Glossary
Key security and privacy terms explained clearly, organized by category.
IP Address & Network
- IP Address
-
A unique identifier assigned to every device connected to the internet. There are two types: IPv4 (32-bit, approximately 4.3 billion addresses) and IPv6 (128-bit, virtually unlimited). It is the foundational technology for web communication and network management, essential for identifying communication partners. Country and region-level geolocation can be estimated from an IP address, but pinpointing a personal home address is not possible. Using a VPN or proxy changes the IP address visible to external parties, which helps protect privacy. Understanding the difference between global IPs and private IPs is important for troubleshooting network issues.
- IPv6
-
A next-generation internet protocol designed to solve the IPv4 address exhaustion problem. With a 128-bit address space, it can assign virtually unlimited unique addresses to devices. Privacy extension addresses (RFC 8981) help reduce tracking risks by rotating interface identifiers. A common misconception is that IPv6 is inherently more secure than IPv4, but encryption is handled by upper-layer protocols like TLS, not the IP protocol itself. Adoption is accelerating worldwide, with countries like Japan seeing widespread deployment through IPoE connections that also deliver faster speeds.
- DNS (Domain Name System)
-
A system that translates human-readable domain names (e.g., example.com) into IP addresses that computers can understand. Often compared to a phone book for the internet, DNS queries occur behind the scenes every time you browse the web. Traditional DNS queries are unencrypted, meaning ISPs and network administrators can see which sites you visit. Technologies like DNS over HTTPS (DoH) and DNS over TLS (DoT) address this privacy gap. DNS cache poisoning is an attack technique that can redirect users to fraudulent websites by corrupting cached DNS records.
- GeoIP
-
A technology that estimates approximate geographic location (country, region, city) from an IP address. Widely used for targeted ad delivery, content localization, and fraud detection. Accuracy varies significantly depending on the ISP and database quality - country-level results are almost always correct, while city-level results are no more than rough estimates. A common misconception is that GeoIP can reveal a user's exact street address, but it can only provide rough area estimates. VPN and proxy users will show the location of the exit server rather than their actual location.
- NAT (Network Address Translation)
-
A technology that translates between private and public IP addresses. Widely used in home and office routers, it allows multiple devices to share a single public IP address for internet access, which has been critical for conserving the limited IPv4 address space. A typical household may have dozens of devices sharing one public IP through NAT. While NAT provides a basic layer of security by hiding internal network structure, it is not a substitute for a proper firewall. The transition to IPv6 reduces the need for NAT, as every device can have its own globally unique address.
- DNS Leak
-
A phenomenon where DNS queries bypass the encrypted VPN tunnel and are sent directly to the ISP's DNS servers, exposing your browsing destinations despite using a VPN or proxy. Common causes include misconfigured VPN settings, the operating system's DNS resolution order, or WebRTC leaks. Even premium VPN services can suffer from DNS leaks if the client software is not properly configured. Dedicated leak test tools can detect this issue, and using DNS over HTTPS (DoH) or configuring custom DNS servers within the VPN client are effective countermeasures.
- DNS over HTTPS (DoH)
-
A technology that encrypts DNS queries using the HTTPS protocol, preventing ISPs and network administrators from intercepting or tampering with DNS traffic. Unlike traditional plaintext DNS on port 53, DoH traffic blends in with regular HTTPS traffic on port 443, making it harder to block or filter. Major browsers including Chrome, Firefox, and Edge now support DoH by default. A related technology, DNS over TLS (DoT), provides similar encryption but uses a dedicated port (853), making it easier to identify and potentially block. Both are effective privacy measures against DNS-based surveillance.
- DHCP (Dynamic Host Configuration Protocol)
-
A protocol that automatically assigns configuration details such as IP address, subnet mask, default gateway, and DNS server to devices joining a network. It eliminates the need for manual setup and enables efficient IP address management across networks of any size. Most home routers have a built-in DHCP server that handles this automatically. In enterprise environments, DHCP servers manage thousands of IP address leases with configurable lease durations. A common misconception is that DHCP assigns permanent addresses - in reality, addresses are leased for a set period and may change upon renewal, which is why static IP configuration is preferred for servers.
- Router
-
A networking device that controls data transfer between networks. In homes, Wi-Fi routers connect the internet to household devices. NAT allows multiple devices to share one global IP address, and the built-in firewall blocks unauthorized external access. Firmware updates and changing the admin password are essential security measures.
- Wi-Fi
-
A brand name for wireless LAN communication standards. Based on IEEE 802.11, it connects devices to the internet through a router. Used everywhere from homes to offices and cafes. Public Wi-Fi is convenient but carries risks of eavesdropping and fake access points, so using a VPN is recommended.
- ISP (Internet Service Provider)
-
A company that provides internet access to individuals and businesses. ISPs handle IP address assignment, DNS server provision, and traffic routing, forming the backbone of internet connectivity. Connection types include fiber optic (FTTH), cable (CATV), mobile (4G/5G), and DSL, each with different speed and reliability characteristics. While ISPs are legally obligated to protect communication privacy, they can technically observe destination domains and connection timestamps. Using a VPN or DNS over HTTPS can minimize the information visible to your ISP.
- BGP (Border Gateway Protocol)
-
A protocol used by different networks (autonomous systems, or ASes) on the internet to exchange routing information. With tens of thousands of ASes interconnected, BGP determines the path packets take to reach their destination. By design, BGP lacks built-in verification of route advertisement legitimacy, making it vulnerable to BGP hijacking attacks where traffic is misdirected. RPKI provides cryptographic verification of route origins as a countermeasure, but prefixes without a ROA fall outside those checks, so it does not deliver complete protection.
- Latency
-
The time delay between sending data and it reaching its destination, measured in milliseconds (ms). Lower values mean faster response. Physical distance, the number of routers traversed, and server processing time are the primary factors. Latency is independent of bandwidth; even a high-speed connection will have high latency to a distant server. Reducing latency is critical for real-time applications such as online gaming, video conferencing, and live streaming, where CDNs and edge computing are commonly employed.
- Port Number
-
A numerical identifier ranging from 0 to 65535 used to distinguish applications and services in network communication. If an IP address is a building address, a port number is the room number. Major protocols have assigned well-known ports: HTTP uses 80, HTTPS uses 443, and SSH uses 22. Firewall-based port control is fundamental to network security, and closing unnecessary ports directly reduces the attack surface.
- CIDR
-
A notation for flexibly specifying the boundary between network and host portions of an IP address. Written as an IP address followed by a slash and prefix length (e.g., 192.168.1.0/24). Introduced in 1993 to replace the inefficient classful addressing system, CIDR reduced IP address waste and routing table bloat. /24 covers 254 addresses, /16 about 65,000, and /8 about 16.7 million. Essential knowledge for AWS security groups, VPC design, and modern network engineering.
VPN & Proxy
- VPN (Virtual Private Network)
-
A technology that encrypts internet traffic and routes it through a server in another location, protecting your real IP address and communication content. Effective for securing public Wi-Fi connections and bypassing geographic restrictions, though the trustworthiness of the VPN provider is crucial since they can see your traffic. A common misconception is that VPNs make you completely anonymous online, but they only shift trust from your ISP to the VPN provider. Free VPN services often monetize user data, so paid services with independently audited no-log policies are recommended. Related technologies include proxy servers and Tor for different anonymity needs.
- Proxy Server
-
A server positioned between the client and the internet that relays communications on behalf of the user. Used for hiding IP addresses, content filtering, and caching to improve performance. Unlike VPNs, proxy servers typically do not encrypt all traffic, offering only limited security protection for the specific application configured to use them. HTTP proxies handle web traffic only, while SOCKS proxies can relay any TCP/UDP traffic. In corporate environments, forward proxies are commonly used to enforce web access policies and log employee browsing activity.
- Tor (The Onion Router)
-
A network that achieves high anonymity by routing communications through multiple relay servers (typically three) with multi-layered encryption. Each relay only knows the previous and next hop in the circuit, making it extremely difficult to link the sender and destination. Communication speed is significantly reduced due to the multi-hop routing, with typical latencies of 200-500ms. Tor is widely used by journalists, activists, and privacy-conscious individuals, but it also hosts hidden services (.onion sites) on the dark web. Exit node operators can potentially see unencrypted traffic, so using HTTPS within Tor is still recommended.
- VPN Kill Switch
-
A safety mechanism that automatically blocks all internet traffic if the VPN connection drops unexpectedly, preventing your real IP address from being exposed even momentarily. Without a kill switch, brief VPN disconnections during network switches or server issues can leak your actual IP address and DNS queries. This feature is especially critical when using public Wi-Fi or in situations where IP exposure poses a real risk. Most reputable VPN services include both system-level and application-level kill switches. Testing the kill switch by manually disconnecting the VPN server is a recommended verification step.
- VPN Protocol
-
A set of rules that defines how a VPN connection is established and how data is encrypted during transmission. WireGuard is the newest option, offering fast speeds and a minimal codebase of around 4,000 lines that simplifies security auditing. OpenVPN provides high compatibility and a proven track record over two decades. IPsec/IKEv2 excels in stability on mobile devices, seamlessly handling network switches between Wi-Fi and cellular. A common misconception is that all VPN protocols offer equal security - older protocols like PPTP are considered broken and should never be used. The choice of protocol directly impacts both performance and security.
