<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Digtal Seatbelt]]></title><description><![CDATA[Short, practical lessons on privacy and online safety — built for real life, not security conferences.]]></description><link>https://digitalseatbelt.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!oFOz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40d424f-25c5-41c1-8545-28ddc17999bc_232x232.jpeg</url><title>Digtal Seatbelt</title><link>https://digitalseatbelt.substack.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 24 Jun 2026 08:44:20 GMT</lastBuildDate><atom:link href="https://digitalseatbelt.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Hammy]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[digitalseatbelt@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[digitalseatbelt@substack.com]]></itunes:email><itunes:name><![CDATA[The Digital Seatbelt]]></itunes:name></itunes:owner><itunes:author><![CDATA[The Digital Seatbelt]]></itunes:author><googleplay:owner><![CDATA[digitalseatbelt@substack.com]]></googleplay:owner><googleplay:email><![CDATA[digitalseatbelt@substack.com]]></googleplay:email><googleplay:author><![CDATA[The Digital Seatbelt]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Importance of Network Segmentation & Segregation]]></title><description><![CDATA[Why Your Smart Toaster Could Take Down Your Entire Network]]></description><link>https://digitalseatbelt.substack.com/p/importance-of-network-segmentation</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/importance-of-network-segmentation</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Tue, 10 Mar 2026 12:51:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oFOz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40d424f-25c5-41c1-8545-28ddc17999bc_232x232.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Why Your Smart Toaster Could Take Down Your Entire Network</h2><p>You&#8217;ve got a smart thermostat, a few IP cameras, maybe a connected coffee maker. They&#8217;re convenient, they&#8217;re modern &#8212; and if they&#8217;re sitting on the same network as your laptops and servers, they could be your biggest security liability.</p><p>IoT devices are notoriously difficult to secure. Many ship with weak default credentials, receive infrequent (or no) firmware updates, and lack the processing power to run robust security software. Attackers know this. In fact, IoT devices have become a preferred entry point for breaches precisely because they&#8217;re often the weakest link in an otherwise well-hardened environment.</p><p>The answer isn&#8217;t to unplug your smart devices. It&#8217;s to isolate them.</p><h2>What Is Network Segregation?</h2><p>Network segregation (or segmentation) means dividing your network into separate zones so that devices in one zone can&#8217;t freely communicate with devices in another. For IoT devices, this typically means placing them on a dedicated VLAN or a separate Wi-Fi network that has no path to your critical systems &#8212; file servers, workstations, databases, or anything holding sensitive data.</p><p>Think of it like a hospital&#8217;s infection control policy: patients stay in their ward, staff move between zones with proper protocols, and contamination doesn&#8217;t spread unchecked.</p><h2>Why It Matters</h2><p><strong>Containing the blast radius</strong></p><p>If an IoT device is compromised, segregation ensures the attacker is trapped in a limited environment. They can&#8217;t pivot to your core infrastructure. A breach becomes an inconvenience rather than a catastrophe.</p><p><strong>Reducing your attack surface</strong></p><p>Every device on a flat network is a potential stepping stone. A smart bulb shouldn&#8217;t have a route to your HR database &#8212; but without segmentation, it does. Isolation removes that route entirely.</p><p><strong>Enforcing least-privilege access</strong></p><p>Network segregation is a practical implementation of the principle of least privilege. Devices only communicate with what they *need* to &#8212; often just the internet and a cloud endpoint &#8212; and nothing else.</p><p>**Visibility and monitoring.** When IoT traffic is isolated, anomalies are easier to spot. A camera suddenly scanning internal IP ranges stands out immediately when it&#8217;s on its own segment with defined, narrow traffic patterns.</p><h2>How to Do It</h2><p>The good news is that meaningful IoT isolation doesn&#8217;t require enterprise hardware. Here&#8217;s a practical starting point:</p><ul><li><p><strong>Create a dedicated IoT VLAN</strong> on your router or managed switch. Most prosumer and business-grade routers support this natively.</p></li><li><p><strong>Set up a separate Wi-Fi SSID</strong> mapped to that VLAN. Connect all smart home and IoT devices here exclusively.</p></li><li><p><strong>Apply firewall rules</strong> that block traffic from the IoT segment to your trusted network. Allow outbound internet access only where required.</p></li><li><p><strong>Disable inter-device communication</strong> on the IoT segment unless a specific use case demands it.</p></li><li><p><strong>Monitor traffic</strong> from the segment. Even basic logging can surface unusual behavior quickly.</p></li></ul><p></p><h3>The Bottom Line</h3><p>IoT devices bring real value, but they carry real risk. The manufacturers of these devices often can&#8217;t &#8212; or won&#8217;t &#8212; keep pace with the security demands of modern networks. That responsibility falls to you.