Blog
Security writing without the theatre
How attacks really work, which defences are worth your time, and honest notes on what we are building.
Password reuse is the breach that keeps happening to you
Most account takeovers do not start with a clever attack on your account. They start with a leaked password from somewhere else entirely.
Synthesis Security Team · 2026-06-18 · 6 min read
How to read a phishing message before it reads you
Phishing works on timing and emotion far more than on typos. Here is a practical way to check a message in under thirty seconds.
Synthesis Security Team · 2026-05-30 · 7 min read
What end-to-end encryption does not protect
Encryption is not a single property that a product either has or does not have. Knowing where it stops is what makes it useful.
Synthesis Security Team · 2026-05-09 · 8 min read
Documenting online harassment so a report actually goes somewhere
Platform reports and police complaints both fail for the same reason: missing dates, missing context, missing links. Here is what to capture.
Synthesis Security Team · 2026-04-21 · 6 min read
Public Wi-Fi in 2026: what changed and what did not
Almost all traffic is encrypted now, which retires some old advice. A few risks remain, and they are not the ones people worry about.
Synthesis Security Team · 2026-03-28 · 5 min read
Choosing a second factor: SMS, app codes, or hardware
All second factors are better than none, but they fail in different ways. A short comparison to help you pick per account.
Synthesis Security Team · 2026-02-14 · 6 min read