- Split Tunneling
-
A VPN technique that routes only specific application or destination traffic through the encrypted VPN tunnel while sending everything else over the regular internet connection. This enables efficient bandwidth usage, faster speeds for non-sensitive activities, and continued access to local network resources like printers and NAS devices. For example, you might route your web browser through the VPN while allowing video streaming to use the direct connection. However, misconfiguration can introduce privacy risks by accidentally sending sensitive traffic outside the tunnel. Some VPN clients offer app-based or URL-based split tunneling for granular control.
- SOCKS Proxy
-
A general-purpose proxy protocol that operates at the session layer (Layer 5) of the OSI model. Unlike HTTP proxies that only handle web traffic, SOCKS can relay arbitrary TCP and UDP traffic, making it versatile for applications like torrenting, gaming, and messaging. SOCKS5, the latest version, supports authentication and UDP forwarding, and is commonly used for local connections to the Tor network. A key limitation is that SOCKS proxies do not encrypt traffic by themselves - they simply relay it. For encrypted proxying, SOCKS5 is often combined with SSH tunneling or used alongside other encryption layers.
- Obfuscation (VPN)
-
A technique that conceals the protocol-specific characteristics of VPN traffic to evade detection by Deep Packet Inspection (DPI) systems. Some methods make traffic look like regular HTTPS, while others transform it into random byte sequences with no identifiable pattern. This is essential in environments where VPN usage itself is restricted or blocked, such as certain countries with internet censorship or corporate networks with strict traffic policies. Well-known implementations include obfs4 (developed by the Tor Project), Shadowsocks (widely used in China), and various proprietary stealth protocols offered by VPN providers. The effectiveness of obfuscation varies as DPI technology continues to evolve, creating an ongoing cat-and-mouse dynamic between censors and privacy tools.
Browser & Tracking
- Cookie
-
A small data file stored in the browser by a website to remember user preferences and session state. First-party cookies are essential for maintaining login sessions and saving settings, while third-party cookies enable cross-site behavioral tracking by ad networks. Safari blocks third-party cookies by default and Firefox isolates them per site with Total Cookie Protection, while Google Chrome abandoned its deprecation plan and confirmed in April 2025 that it would keep them. A common misconception is that deleting cookies makes you untraceable, but techniques like browser fingerprinting can identify users without any cookies. The EU's GDPR and ePrivacy Directive require explicit consent before setting non-essential cookies.
- Browser Fingerprint
-
A technique that identifies and tracks users based on unique combinations of browser settings, installed plugins, screen resolution, fonts, GPU renderer, and other attributes. Since tracking is possible even after deleting cookies or using incognito mode, it has drawn significant attention as a persistent privacy threat. Canvas fingerprinting and AudioContext fingerprinting extract hardware-specific rendering differences for high-accuracy identification. In the initial study of the EFF's Panopticlick project, launched in 2010, 83.6% of the browsers that visited the project had a fingerprint that was unique at that time. Countermeasures include using Tor Browser (which normalizes fingerprint attributes), privacy-focused browsers like Brave (which instead varies attribute values per site and per session), or dedicated extensions like CanvasBlocker.
- WebRTC
-
A browser technology that enables real-time peer-to-peer audio, video, and data communication without plugins. Widely used for video conferencing (Google Meet, Zoom web client), file sharing, and online gaming. However, WebRTC can leak local and public IP addresses even when using a VPN, as it uses STUN/TURN servers to establish direct connections. This WebRTC leak is a well-known privacy issue that can expose your real IP address. The scope of what you can configure differs by browser, so mitigation means combining browser-side settings or an extension that limits ICE Candidate gathering with a VPN client that includes built-in WebRTC leak protection.
- Do Not Track (DNT)
-
An HTTP header setting that tells websites "please do not track me" from the browser side. It carries no legal force, however, and whether a site honors the request is left to each site's discretion. The W3C ended its standardization work in January 2019, and Apple Safari removed the feature entirely. GPC (Global Privacy Control), proposed in 2020, is regarded as its successor and has legal backing under California state law, but effective tracking prevention still requires combining it with ad blockers and the browser's own tracking protection.
- Tracking Pixel
-
A transparent 1x1 pixel image (also called a web beacon or pixel tag) embedded in web pages or HTML emails. When loaded, it sends a request to a tracking server, recording the viewer's IP address, access time, device information, and whether an email was opened. Widely used for measuring email campaign open rates, ad conversion tracking, and retargeting audiences. Unlike cookies, tracking pixels work across different browsers and devices. Countermeasures include disabling automatic image loading in email clients, using privacy-focused email services that proxy remote images, and browser extensions that block known tracking domains.
- Browser Isolation
-
A security technology that separates web content rendering from the user's endpoint device and executes it in a secure, isolated environment. Remote Browser Isolation (RBI) renders web pages in a cloud-based virtual container and streams only the visual output (pixels or DOM commands) to the user's browser, preventing malware, exploits, and malicious scripts from reaching the local system. This approach is particularly effective against zero-day browser vulnerabilities and drive-by download attacks. Enterprises adopt it to protect against web-based threats without restricting employee internet access.
- Third-Party Cookie
-
A cookie set by a domain different from the website the user is currently visiting, typically placed by embedded ad networks, social media widgets, or analytics services. These cookies enable cross-site tracking, allowing advertisers to build detailed user profiles across multiple websites. Safari blocks them outright by default and Firefox isolates them per site with Total Cookie Protection, but Chrome reversed its phase-out plan in 2024 and confirmed in April 2025 that it would keep them; Google also announced the retirement of the main Privacy Sandbox APIs (such as Topics) in October 2025. Contextual advertising and first-party data are the main replacements the industry relies on. Understanding the difference between first-party and third-party cookies is essential for grasping modern web privacy dynamics.
- Canvas Fingerprint
-
A browser fingerprinting technique that draws invisible graphics (text, shapes, gradients) on an HTML5 Canvas element and generates a hash from the resulting pixel data. Subtle differences in GPU hardware, graphics drivers, operating system font rendering, and anti-aliasing algorithms produce unique output for each device configuration, enabling high-accuracy browser identification. CanvasBlocker extensions counter this by injecting random noise into the Canvas output. Related techniques include WebGL fingerprinting, which extracts even more hardware-specific rendering information.
- URL
-
A string that serves as the address of a web page. Composed of a scheme (https://), domain name, and path. The most important clue for judging link safety. Phishing attacks often use URLs with subtly altered domain names, so verifying the domain before clicking is essential. URLs may also contain query parameters for tracking and fragment identifiers for linking to specific page sections.
- Browser
-
An application for displaying web pages. Interprets HTML, CSS, and JavaScript from servers and renders them visually. Chrome, Safari, Edge, and Firefox are the most popular. Modern browsers include privacy features such as incognito mode, cookie management, and built-in password managers, making them the primary gateway to the internet.
- Domain
-
The name of a website (e.g., example.com). Converted to an IP address by DNS. Checking the domain name is the most important step in identifying fake websites. Domains are registered through registrars and maintained with annual fees. Understanding the structure of top-level domains (.com, .org, .jp) and subdomains helps assess the trustworthiness of a site.
- QR Code
-
A two-dimensional matrix barcode developed by Denso Wave in 1994. It can store thousands of characters in a small area by encoding data in both horizontal and vertical directions. The structure consists of finder patterns, version information, Reed-Solomon error correction codes, and data regions. While widely used for payments, URL sharing, and ticketing, it has also become a vehicle for QR phishing (Quishing). Attackers embed malicious URLs in QR codes to redirect users to phishing sites. Since the encoded content cannot be visually inspected before scanning, verifying the URL after scanning is the most effective countermeasure.
Authentication & Password
- Two-Factor Authentication (2FA)
-
A security method that requires an additional authentication factor beyond a password, such as an SMS code, authenticator app, or physical security key. Even if a password is compromised through phishing or a data breach, 2FA prevents unauthorized access by requiring something the attacker does not possess. TOTP-based authenticator apps (Google Authenticator, Authy) are more secure than SMS codes, which are vulnerable to SIM swap attacks. FIDO2 hardware security keys like YubiKey offer the strongest protection with built-in phishing resistance. Enabling 2FA on email and financial accounts should be considered a baseline security practice.
- Passkey
-
A passwordless authentication technology based on the FIDO2/WebAuthn standard that uses public key cryptography for login. Users authenticate via biometrics (fingerprint, face recognition) or device PIN, eliminating the need to remember or manage passwords entirely. Passkeys are inherently phishing-resistant because the cryptographic challenge is bound to the specific website domain, making credential theft through fake login pages impossible. Apple, Google, and Microsoft have all integrated passkey support into their platforms, enabling cross-device synchronization.
- Password Manager
-
A tool that generates, securely stores, and auto-fills complex, unique passwords for every online account. All credentials are protected by a single master password and encrypted using algorithms like AES-256. Password managers eliminate the dangerous practice of password reuse, which is the root cause of credential stuffing attacks. Leading options include 1Password, Bitwarden, and KeePass. A common misconception is that storing all passwords in one place creates a single point of failure, but the encryption and zero-knowledge architecture of reputable managers make them far more secure than reusing memorable passwords across sites.