</p><p>Network segregation won&#8217;t make your IoT devices invulnerable, but it means that when one *is* compromised, the damage stops there. In security, containment is everything. Don&#8217;t let your smart fridge have a conversation with your payroll system.</p><p><strong>Isolate early. Monitor always. Patch when you can.</strong></p>]]></content:encoded></item><item><title><![CDATA[YubiKeys: Why Hardware Keys Represent the Gold Standard of Two-Factor Authentication]]></title><description><![CDATA[YubiKeys are small devices that run via USB or NFC, to allow you to have a fixed hardware component to Two-Factor Authentication (2FA).]]></description><link>https://digitalseatbelt.substack.com/p/yubikeys-why-hardware-keys-represent</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/yubikeys-why-hardware-keys-represent</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Tue, 03 Feb 2026 11:29:05 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/8a3d721c-319f-47da-86b0-d8d569827ab1_1179x755.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>YubiKeys are small devices that run via USB or NFC, to allow you to have a fixed hardware component to Two-Factor Authentication (2FA). It&#8217;s the equivalent of having a physical key to your account. Most hardware keys are clone resistant. Meaning, the only way to access a fully YubiKey locked-down account is to have physical access to your key. In addition, YubiKeys allow storage of One-Time-Passcodes (OTPs). Allowing you to generate OTPs only with the key. Providing the same security, albeit less closed (someone can copy the keys before you store them through screen capture), for standard OTP 2FA.</p><p>One of the protocols YubiKeys runs works as an external bluetooth keyboard, to ensure data transmission of signed authentication is as secure as possible. The YubiKey plugs into a device for power and then when triggered, transmits the code via bluetooth.</p><p><em>&#171;This is why if you have used a YubiKey and initiated a code, while your cursor was in an input field, you may have noticed it type-out a seemingly random string of characters&#187;</em></p><p>Two-factor authentication (2FA) has become essential in our digital lives, adding a critical security layer beyond passwords alone. Yet not all 2FA methods are created equal. While SMS codes and authenticator apps have become commonplace, YubiKeys and similar hardware security keys offer a fundamentally more secure approach. Here&#8217;s why they represent the future of authentication.</p><h2>The Vulnerability of Common 2FA Methods</h2><p>Before understanding YubiKey&#8217;s advantages, it&#8217;s worth recognizing the limitations of mainstream alternatives. SMS-based 2FA, despite its ubiquity, suffers from serious weaknesses. SIM swapping attacks&#8212;where attackers convince carriers to transfer a phone number to their device&#8212;have compromised countless accounts. Even without such dramatic attacks, SMS interception remains possible on compromised networks.</p><p>Authenticator apps like Google Authenticator fare better but still have vulnerabilities. They&#8217;re vulnerable to phishing attacks where users are tricked into entering time-based codes into fake login pages. The codes themselves are only six digits, providing limited entropy. If a device is compromised, all stored secrets could be exposed simultaneously.</p><h2>How YubiKeys Work Differently</h2><p>YubiKeys are small, physical devices&#8212;about the size of a USB drive&#8212;that generate cryptographic responses to authentication challenges. Rather than displaying codes that users manually enter, YubiKeys perform authentication through built-in cryptographic protocols, most notably FIDO2/WebAuthn standards.</p><p>When you authenticate with a YubiKey, you&#8217;re not transmitting a code that could be intercepted or phished. Instead, the device cryptographically signs a challenge issued by the service you&#8217;re logging into. Only the legitimate YubiKey in your possession can generate the correct signature, making it extraordinarily difficult for attackers to compromise the authentication process.</p><h2>The Phishing-Resistant Advantage</h2><p>The most compelling distinction is YubiKey&#8217;s resistance to phishing. Even if you&#8217;re deceived into entering your credentials on a fake website, a YubiKey won&#8217;t authenticate because the cryptographic challenge will be issued by the fake site, not the legitimate service. The key literally can&#8217;t be tricked into authenticating to the wrong domain.</p><p>Contrast this with authenticator apps, where a user might accidentally paste a code into a phishing site before realizing the deception. With YubiKeys, no amount of social engineering can trick the device into proving your identity to an attacker.</p><h2>Convenience Meets Security</h2><p>A common objection to hardware keys is inconvenience&#8212;they&#8217;re physical objects you must carry and use for each login. However, this is increasingly less of a burden. Modern YubiKeys work via NFC (near-field communication) with smartphones, USB-C with computers, and even Bluetooth. Many services now support passwordless login with YubiKeys, where authentication is a simple tap or press rather than remembering passwords at all.