Articles & ideas

Security knowledge you can put to work.

This is the home of my long-form writing on authentication. I translate research into clear explanations, practical choices, and questions worth debating—without losing the technical detail that matters.

Start here

Featured article

New work will be published and maintained here as the primary source. Earlier articles may also link to their LinkedIn edition.

Hardware one-time-password tokens shown with several online services
Research Deep Dive · 9 min read

Why Use SMS OTP—and When Do Hardware Tokens Make Sense?

Follow an SMS code from server to phone, examine channel and phishing risks, and compare it with independent TOTP and HOTP devices.

Read article

The archive

Explore all articles

Follow the series from password fundamentals to multi-factor and phishing-resistant authentication.

Diagram showing how a fake bank site captures a user credential in a phishing attack
Research Deep Dive · 8 min read

Password Manager Risks: How Vaults Are Targeted—and How to Protect Them

A balanced threat analysis of endpoint attacks, synchronized vaults, phishing, and malicious extensions, with practical defenses.

Read article
PwdHash diagram showing a unique password derived for each website
Intermediate · 7 min read

Password Manager Models: Storage, Synchronization, and Store-less Generation

A comparison of local and synchronized vaults with systems that derive site-specific passwords without conventional storage.

Read article
A hardware one-time-password token resting on a computer keyboard
Introduction · 6 min read

Two-Factor Authentication: An Extra Layer That Is Not Always Equal

An introduction to authentication factors and common 2FA methods, separating added protection from genuine phishing resistance.

Read article
Introduction · 5 min read

Password Managers: A Practical Way to Manage Digital Security

Why password managers make unique credentials realistic, plus the benefits and limitations to understand before choosing one.

Read article
Diagram of an online password guessing attack against a login service
Introduction · 6 min read

Passwords: The Foundation of Authentication—and Its Security Limits

How passwords work, why guessing, phishing, and reuse remain dangerous, and which practices reduce those risks.

Read article