Articles & ideas
Security knowledge you can put to work.
This is the home of my long-form writing on authentication. I translate research into clear explanations, practical choices, and questions worth debating—without losing the technical detail that matters.
Start here
Featured article
New work will be published and maintained here as the primary source. Earlier articles may also link to their LinkedIn edition.

Why Use SMS OTP—and When Do Hardware Tokens Make Sense?
Follow an SMS code from server to phone, examine channel and phishing risks, and compare it with independent TOTP and HOTP devices.
Read articleThe archive
Explore all articles
Follow the series from password fundamentals to multi-factor and phishing-resistant authentication.

Password Manager Risks: How Vaults Are Targeted—and How to Protect Them
A balanced threat analysis of endpoint attacks, synchronized vaults, phishing, and malicious extensions, with practical defenses.
Read article
Password Manager Models: Storage, Synchronization, and Store-less Generation
A comparison of local and synchronized vaults with systems that derive site-specific passwords without conventional storage.
Read article
Two-Factor Authentication: An Extra Layer That Is Not Always Equal
An introduction to authentication factors and common 2FA methods, separating added protection from genuine phishing resistance.
Read articlePassword Managers: A Practical Way to Manage Digital Security
Why password managers make unique credentials realistic, plus the benefits and limitations to understand before choosing one.
Read article
Passwords: The Foundation of Authentication—and Its Security Limits
How passwords work, why guessing, phishing, and reuse remain dangerous, and which practices reduce those risks.
Read article