- Credential Stuffing
-
An automated attack that takes leaked username and password combinations from past data breaches and systematically tries them on other services, exploiting the widespread habit of password reuse. With billions of credentials available on the dark web, attackers use botnets to test thousands of combinations per minute across banking, email, and social media platforms. The success rate of any single attempt is low, but automation pushes the cost per attempt close to zero, so even a small share of hits produces a large absolute number of compromised accounts. Using a unique password for each service and enabling two-factor authentication are the practical baseline defenses against this attack.
- TOTP (Time-Based One-Time Password)
-
An algorithm defined in RFC 6238 that generates a new 6-digit one-time password every 30 seconds based on the current time and a shared secret key. Used by authenticator apps such as Google Authenticator, Authy, and Microsoft Authenticator as a second factor for login. TOTP is significantly more secure than SMS-based verification codes because it is immune to SIM swap attacks and SS7 network vulnerabilities. The shared secret is established during initial setup via a QR code. A common pitfall is losing access to the authenticator app without backup codes, which can result in permanent account lockout.
- Single Sign-On (SSO)
-
A mechanism that allows users to access multiple related services and applications with a single authentication event, eliminating the need to log in separately to each system. Protocols like SAML 2.0 and OpenID Connect enable SSO across different platforms and organizations. While SSO dramatically improves user convenience and reduces password fatigue, it creates a critical dependency - if the SSO identity provider is compromised, all linked services become vulnerable. Enterprise SSO solutions like Okta and Microsoft Entra ID (renamed from Azure AD in July 2023) typically combine SSO with multi-factor authentication and conditional access policies to mitigate this risk.
- Brute Force Attack
-
An attack method that systematically tries every possible combination of characters to guess a password or encryption key. In an offline attack against a leaked password hash, a GPU can test candidates against fast hashes such as MD5 or SHA-1 at enormous rates, so a 6-character password falls almost immediately; online login attempts, by contrast, are held back by rate limiting and account lockout. Increasing password length to 12+ characters with mixed character types makes brute force computationally infeasible with current technology. Dictionary attacks, a variant that tries common words and known passwords first, are even more efficient. Effective defenses include account lockout policies, progressive rate limiting, CAPTCHA challenges, and using bcrypt or Argon2 for password hashing with high work factors.
- OAuth 2.0
-
An authorization framework (RFC 6749) that grants third-party applications limited access to user resources without sharing the user's password. It is the underlying technology behind social login buttons like 'Sign in with Google' or 'Sign in with GitHub.' OAuth 2.0 defines several grant types for different scenarios: authorization code flow for web apps, PKCE for mobile apps, and client credentials for server-to-server communication. A common misconception is that OAuth is an authentication protocol - it is strictly an authorization framework. For authentication, it is typically combined with OpenID Connect (OIDC), which adds an identity layer on top of OAuth 2.0.
Privacy & Data Protection
- Digital Footprint
-
The collective traces left by all online activity, encompassing both active footprints (social media posts, comments, reviews) and passive footprints (search history, browsing patterns, purchase records, location data). Every website visit, app interaction, and online transaction contributes to a digital profile that can be aggregated by data brokers and advertisers. Once information is published online, completely removing it is extremely difficult due to web archives, screenshots, and data sharing between services. Regular auditing of privacy settings, using search engines to check your own digital footprint, and practicing data minimization are essential for ongoing management.
- Metadata
-
Data that describes other data, providing context about how, when, where, and by whom information was created or modified. Photo Exif data can reveal the exact GPS coordinates, date, camera model, and even lens settings used. Email headers expose sender IP addresses, relay server paths, and timestamps. Document properties may contain author names, organization details, and complete edit histories. Metadata often reveals more sensitive personal information than the content itself - a photo's Exif data can pinpoint your home location even if the image shows nothing identifiable. Stripping metadata before sharing files is an important privacy practice that many users overlook.
- GDPR (General Data Protection Regulation)
-
The European Union's comprehensive regulation governing the protection of personal data, effective since May 2018. It requires explicit consent for data collection and processing, guarantees the right to be forgotten (data erasure) and data portability, and mandates breach notification within 72 hours. Violations can result in fines of up to 4% of global annual revenue or 20 million euros, whichever is higher - Meta was fined 1.2 billion euros in 2023 for data transfer violations. The GDPR has influenced privacy legislation worldwide, including Brazil's LGPD, California's CCPA, and Japan's amended APPI. Any organization processing the data of individuals in the EU must comply, regardless of where the organization is based.
- Privacy-Focused Search Engine
-
A search engine designed to protect user privacy by not collecting, storing, or tracking search history or building user profiles. DuckDuckGo, Startpage (which proxies Google results), and Brave Search are the leading examples. While search results are not personalized, this actually helps users avoid filter bubbles - the phenomenon where personalized results reinforce existing beliefs and limit exposure to diverse viewpoints. A common misconception is that privacy search engines deliver inferior results, but modern privacy engines have significantly improved their relevance algorithms. They generate revenue through contextual advertising based on the current search query rather than user profiles.
- Act on the Protection of Personal Information (APPI)
-
Japan's primary law governing the proper handling of personal information by businesses and organizations. It requires entities handling personal data to clearly specify the purpose of use, implement appropriate security measures, and restrict third-party disclosure without consent. The 2020 amendment, in force from April 2022, significantly expanded individual rights, including the right to request data deletion, strengthened breach reporting obligations, requiring a preliminary report to the Personal Information Protection Commission within roughly 3-5 days and a final report within 30 days, and increased penalties for violations. The APPI applies to all businesses handling personal information in Japan, regardless of company size, making it one of Asia's most comprehensive data protection frameworks.
- Data Minimization Principle
-
A foundational privacy principle stating that organizations should collect and process only the minimum amount of personal data strictly necessary to achieve a specific, stated purpose. Enshrined as one of the seven core principles of the GDPR (Article 5), it serves as a check against excessive data collection practices. For example, an e-commerce site should not require a date of birth if it is not needed for the transaction. Closely related to the concept of Privacy by Design, which embeds data minimization into system architecture from the outset rather than adding it as an afterthought. Implementing this principle reduces both the attack surface for data breaches and the compliance burden for organizations.
- Social Media Privacy Settings
-
A set of controls on social media platforms that govern the visibility of personal information, posts, and activity to different audiences. Properly managing settings for profile details, post visibility, location sharing, tagging permissions, and search engine indexing helps prevent unintended information exposure. Platforms frequently update their privacy interfaces and sometimes reset settings during major updates, so periodic reviews are essential. A common oversight is leaving old posts publicly visible - most platforms offer tools to bulk-restrict past posts. Understanding the difference between 'public,' 'friends,' and 'only me' visibility levels, and applying them consistently, is the foundation of social media privacy management.
- Safe Online Shopping Practices
-
Practical security measures to protect personal and payment information when making purchases on e-commerce sites. The fundamentals include verifying HTTPS connections (lock icon in the address bar), using trusted and well-known payment methods, and avoiding deals that seem too good to be true on unfamiliar sites. Virtual credit card numbers, offered by many banks and services, generate temporary card details for each transaction, limiting exposure if a merchant is compromised. One-time passwords and biometric payment confirmation add additional layers of security. Checking seller reviews, being cautious of phishing emails disguised as shipping notifications, and monitoring bank statements regularly are also important habits.
Encryption & Secure Communication
- TLS/SSL
-
Cryptographic protocols that encrypt internet communications to ensure confidentiality and integrity. SSL (Secure Sockets Layer) is the deprecated predecessor that TLS (Transport Layer Security) replaced as the standard. TLS is used for HTTPS website connections, email transmission (STARTTLS), and VPN communications. TLS 1.3, released in 2018, reduced the handshake from two round trips to one, improving both speed and security while removing support for weak cipher suites. A common misconception is that SSL and TLS are interchangeable terms - SSL 3.0 has known vulnerabilities (POODLE attack) and should never be used. TLS 1.0 and 1.1 were disabled by default in major browsers in 2020 and RFC 8996 prohibited their use in 2021, so websites should enforce TLS 1.2 or higher as the minimum supported version.
- End-to-End Encryption (E2EE)
-
An encryption method where data is encrypted on the sender's device and can only be decrypted by the intended recipient, ensuring that no third party - including the service provider, network operators, or government agencies - can access the communication content. Adopted by messaging apps like Signal (which pioneered the Signal Protocol), WhatsApp, and email services like Proton Mail. A common misconception is that E2EE protects metadata - while message content is encrypted, information about who communicated with whom and when is often still visible to the service provider.
- HTTPS
-
A protocol that adds TLS encryption to HTTP, securing communication between the browser and web server to prevent eavesdropping, tampering, and impersonation. Identifiable by the padlock icon in the browser's address bar, HTTPS is the norm for the vast majority of websites as of 2026. Google has stated since 2014 that it uses HTTPS as a ranking signal for search results, and Chrome and other major browsers label HTTP-only sites as "Not secure". A common misconception is that HTTPS guarantees a website is safe - it only ensures the connection is encrypted, not that the site itself is legitimate. Phishing sites frequently use HTTPS to appear trustworthy. Let's Encrypt has made free TLS certificates widely accessible, driving universal adoption.
