Blog
Articles and practical guides about cybersecurity, privacy, surveillance, infrastructure, and technology.
- Cybersecurity
- Privacy
- Technology
- Digital life
Every device records. Every platform profiles. Every system makes assumptions about who you are, what you want, and what you may do next.
Digital Sentry is a small cybersecurity company and the home for our writing, projects, and practical security work.
// What Digital Sentry is
We use Digital Sentry to share what we are learning, building, and thinking about across cybersecurity, privacy, surveillance, and technology. It is also where we offer practical security services.
// Explore Digital Sentry
Everything here follows the same themes: understand technology, protect your privacy, improve security, and share useful work.
Articles and practical guides about cybersecurity, privacy, surveillance, infrastructure, and technology.
Software, security tools, learning platforms, and experiments we are building or documenting.
Practical assessments and technical guidance for organizations that need clearer risk decisions and fewer blind spots.
// Latest posts
Cybersecurity, privacy, infrastructure, technology, and the lessons we find worth sharing.
A field-level look at Lazarus Group, the North Korean state-sponsored threat actor behind some of the largest cyber heists on record. Background, observed TTPs, the major public incidents, and what defenders can actually do about it.
OAuth 2.0 is the backbone of modern delegated authorization, but the spec is large and the failure modes are subtle. The grant types that matter, the token storage decisions that actually keep you safe, the scope designs that survive the test of time, and the operational practices that catch the rest.
Push-based MFA and SMS one-time passwords are vulnerable to phishing and push fatigue. FIDO2 / WebAuthn with hardware-backed credentials is the standard that holds up. What phishing-resistant MFA actually means, how WebAuthn works, where the failure modes still are, and how to roll it out without breaking everything.
// Cybersecurity services
Security assessments, technical risk analysis, and clear guidance grounded in actual exposure—not fear, theater, or generic checklists.