constraints.
Development · 3 min
Handling .env files safely
Prevent local configuration from leaking into Git, chat, logs, and build artifacts.
Infrastructure · 3 min
Safe SSH key handoff
Prefer individual identities, constrain access, and verify before revoking bootstrap credentials.
Cloud security · 3 min
Service-account JSON without the sprawl
Replace long-lived downloaded keys with workload identity wherever possible.
System design · 3 min
Designing expiration and deletion
Separate read-once behavior from time-based expiry and make failure states observable.
Architecture · 3 min
Threat-modeling client-side encryption
See what zero-knowledge architecture protects—and the risks it leaves behind.