- Firewall
-
A security mechanism placed at network boundaries that inspects and controls incoming and outgoing traffic based on predefined security rules. Types include packet filtering (examines individual packets), stateful inspection (tracks connection states), and application-layer gateways (inspect application-specific data). Next-generation firewalls (NGFWs) combine traditional filtering with deep packet inspection, intrusion prevention, and application awareness. Firewalls serve as the first line of defense against unauthorized access and malware intrusion, but they cannot protect against threats that bypass the network perimeter, such as phishing emails or insider threats. Both hardware and software firewalls play complementary roles in a defense-in-depth strategy.
- Public Key Cryptography
-
A cryptographic method that uses a mathematically linked pair of keys - a public key (shared openly) and a private key (kept secret) - for encryption and decryption. Data encrypted with the public key can only be decrypted with the corresponding private key, and vice versa. This asymmetric approach solves the key distribution problem that plagued symmetric encryption. It underpins virtually all modern internet security: TLS key exchange for HTTPS, digital signatures for software verification, SSH for secure remote access, and passkey authentication. RSA and elliptic curve cryptography (ECC) are the most widely used algorithms, with ECC offering equivalent security at smaller key sizes.
- Digital Certificate
-
An electronic document issued by a trusted Certificate Authority (CA) that binds a public key to the identity of a website, organization, or individual. Browsers validate certificates to confirm the authenticity of HTTPS connections - if a certificate is expired, self-signed, or issued by an untrusted CA, the browser displays a security warning. There are three validation levels: Domain Validation (DV), Organization Validation (OV), and Extended Validation (EV). Let's Encrypt revolutionized the ecosystem by offering free DV certificates with automated renewal, driving HTTPS adoption from under 40% to over 95% of web traffic. Certificate Transparency logs provide public auditability of all issued certificates.
- Encrypted Email
-
A technology that encrypts email body text and attachments so that only the sender and intended recipient can read the content, protecting against interception during transit and unauthorized access on mail servers. Proton Mail and Tuta (formerly Tutanota) offer end-to-end encryption by default with zero-knowledge architecture. Manual encryption via PGP/GPG provides strong protection but requires complex key management that limits mainstream adoption. S/MIME is another standard supported by enterprise email clients. A common misconception is that standard email providers like Gmail encrypt emails end-to-end - they encrypt in transit (TLS) but can still access message content on their servers.
- Security Header
-
HTTP response headers sent by a web server that instruct the browser to enforce specific security policies, forming a critical layer of defense for web applications. Content-Security-Policy (CSP) restricts which resources can be loaded, mitigating XSS attacks. Strict-Transport-Security (HSTS) forces HTTPS connections. X-Frame-Options prevents clickjacking by controlling iframe embedding. X-Content-Type-Options stops MIME type sniffing. Referrer-Policy controls how much referrer information is shared. Properly configuring security headers is one of the most cost-effective security improvements for any website. Tools like securityheaders.com can scan and grade a site's header configuration.
- Encryption
-
A technology that converts data into a format unreadable by third parties. There are two types: symmetric-key encryption (e.g., AES) and public-key encryption (e.g., RSA). Used in HTTPS, end-to-end encrypted messaging, and disk encryption, it is a foundational technology of modern digital security. Encrypted data cannot be decrypted without the correct key. The longer the key length in bits, the harder it is to break, and AES-256 is widely adopted. Encryption protects the confidentiality of data, but ensuring integrity and authentication requires separate mechanisms such as hashing and digital signatures.
- SSH (Secure Shell)
-
An encrypted network protocol for securely connecting to remote computers. SSH encrypts all communication, preventing eavesdropping on passwords and commands. Public key authentication virtually eliminates brute-force attacks, and port forwarding enables secure tunneling of other protocols through the SSH connection. Used extensively for server administration, Git repository access, CI/CD pipelines, and file transfers via SCP/SFTP. The default port is 22.
- Hash Function
-
A one-way function that converts arbitrary-length data into a fixed-length hash value. The same input always produces the same output, but reversing the process is computationally infeasible. MD5 and SHA-1 have broken collision resistance; SHA-256 is the current standard for general-purpose hashing. Password storage requires intentionally slow algorithms like bcrypt or Argon2 with salting to defeat rainbow table attacks. In blockchain, SHA-256 underpins block chaining and Proof of Work mining.
- Certificate Authority (CA)
-
An organization that issues and manages digital certificates. In HTTPS communication, a CA verifies that the applicant is the legitimate administrator of a domain and digitally signs a certificate binding the public key to the domain name. Browsers contain a built-in list of trusted CAs (root store) and only accept certificates signed by CAs in that list. Certificates are classified into DV, OV, and EV based on verification rigor. Let's Encrypt, launched in 2015, accelerated HTTPS adoption by providing free automated DV certificates. The 2011 DigiNotar incident led to the development of Certificate Transparency (CT), a system for detecting fraudulently issued certificates.
- HTTP Header
-
Metadata exchanged between clients and servers during HTTP communication, separate from the message body. Request headers convey browser type, accepted content types, and authentication tokens to the server, while response headers specify content type, caching policies, and security directives to the browser. Security-related headers such as CSP, HSTS, X-Frame-Options, and X-Content-Type-Options control browser behavior to mitigate XSS, clickjacking, and MIME-type sniffing attacks. Cache-control headers (Cache-Control, ETag) affect both performance and security, and privacy headers (Referrer-Policy, Permissions-Policy) prevent user tracking and unauthorized access to device features.
Cyber Threats & Countermeasures
- Phishing
-
An attack in which criminals impersonate a legitimate organization or person to steal passwords, credit card numbers, and other sensitive data. Email, SMS (smishing), and fake websites are among the many channels used. The main defenses are checking the URL, verifying the sender, and enabling two-factor authentication. Some phishing emails are written with generative AI, so awkward wording alone is not enough to spot them. Hovering over a link to check where it goes, and opening the official app directly instead, are habits that prevent damage. In companies, regular phishing drills are effective at raising staff awareness.
- Ransomware
-
Malware that encrypts the files on an infected device and demands a ransom (usually in cryptocurrency such as Bitcoin) in exchange for decryption. It spreads through email attachments and the exploitation of vulnerabilities. Regular backups, keeping the OS and software updated, and avoiding the execution of suspicious files are the key preventive measures. Paying the ransom does not guarantee that a decryption key will be provided, and the payment funds criminal organizations, so it is not recommended. Double extortion ransomware not only encrypts data but also uses the threat of publishing stolen data as leverage. Keeping offline backups is the last line of defense.
- Social Engineering
-
An attack technique that extracts information by exploiting human psychological weaknesses instead of technical means. Attackers rely on levers such as deference to authority, manufactured urgency, and the exploitation of goodwill. Because technical controls alone cannot stop it, raising security awareness is indispensable. Typical approaches include an urgent payment request that appears to come from a manager, or a password check from someone claiming to be in the IT department. It is carried out through every available channel: phone, email, face-to-face contact, and social media. For organizations, the core of the defense is to combine regular security training with simulated attack exercises, measuring how well people respond and improving continuously.
- Zero-Day Attack
-
An attack that exploits a software vulnerability while no fix for it is available. The term zero-day points to the fact that the vendor has had no time to prepare a patch, so the basic defense of applying an update cannot be used. That leaves layered controls, plus detection and response that assume a breach, as the core of any preparation. Zero-day vulnerabilities change hands through several routes, from legitimate bug bounty programs to non-public markets, and they appear disproportionately in state-linked operations and advanced persistent threats (APT). Endpoint detection and response (EDR) offers a way to spot signs of compromise from the unusual behavior that follows exploitation. Attacks continue after a patch becomes public, because the fix itself can be analyzed, so how quickly you can deploy an update belongs in the same discussion as the countermeasures.
- Deepfake
-
A technique that uses deep learning to synthesize or alter a person's face and voice with high fidelity. The fake video and audio it produces are abused for impersonation and for spreading disinformation. In a case reported in 2019, a UK subsidiary wired roughly USD 240,000 (EUR 220,000) after receiving a call that imitated the voice of the CEO at its German parent company. Unnatural blinking and blurred outlines were useful clues in early synthetic footage, but improved generation quality has made judgment by eye unreliable. Detection tools do not settle authenticity either, since they only report a confidence level, so payments and identity checks must not rest on the content of a call alone and should assume verification through a separate channel. A threat that also reaches identity verification over video calls.
- Supply Chain Attack
-
An attack technique that intervenes in the software development and distribution process to inject malware into legitimate updates or dependency libraries. Because it arrives by way of trusted software, detection is difficult and the damage reaches a wide range of organizations. In the SolarWinds incident disclosed in December 2020, up to 18,000 customer organizations are said to have downloaded the tampered update, according to the company's own disclosure. Publishing malicious packages to package registries such as npm and PyPI has also been observed. Tools that automatically scan open-source dependencies, such as Dependabot and Snyk, are effective countermeasures. Verifying software signatures and ensuring reproducible builds also serve as defenses.
