Writing on threat models, design choices, and assumptions that sound safer than they are.
Why a vault should be invisible, not just encrypted — LastPass, local-first architecture, steganography, and honest limits.