#fundamentals
-
How Passkeys Work: The Login Flow, Step by Step
A mechanism-level walkthrough of a passkey login: the challenge, the signature, the origin check, and the flag bits a site reads on every sign-in.
-
Password manager breach response: what to do in 24 hours
A 24-hour password manager breach playbook: confirm impact, assess the master password, rotate accounts by priority, and handle TOTP and passkeys.
-
Browser-Saved Passwords vs. a Dedicated Password Manager
Browser-built-in password saving in Chrome, Safari and Firefox compared with dedicated managers like Bitwarden and 1Password, and when to switch.
-
Passkeys explained: how they work and when to use them
An explanation of passkeys (FIDO2/WebAuthn): what they are, why they resist phishing, where they are supported, and how they work with password managers.
-
Password security fundamentals: what actually matters
The credential security basics that actually matter in 2026: password length, uniqueness, breach exposure, phishing-resistant 2FA, and passkeys.