- DDoS Attack
-
An attack that sends requests simultaneously from a large number of computers to a target server or network and leaves the service unusable. Groups of infected devices known as botnets are often used to carry it out. CDNs, rate limiting, and anomaly detection through traffic analysis are the main defenses. CISA alert TA16-288A in the United States records an attack exceeding 620 Gbps in September 2016 that was generated by Mirai, a botnet of IoT devices. Services that carry out DDoS attacks on request, calling themselves booters or stressers, also exist, and the fact that an attack can be ordered without technical knowledge is treated as a problem. Combining a cloud mitigation service with rate limiting on your own side is the practical way to defend.
- Man-in-the-Middle Attack (MITM)
-
An attack in which an adversary inserts itself between two communicating parties to intercept or alter their traffic. The entry points are techniques that seize a relay point on the path, such as ARP spoofing, DNS spoofing, and rogue access points (Evil Twin). Where HTTPS is the default, reading the payload itself is difficult, so the focus has shifted to downgrading to unencrypted HTTP (SSL stripping), luring users to lookalike domains, and observing metadata such as which sites are being visited. Defense rests on encryption plus authentication of the other party: HSTS to block downgrades, a practice of never clicking through certificate warnings, and a VPN on public Wi-Fi.
- Data Breach
-
An incident in which personal information or confidential data held by an organization is exposed to parties without authorization through unauthorized access, insider misconduct, or misconfiguration. Leaked credentials are traded on the dark web and abused in secondary attacks such as credential stuffing. Prompt password changes and establishing the scope of exposure are the core of first response. Checking periodically on Have I Been Pwned whether your email address appears in breach lists is recommended. Under Japan's Act on the Protection of Personal Information (amended in 2020, in force from April 2022), reporting to the Personal Information Protection Commission and notifying the affected individuals are mandatory when a leak meets defined conditions, such as involving sensitive personal information or affecting more than 1,000 individuals.
- Digital Identity Theft
-
A crime in which someone illegally obtains another person's personal information and impersonates them to gain money or abuse services. Phishing, data breaches, and social engineering are the main methods. To notice the damage early, requesting disclosure of your own records from credit reporting agencies and watching for anomaly alerts on your accounts both help. If you are hit, the first steps are changing the affected passwords immediately, contacting your financial institutions, and filing a report with the police. Stolen information is combined with names and addresses, traded on the dark web, and sometimes abused only after a long delay.
- Malware
-
Malware, short for malicious software, is an umbrella term for any software intentionally designed to cause damage to computers, networks, or users. Common types include viruses, worms, trojans, ransomware, spyware, and adware. It spreads through email attachments, compromised websites, fake installers, and USB drives, and can lead to stolen or destroyed data and to ransom demands backed by file encryption. The basics still carry most of the weight: apply operating system and application updates regularly, avoid opening suspicious links and files, and install security software. Even so, fileless malware runs only in memory and leaves no executable on disk, slipping past detection that assumes there is a file to scan, so an installed security product is not the same thing as being safe.
- Botnet
-
A network of many computers and IoT devices that are infected with malware and operated remotely from an attacker's C&C server. Botnets are abused for DDoS attacks, spam distribution, credential stuffing, and cryptocurrency mining. The Mirai botnet of 2016 spread to hundreds of thousands of devices by exploiting default passwords on IoT equipment, and on October 21 of that year the DNS provider Dyn was attacked, leaving Twitter, Netflix, and many other services unreachable. Updating firmware, changing default passwords, closing unnecessary ports, and monitoring network traffic are effective countermeasures.
- Spam
-
Unsolicited messages sent in bulk without the recipient's consent. Spam arrives via email, SMS, social media, forums, and comment sections. Kaspersky's spam and phishing report for 2025 put the average share of spam in global email traffic at 44.99%, and spam also serves as a distribution channel for phishing and malware. Key countermeasures include SPF, DKIM, and DMARC email authentication, Bayesian filtering, and real-time blacklists. Google has required senders of more than 5,000 messages a day to Gmail addresses to authenticate their email since February 2024, and Yahoo introduced comparable requirements in the first quarter of 2024.
- Bot
-
A software program that performs automated tasks without human intervention. The term derives from 'robot.' According to Imperva's annual report (2025 edition), automated traffic accounted for 51% of all web traffic, surpassing human activity. Benign bots include search engine crawlers (Googlebot), chatbots, and monitoring bots that support internet infrastructure. Malicious bots are used for scraping, credential stuffing, spam posting, and DDoS attacks. Detection techniques include CAPTCHA, behavioral analysis (mouse movements, keystroke rhythm), rate limiting, JavaScript challenges, and device fingerprinting. A multi-layered approach combining several techniques is effective against sophisticated bots. Many malicious bots operate as part of botnets.
Web Security
- XSS (Cross-Site Scripting)
-
An attack that exploits vulnerabilities in web applications to inject and execute malicious JavaScript in a victim's browser, potentially stealing session cookies, redirecting users, or modifying page content. There are three main types: reflected XSS (malicious script in URL parameters), stored XSS (script persisted in the database and served to all visitors), and DOM-based XSS (client-side JavaScript manipulation). The primary defense is escaping output according to the context it is written into, with a Content-Security-Policy (CSP) header used alongside it as a supplementary layer that limits the damage. In the OWASP Top 10, XSS has been folded into the Injection category as CWE-79 since the 2021 edition. Frameworks such as React and Vue.js escape output by default, but that protection is lost wherever an API that injects raw HTML is used.
- CSRF (Cross-Site Request Forgery)
-
An attack that tricks a user's browser into sending unintended HTTP requests to a website where the user is already authenticated, exploiting the browser's automatic inclusion of cookies with every request. Simply visiting a malicious page or clicking a crafted link can trigger actions like password changes, fund transfers, or account modifications without the user's knowledge. CSRF attacks exploit the trust that a website has in the user's browser. Effective countermeasures include CSRF token validation (unique tokens embedded in forms), the SameSite cookie attribute, and requiring re-authentication for sensitive operations. Since Chrome 80 (February 2020), cookies with no SameSite attribute are treated as Lax, so naive attacks are blocked by the browser itself. SameSite is only one layer of defense, though: it does not stop designs that change state via GET, nor attacks that originate from the same registrable domain. Important operations require the POST method and CSRF tokens together.
- SQL Injection
-
An attack that inserts malicious SQL statements into the input fields of a web application in order to manipulate the database without authorization. It can bypass authentication and allow data to be stolen, altered, or deleted. The first line of defense is to separate the structure of an SQL statement from the data using prepared statements (parameterized queries); the Injection entry of the OWASP Top 10 (A03:2021 in the 2021 edition and A05:2025 in the 2025 edition) likewise puts the use of parameterized interfaces first. Even when an ORM (Object-Relational Mapping) is in use, any place that assembles raw SQL directly can still introduce the flaw. Detecting suspicious input patterns with a WAF is effective as a supplementary defense.
- CORS (Cross-Origin Resource Sharing)
-
A mechanism by which a server uses HTTP headers to tell the browser whether JavaScript is allowed to read a response fetched from a different origin (a combination of scheme, host name, and port number). What forbids that read by default is the same-origin policy, and CORS sits on the side that relaxes the restriction only as far as needed. It does not stop a request from arriving or the server from processing it, so tightening CORS is not a countermeasure against CSRF or against direct access to the server. The wildcard (*) in Access-Control-Allow-Origin stops working as soon as credentials are attached, so list the allowed origins individually unless the API is public. Without knowing what triggers a preflight request (OPTIONS), you cannot trace the cause of CORS errors while developing an API.
- CSP (Content Security Policy)
-
An HTTP response header that restricts the sources from which a web page can load resources such as scripts, stylesheets, images, fonts, and frames. It can control the execution of inline scripts and the sending of data to external destinations, acting as a layer that keeps an attacker's script from running even when an XSS vulnerability remains. For example, 'script-src self' allows scripts only from the same origin. The report-only mode (Content-Security-Policy-Report-Only) is invaluable for gradual adoption, allowing you to monitor violations without breaking existing functionality. Nonce-based and hash-based policies provide fine-grained control over inline scripts. It is not a substitute for output escaping, and is used alongside it as a supplementary layer that limits the damage.
- Clickjacking
-
An attack technique that overlays a transparent or disguised iframe containing a target website over a decoy page, tricking users into clicking buttons or links they cannot see. Common targets include social media 'like' and 'share' buttons, account settings toggles, and payment confirmation buttons. The X-Frame-Options header (DENY or SAMEORIGIN) and CSP's frame-ancestors directive prevent a page from being embedded in iframes on unauthorized domains. Because the attacker overlays the target site on top of their own decoy page with a transparent iframe, the victim believes they are operating the decoy page while actually pressing buttons on the target site hidden in the invisible layer. Attacks that stack different content on top of a visible UI to mislead the user are collectively called UI redressing (UI spoofing), and clickjacking is its best-known form. Overlaying elements on a camera or microphone permission dialog to obtain consent belongs to the same broad category.
- HSTS (HTTP Strict Transport Security)
-
A security mechanism where a web server sends a response header instructing the browser to always use HTTPS for all subsequent connections to that domain. Defined in RFC 6797 (November 2012), it makes the browser rewrite HTTP URLs to HTTPS before they are sent and terminate the connection when a certificate error occurs. A setup that relies on an HTTP-to-HTTPS redirect leaves the first round trip in plaintext, which is exactly what SSL stripping attacks target; on a domain where HSTS is in effect, that plaintext round trip never happens. The max-age directive specifies how long the browser remembers the policy, and includeSubDomains extends it to subdomains. Because the policy only takes effect once the header has been received, the very first visit to the domain falls outside its protection.
- WAF (Web Application Firewall)
-
A security layer that monitors and filters HTTP/HTTPS traffic to a web application and blocks malicious requests. It detects and blocks known attack patterns such as SQL injection and XSS, whose traces appear in the syntax of the request itself. Whereas a traditional network firewall controls traffic by IP address and port number, a WAF inspects the contents of the HTTP request (headers, body, and URL parameters). Cloud-based offerings such as AWS WAF and the Cloudflare WAF can be applied without provisioning dedicated hardware, but tuning away false positives (blocking legitimate requests) remains the main operational burden.
- HTTP
-
The foundational protocol for data exchange between web browsers and servers. HTTP operates on a request-response model where the client sends a request specifying a method (GET, POST, PUT, DELETE) and the server returns a response with a status code (200, 404, 500) and data. HTTP is stateless by design, meaning each request is processed independently without knowledge of previous requests - session management relies on cookies or tokens. The protocol has evolved from HTTP/1.1, where a single connection handled one request at a time, through HTTP/2 (2015, multiplexing over a single TCP connection) to HTTP/3 (2022, QUIC-based transport eliminating TCP head-of-line blocking). HTTPS adds TLS encryption to HTTP and, as of August 2026, is the de facto standard for serving websites.
- CAPTCHA
-
A test designed to distinguish human users from automated bots. Methods include distorted text input, image selection challenges, and behavioral analysis. reCAPTCHA v3 returns a score based on how a visitor interacts with the site, without asking for any interaction. Widely used to prevent spam submissions, brute-force attacks, and ticket scalping bots, CAPTCHA cannot stop them on its own and is meant to be combined with a WAF, rate limiting, and other defenses.
Mobile & IoT Security
- Mobile App Permission Management
-
The practice of managing and controlling the permissions that smartphone apps request to access device resources such as the camera, microphone, location services, contacts, and storage. Both iOS and Android provide granular permission controls, allowing users to grant, deny, or limit permissions on a per-app basis. Since Android 11 and iOS 14, permissions can be granted for one-time use only, and unused app permissions are automatically revoked. A common oversight is granting location access to apps that do not need it - weather apps, for example, can function with approximate rather than precise location. Regularly auditing app permissions and revoking unnecessary access is a fundamental mobile privacy practice.
- IoT Device Security
-
Security measures for the growing ecosystem of internet-connected devices including smart appliances, surveillance cameras, wearable fitness trackers, industrial sensors, and medical devices. Every additional connected device adds another remotely reachable endpoint, so the attack surface widens with each unit deployed. Fundamental security practices include changing default passwords (many IoT botnets like Mirai exploit factory defaults), regularly updating firmware, and isolating IoT devices on a separate network segment. Many IoT devices have limited computing resources that make advanced encryption and security software impractical, so network-level defenses such as firewalls and intrusion detection systems become critical compensating controls.
- Smart Home Privacy
-
Privacy concerns related to the voice recordings, video footage, and behavioral data collected by smart home devices such as voice assistants (Amazon Echo, Google Nest), smart cameras, smart locks, robot vacuums, and connected appliances. Always-on microphones and cameras carry the risk of unintended recording and potential data breaches. Smart speakers send audio to the cloud once a wake word is detected, and those recordings stay in a history until deleted; combined with logs from other devices, they can reveal household routines and occupancy patterns. Reviewing and adjusting privacy settings on each device, regularly deleting stored voice recordings, disabling features you do not use, and keeping firmware updated are essential practices for maintaining privacy in a connected home.
- App Tracking Transparency
-
A privacy framework introduced by Apple in iOS 14.5 (April 2021) that requires apps to obtain explicit user consent through a system prompt before tracking them across other apps and websites using the device's IDFA (Identifier for Advertisers). Without that permission the IDFA returns only a zeroed-out value, so measurement that spans multiple apps had to be rebuilt from its premises. On its October-December 2021 earnings call (February 2022), Meta said it expected the iOS privacy changes to be a headwind on the order of $10 billion for its business in 2022. Google also pursued an approach for Android that does not depend on the advertising ID (the Privacy Sandbox), but announced the retirement of its main APIs in October 2025.
- Device Encryption
-
A technology that encrypts the entire storage of a smartphone, tablet, or computer, rendering all data unreadable without the correct authentication credentials (password, PIN, or biometrics). This protects sensitive data in case of device loss or theft. iOS has enabled full-disk encryption by default since iOS 8, and Android has required it since Android 10. On desktop systems, BitLocker (Windows) and FileVault (macOS) provide equivalent protection. A common misconception is that a screen lock alone protects data - without encryption, data can be extracted by removing the storage device. Modern devices use hardware-backed encryption that performs encryption and decryption with minimal performance impact.
- Mobile VPN
-
A technology that encrypts smartphone and tablet communications to protect privacy and security on untrusted networks such as public Wi-Fi hotspots, hotel networks, and airport connections. The IKEv2 protocol is particularly well-suited for mobile environments because its MOBIKE extension (RFC 4555) lets an established session follow a changing IP address instead of tearing down and rebuilding the tunnel, which is exactly what happens when a device moves between Wi-Fi and cellular data. WireGuard is also gaining popularity on mobile due to its lightweight design and battery efficiency. A common misconception is that mobile data connections are inherently secure - while cellular networks use encryption, your ISP can still monitor your traffic. On Android, always-on VPN can be turned on from the built-in VPN settings, while on iOS the Always On VPN feature is offered for supervised devices managed through MDM.
- SIM Swap Attack
-
A fraud technique where an attacker convinces a mobile carrier's customer service representative to transfer the victim's phone number to a SIM card controlled by the attacker, usually through social engineering, and in some cases with help from a bribed insider. Once the phone number is hijacked, the attacker receives all SMS messages and calls intended for the victim, enabling them to bypass SMS-based two-factor authentication and take over bank accounts, email, cryptocurrency wallets, and social media profiles. The FBI Internet Crime Complaint Center (IC3) received 1,611 SIM swapping complaints in 2021, with adjusted losses of more than $68 million, and holders of cryptocurrency are among the most frequent targets. Because the phone number itself is taken over, codes delivered by SMS stop working as a defense, so the core of any fix is moving to methods that complete authentication on the device, such as TOTP authenticator apps or hardware security keys, and requiring a passcode before a SIM can be reissued or a line moved.
- MDM (Mobile Device Management)
-
An enterprise solution that enables organizations to centrally manage, monitor, and secure employee mobile devices including smartphones, tablets, and laptops. Core capabilities include enforcing device encryption, restricting app installations to approved lists, configuring Wi-Fi and VPN settings remotely, and performing remote wipe (complete data erasure) if a device is lost or stolen. In BYOD (Bring Your Own Device) environments where personal devices access corporate resources, MDM is the mechanism that keeps the boundary between business data and personal data enforceable. Leading solutions include Microsoft Intune, Omnissa Workspace ONE (formerly VMware Workspace ONE), and Jamf (for Apple devices). Products in this space are often sold as Unified Endpoint Management (UEM) suites that manage phones, tablets, and desktops from a single console.
- Bluetooth
-
A short-range wireless communication standard. It is used to connect a phone to earphones, keyboards, speakers and similar devices. The usable range depends on the transmit power class of the device and on the surrounding environment, so a few meters up to about 10 m is a reasonable expectation for the small devices people carry. Connecting requires pairing (linking two devices together), but devices without a screen exchange keys with no step that verifies the other side, so the practical rule is to never approve a connection request you did not start yourself. Bluetooth Low Energy (BLE) is the low-power variant, widely adopted in wearables and IoT devices. Version 5 added faster and longer-range options on the BLE side, though both are only used when the devices involved support them.
- GPS
-
A positioning system that works out your current location from satellite signals. It is what map apps, navigation, and location-based games on a smartphone rely on. The umbrella term for satellite positioning is GNSS, and GPS is the system the United States operates. Using signals from Russia's GLONASS, the EU's Galileo, China's BeiDou, and Japan's Quasi-Zenith Satellite System (QZSS, Michibiki) alongside it means more satellites in view and a steadier fix. Accuracy depends heavily on how open the sky is: indoors and among high-rise buildings the satellite signals are blocked, so Wi-Fi and cell tower positioning fill the gap. Location data is sensitive personal information, so managing location permissions app by app matters.
- MAC Address
-
A 48-bit address that identifies a network device at the data link layer. It is used to identify the other party within the same network; whereas an IP address handles routing between networks, a MAC address refers to a device within the same segment and is not forwarded beyond a router. In a factory-assigned address, the leading bits are an identifier that the IEEE assigns to an organization (such as an OUI), so the manufacturer can be traced, and the remaining bits form a per-unit number. However, iOS 14 and later and Android 10 and later use a randomized address by default when connecting to Wi-Fi, so the MAC address a device presents is not necessarily a fixed identifier, and it has become difficult for stores and venues to track the same device over a long period.
- Bandwidth
-
The maximum amount of data a network connection can transfer per unit of time, measured in Mbps or Gbps. Bandwidth represents the 'width' of the pipe - how much data can flow at once - while latency represents the 'length' of the pipe - how long it takes for data to arrive. The 'up to 1 Gbps' figure in ISP contracts is a theoretical maximum (best effort), and the throughput actually achieved depends on where the bottleneck lies, such as network congestion, router performance or Wi-Fi conditions. ISPs may also intentionally reduce bandwidth through throttling under certain conditions, such as exceeding monthly data caps or during peak hours.
- SSID
-
The name that identifies a Wi-Fi network. Access points broadcast the SSID in beacon frames, which devices display in their Wi-Fi network list. Up to 32 bytes long, with multiple SSIDs configurable per router. An SSID is a name used for identification and is a separate mechanism from encryption: even with a stealth SSID (broadcast disabled), the SSID can be read from the frames that connecting devices send, so hiding it is not a defense in itself. In an Evil Twin attack, a rogue access point using the same SSID as the legitimate one is set up and the traffic of users who connect is intercepted. What protects your traffic is not the SSID setting but WPA3 or WPA2 encryption and a passphrase that is hard to guess.
Data & Cloud Security
- Cloud Storage Security
-
The set of measures to ensure the confidentiality, integrity, and availability of data stored in cloud services like AWS S3, Google Cloud Storage, and Azure Blob Storage. Proper access control configuration (IAM policies, bucket policies), encryption at rest (server-side or client-side), and encryption in transit (TLS) are the fundamental security elements. Misconfiguration leading to unintended public data exposure is the most common cause of cloud storage incidents - thousands of S3 buckets have been found publicly accessible due to overly permissive policies. Enabling access logging, versioning for data recovery, and regular security audits of storage configurations are essential practices for any organization using cloud storage.
- Zero-Knowledge Proof
-
A cryptographic method that allows one party to prove knowledge of certain information (such as a password or secret) to another party without revealing the information itself. In cloud services, zero-knowledge encryption means that the service provider encrypts and decrypts data using keys derived from the user's password, which never leaves the user's device - even the provider cannot access the stored data. Proton Mail, Tresorit, and SpiderOak are notable implementations. The tradeoff is that if the user forgets their password, data recovery is impossible since the provider has no access to the decryption keys. Zero-knowledge proofs are also fundamental to privacy-preserving blockchain technologies and digital identity systems.
- Backup Strategy (3-2-1 Rule)
-
A fundamental data protection principle: maintain at least 3 copies of important data, store them on 2 different types of media (e.g., local SSD and cloud storage), and keep 1 copy offsite (geographically separate location). The importance of offline or air-gapped backups has been dramatically reaffirmed as ransomware attacks increasingly target connected backup systems to maximize leverage. An enhanced version, the 3-2-1-1-0 rule, adds 1 offline copy and 0 errors (verified through regular restore testing). Many organizations discover their backups are corrupted or incomplete only when they need them most, making periodic restore drills essential. Automated backup solutions with versioning provide protection against both accidental deletion and ransomware encryption.
- Data Encryption
-
The process of transforming readable plaintext data into unreadable ciphertext using cryptographic algorithms, ensuring that only authorized parties with the correct decryption key can access the original information. Encryption should be applied both at rest (stored data on disks and databases) and in transit (data moving across networks) to provide comprehensive protection throughout the entire data lifecycle. AES (in particular AES-256 with 256-bit keys) is the standard algorithm and is approved for protecting US government classified information. A common misconception is that encryption alone guarantees security - proper key management, including secure storage, rotation, and access control for encryption keys, is equally critical.
- Zero Trust Security
-
A security model built on the principle of 'never trust, always verify,' requiring strict identity verification and authorization for every access request regardless of whether it originates from inside or outside the corporate network. This represents a fundamental shift from traditional perimeter-based security that implicitly trusted anything inside the firewall. The three pillars of Zero Trust are: continuous identity verification, device health validation, and least-privilege access. Implementation typically involves micro-segmentation, multi-factor authentication, and real-time access policy evaluation. The model gained urgency with the rise of remote work and cloud adoption, which dissolved the traditional network perimeter. NIST SP 800-207 provides the reference architecture.
- Secure File Sharing
-
Methods and tools for transferring and sharing files while maintaining data confidentiality, integrity, and access control. Key security measures include end-to-end encryption (so only intended recipients can access files), password protection, time-limited sharing links that automatically expire, download limits, and comprehensive access logging. A common source of data leaks is setting cloud storage sharing permissions to 'anyone with the link' for convenience and forgetting to revoke access later. Enterprise solutions like Box, OneDrive, and Google Workspace offer granular sharing controls with audit trails. For sensitive files, client-side encryption before uploading to any cloud service provides an additional layer of protection independent of the provider's security.
- Dark Web Monitoring
-
A service that continuously scans dark web marketplaces, forums, paste sites, and underground channels to detect whether your personal information - email addresses, passwords, credit card numbers, Social Security numbers, or corporate credentials - has been leaked or is being traded. Basic self-checks are available through free tools like Have I Been Pwned, which indexes billions of compromised records from known data breaches. Enterprise dark web monitoring services provide real-time alerts and deeper coverage of private forums. Early detection of compromised credentials is directly linked to preventing further damage, as it enables prompt password changes and account security measures before attackers can exploit the stolen data.
- Data Sanitization (Secure Deletion)
-
The process of rendering data on storage media permanently unrecoverable through methods that go beyond standard file deletion. When you delete a file normally, only the file system reference is removed while the actual data remains intact on the disk until overwritten, making recovery trivial with forensic tools. For traditional hard drives (HDDs), overwriting is effective; multi-pass methods (such as DoD 5220.22-M) are now regarded as a past practice. However, due to wear leveling and over-provisioning on SSDs, complete overwrite erasure is unreliable - Cryptographic Erase (destroying the encryption key for self-encrypting drives) is the recommended approach for flash storage. Physical destruction (shredding, degaussing) provides the highest assurance for decommissioned media containing highly sensitive data.
- Streaming
-
A technology that plays data in real-time while downloading it. Used for video (Netflix, YouTube), music (Spotify, Apple Music), and live broadcasts. Since data is played in real-time without being saved to the device, a stable internet connection is required. Using a VPN encrypts the communication but may reduce speed.
Incident Response & Forensics
- Incident Response
-
A systematic, structured process for detecting, containing, eradicating, and recovering from security incidents such as unauthorized access, data breaches, malware infections, and DDoS attacks. The process is commonly divided into the following phases: preparation (planning and training), detection and analysis (identifying the incident), containment (limiting damage spread), eradication (removing the threat), recovery (restoring normal operations), and lessons learned (improving future response). Organizations with a tested incident response plan reduce the average cost of a data breach by over $2 million according to IBM research. Advance planning, clearly defined roles and communication channels, and regular tabletop exercises are key to ensuring a swift and effective response when incidents occur.
- Digital Forensics
-
The scientific discipline of collecting, preserving, analyzing, and presenting electronic evidence from computers, networks, mobile devices, and cloud environments in a manner that is legally admissible. Used in cybercrime investigations, incident root cause analysis, intellectual property disputes, and regulatory compliance audits. Maintaining the chain of custody and using hash-based integrity verification (SHA-256) are essential to prevent evidence tampering and ensure admissibility in court. Forensic investigators use specialized tools like EnCase, FTK, and Autopsy to create bit-for-bit disk images and recover deleted files. The field is evolving rapidly to address challenges posed by encryption, cloud storage, and volatile memory analysis.
- CSIRT (Computer Security Incident Response Team)
-
A specialized team within an organization responsible for the coordinated handling of security incidents from detection through resolution. Core functions include monitoring security alerts, analyzing potential threats, coordinating incident response activities, communicating with stakeholders, and conducting post-incident reviews. CSIRTs also serve as the primary liaison with external entities including other CSIRTs, law enforcement agencies, and industry information sharing groups. In Japan, JPCERT/CC functions as the national-level coordination center, while many large enterprises maintain their own internal CSIRTs. Establishing a CSIRT with clear authority, defined escalation procedures, and 24/7 availability is considered a security best practice for organizations of all sizes.
- Threat Intelligence
-
The practice of systematically collecting, processing, and analyzing information about current and emerging cyber threats - including attacker tactics, techniques, and procedures (TTPs), tools used, targeted industries, and indicators of compromise (IoCs) - to inform and strengthen an organization's defensive posture. Threat intelligence is categorized into strategic (high-level trends for executives), tactical (TTPs for security teams), and operational (specific threat details for incident responders). Sharing IoCs through platforms like MISP and STIX/TAXII enables organizations to collectively enhance their defenses. The MITRE ATT&CK framework provides a comprehensive knowledge base of adversary behaviors that serves as a common language for threat intelligence.
- Penetration Testing
-
A proactive security assessment method where authorized security professionals simulate real-world attacker techniques to identify exploitable vulnerabilities in systems, networks, and applications before malicious actors can find them. There are three approaches: white-box (testers have full internal knowledge), black-box (testers have no prior information, simulating an external attacker), and gray-box (testers have partial information). Unlike automated vulnerability scanning, penetration testing verifies the actual exploitability of discovered weaknesses and assesses the potential business impact. Results are documented in detailed reports with risk ratings and remediation recommendations. Annual penetration testing is required by compliance frameworks including PCI DSS and SOC 2.
- SIEM (Security Information and Event Management)
-
A platform that aggregates and correlates log data from diverse sources across the IT infrastructure - including network devices, servers, applications, firewalls, and endpoints - to detect security threats through real-time analysis and historical pattern matching. SIEM systems use correlation rules, statistical analysis, and increasingly machine learning to identify anomalous behavior that may indicate a security incident. Leading solutions include Splunk, Microsoft Sentinel, and IBM QRadar. Beyond threat detection, SIEMs provide centralized log retention essential for compliance audits (PCI DSS, HIPAA, SOX) and forensic investigations. Modern SIEM platforms are evolving into Security Orchestration, Automation, and Response (SOAR) capabilities for automated incident handling.
- Vulnerability Management
-
The continuous, cyclical process of discovering, assessing, prioritizing, and remediating security vulnerabilities in an organization's systems, software, and infrastructure. CVE (Common Vulnerabilities and Exposures) provides standardized identification numbers, while CVSS (Common Vulnerability Scoring System) assigns severity scores from 0 to 10 to help prioritize remediation efforts. Automated vulnerability scanners like Nessus, Qualys, and OpenVAS regularly scan environments to identify known weaknesses. A critical challenge is the remediation gap - the interval between vulnerability disclosure and patch application, during which systems remain exposed. Risk-based prioritization that considers exploitability, asset criticality, and threat intelligence is essential for effective vulnerability management.
- BCP (Business Continuity Plan)
-
A comprehensive plan designed to minimize business disruption and ensure the continuity and rapid recovery of critical operations during emergencies such as cyberattacks, natural disasters, pandemics, or major system failures. The planning process begins with a Business Impact Analysis (BIA) to identify critical functions and set Recovery Time Objectives (RTO - maximum acceptable downtime) and Recovery Point Objectives (RPO - maximum acceptable data loss). A well-designed BCP covers alternative work arrangements, communication plans, supply chain contingencies, and IT disaster recovery procedures. Regular reviews, updates, and realistic drills (at least annually) are vital to maintaining plan effectiveness - an untested BCP provides a false sense of security.
- Honeypot
-
A deliberately deployed decoy system, service, or data resource designed to appear as a legitimate target to attract and detect attackers. Honeypots serve multiple purposes: observing attack techniques and tools in a controlled environment, detecting intrusion attempts early (any interaction with a honeypot is suspicious by definition), analyzing attacker behavior patterns, and diverting attention from production systems. They range from low-interaction honeypots (simulating basic services) to high-interaction honeypots (running full operating systems). Honeypots must be deployed in environments carefully isolated from production systems to prevent attackers from using them as a pivot point. Honeynets (networks of honeypots) provide broader visibility into attacker methodologies.
Cloud & Infrastructure Security
- IaC (Infrastructure as Code)
-
An approach to defining, provisioning, and managing infrastructure configurations - servers, networks, storage, security groups - as version-controlled code rather than through manual processes. Tools like Terraform (multi-cloud), AWS CloudFormation, and Pulumi enable teams to automate infrastructure deployment and ensure reproducibility across environments. IaC eliminates configuration drift and security gaps caused by manual setup, and enables infrastructure changes to go through the same code review and testing processes as application code. A common misconception is that IaC is only for large organizations - even small teams benefit from reproducible, auditable infrastructure. GitOps practices extend IaC by using Git repositories as the single source of truth for infrastructure state.
- Container Security
-
The comprehensive set of security practices for safely building, deploying, and operating container technologies such as Docker and Kubernetes in production environments. Key practices include vulnerability scanning of container images before deployment (using tools like Trivy or Snyk), running containers with least-privilege settings (non-root users, read-only file systems), applying Kubernetes network policies to restrict inter-pod communication, and implementing runtime monitoring for anomalous behavior. Image integrity verification through digital signatures (Docker Content Trust, Sigstore) prevents deployment of tampered images. A common pitfall is using base images with known vulnerabilities - regularly updating and using minimal base images (Alpine, distroless) significantly reduces the attack surface.
- IAM (Identity and Access Management)
-
A framework for centrally managing the authentication (verifying identity) and authorization (granting permissions) of users, services, and applications in cloud environments and enterprise systems. Based on the principle of least privilege, IAM ensures that each entity receives only the minimum permissions necessary to perform its function. In AWS, IAM policies define granular permissions using JSON documents that specify allowed actions on specific resources. IAM policy misconfiguration - such as overly permissive wildcard permissions or unused access keys - is consistently ranked as one of the most common and dangerous security risks in cloud environments. Regular access reviews, enforcing MFA for privileged accounts, and using IAM Access Analyzer are essential governance practices.
- Secrets Management
-
A system and set of practices for securely storing, distributing, rotating, and auditing access to sensitive credentials (secrets) such as API keys, database passwords, encryption keys, TLS certificates, and OAuth tokens. Dedicated tools like AWS Secrets Manager, HashiCorp Vault, and Azure Key Vault eliminate the dangerous practice of hardcoding secrets in source code, configuration files, or environment variables. These tools provide encryption at rest, fine-grained access control, automatic rotation schedules, and comprehensive audit logging. A single leaked API key or database password can lead to a catastrophic breach - GitHub scans public repositories and has found millions of exposed secrets. Regular secret rotation limits the window of exposure if a secret is compromised.
- Network Segmentation
-
A security technique that logically divides a network into isolated segments and controls communication between them using firewalls, VLANs, or software-defined networking. The primary goal is to limit lateral movement - preventing an attacker who compromises one system from freely accessing other parts of the network. For example, separating IoT devices, guest Wi-Fi, and production servers onto different network segments ensures that a compromised smart camera cannot reach the database server. Microsegmentation takes this further by applying granular policies at the individual workload level. Network segmentation is a foundational technology for Zero Trust architecture and is required by compliance frameworks including PCI DSS for isolating cardholder data environments.
- CDN (Content Delivery Network)
-
A globally distributed network of edge servers that caches and delivers web content from locations geographically close to the user, dramatically reducing latency and improving page load times. Major CDN providers such as Cloudflare and Amazon CloudFront operate edge locations worldwide. Beyond performance improvements, CDNs play a critical security role: absorbing and mitigating DDoS attacks at the edge before they reach origin servers, offloading TLS termination to reduce server load, and providing Web Application Firewall (WAF) capabilities. CDNs also improve availability by serving cached content even if the origin server goes down. For many web applications, a CDN is treated as core infrastructure rather than an optional optimization.
- Cloud Shared Responsibility Model
-
A security framework that clearly divides responsibilities between the cloud service provider and the customer. The provider is responsible for security 'of' the cloud - physical data center security, hypervisor, and network infrastructure. The customer is responsible for security 'in' the cloud - data encryption, access control, application security, and operating system patching. The exact division varies by service model: IaaS customers manage more (OS, middleware, applications), while SaaS customers manage less (primarily data and access). Misunderstanding these boundaries is a leading cause of cloud security incidents - many organizations assume the provider handles everything. AWS, Azure, and GCP all publish detailed shared responsibility documentation that should be reviewed before deploying any workload.
- Serverless Security
-
Security challenges and best practices specific to serverless computing environments such as AWS Lambda, Azure Functions, and Google Cloud Functions. While the cloud provider manages the underlying OS, runtime, and infrastructure patching, the customer remains responsible for function code quality, third-party dependency vulnerabilities, IAM permission minimization (each function should have only the permissions it needs), input validation, and secure handling of environment variables and secrets. A common misconception is that serverless is inherently more secure - while it eliminates server management overhead, it introduces new attack vectors including event injection and insecure function chaining. Cold start initialization code also requires security attention, as it may execute with elevated privileges.
- DLP (Data Loss Prevention)
-
A security technology and strategy designed to detect, monitor, and prevent the unauthorized exfiltration, leakage, or accidental loss of sensitive data from an organization. DLP systems monitor data movement across multiple channels including email attachments, cloud uploads, USB device copying, printing, and screen sharing, blocking or alerting on policy violations in real time. Detection methods include pattern matching for structured data (credit card numbers, Social Security numbers), keyword matching, document fingerprinting, and machine learning-based classification. DLP solutions operate at three levels: network DLP (monitoring traffic), endpoint DLP (monitoring device activity), and cloud DLP (monitoring SaaS applications). Effective DLP requires clear data classification policies that define what constitutes sensitive data and how it should be handled.
- API (Application Programming Interface)
-
A set of rules and protocols that allow software applications to communicate and exchange data. Modern web services are built by combining dozens to hundreds of APIs. Common styles include REST, GraphQL, WebSocket, and gRPC. Authentication (API keys, OAuth 2.0, JWT) and rate limiting are essential for protection, and security practices based on the OWASP API Security Top 10 are recommended.
- Server
-
A computer or software that provides services and data to other computers (clients) over a network. Types include web servers, mail servers, DNS servers, and database servers. Deployment options range from on-premises physical servers to cloud instances (IaaS/PaaS) and serverless architectures. The choice depends on traffic volume, availability requirements, data residency regulations, and operational capacity. Regardless of deployment model, fundamental security practices such as patching, access control, and log monitoring remain essential.