</p><p>Moreover, the inconvenience argument contains a hidden virtue: the very friction that makes hardware keys less convenient than apps also makes account takeover dramatically less convenient for attackers. That friction is a feature, not a bug.</p><h2>Ecosystem Support and Adoption</h2><p>YubiKeys work with virtually every major platform and service that supports FIDO2 standards, including Google, Microsoft, Apple, Amazon, GitHub, and countless others. This broad support means you&#8217;re not locked into a proprietary ecosystem. The FIDO2 standard ensures interoperability&#8212;if you decide to switch to another hardware key manufacturer, your existing credentials remain compatible.</p><h2>Additional Security Considerations</h2><p>Beyond phishing resistance, hardware keys offer other advantages. They can store multiple credentials, reducing the temptation to reuse passwords. Many YubiKeys also support additional protocols like U2F, OTP, PIV, and OpenPGP, making them multifunctional security tools. For organizations handling sensitive data, this consolidation simplifies security infrastructure.</p><p>The physical nature of the device also prevents certain classes of remote attacks. A compromised computer can&#8217;t extract cryptographic secrets from a YubiKey&#8212;the device performs cryptographic operations internally and never exposes private keys.</p><h2>Addressing the Legitimate Concerns</h2><p>To be fair, hardware keys aren&#8217;t without challenges. They cost money (typically $40-70), which creates friction for adoption at scale. They can be lost or damaged, requiring backup keys. For users managing many accounts, carrying multiple keys might feel burdensome.</p><p>These aren&#8217;t minor issues, and they explain why universal adoption remains limited. Organizations prioritizing security over cost have largely adopted hardware keys for employees, while consumer adoption has grown but still lags behind app-based methods.</p><h2>The Future of Authentication</h2><p>Security experts and major technology companies increasingly view hardware security keys as the authentication standard worth pursuing. Google&#8217;s research has consistently shown that hardware keys are dramatically more effective at preventing account compromise than other 2FA methods. As costs decrease and convenience improves&#8212;particularly through wireless connectivity&#8212;the barriers to adoption continue eroding.</p><p>For anyone handling sensitive accounts, whether for professional or personal reasons, a YubiKey represents a meaningful security upgrade. They&#8217;re not perfect, and they&#8217;re not the right choice for every use case. But in an era of sophisticated phishing and credential theft, they offer a level of protection that other 2FA methods simply cannot match. In security, that distinction matters profoundly.&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;&#8203;</p>]]></content:encoded></item><item><title><![CDATA[🔐 Firewalla Firewall Review]]></title><description><![CDATA[&#8212; Purple vs. Gold]]></description><link>https://digitalseatbelt.substack.com/p/firewalla-firewall-review</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/firewalla-firewall-review</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Wed, 31 Dec 2025 20:43:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oFOz!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff40d424f-25c5-41c1-8545-28ddc17999bc_232x232.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>In a world where network security matters as much as speed, consumer-focused firewalls have become essential &#8212; whether at home, remote working, or in small business setups. Today we&#8217;re diving into two standout products from Firewalla: Purple and Gold &#8212; what they do, how they compare, and which might be right for you.</p><p><strong>&#128995; What Is Firewalla Purple?</strong></p><p>The Firewalla Cyber Security Firewall for Home &amp; Business, Prote (Purple) is Firewalla&#8217;s compact, affordable all-in-one firewall and router aimed at home users, remote workers, and small offices.</p><p><strong>&#129504; Key Strengths</strong></p><ul><li><p>Firewall + Router in One: Protects your network with firewall, parental controls, ad-blocking and content rules.</p></li><li><p>VPN Support: Includes OpenVPN and WireGuard &#8212; good for secure remote access without monthly fees.</p></li><li><p>Network Controls: You can block countries, quarantine unknown devices, and set application-level rules.</p></li><li><p>Compact &amp; Simple: Small device that&#8217;s easy to install and manage through the Firewalla mobile app.</p></li></ul><p><strong>&#128161; Real-World Notes</strong></p><ul><li><p>The Purple generally handles up to ~1 Gbps traffic with inspection rules applied, suitable for most home broadband plans.</p></li><li><p>Included Wi-Fi is useful in a pinch (e.g., travel or small spaces) but not a replacement for a dedicated access point for larger areas.</p></li><li><p>User Experiences Vary: Some users praise its simplicity and tools; others report setup quirks or support frustrations &#8212; so results can differ based on expectations.</p></li></ul><p>&#128073; Best for: Home networks, digital enthusiasts, basic to intermediate protection.</p><p><strong>&#128993; What Is Firewalla Gold?</strong></p><p>Firewalla&#8217;s Gold series represents the higher-end firewall appliances in their lineup &#8212; built for larger homes, power users, creatives and small businesses with heavier network demands.</p><p><strong>&#128640; What Makes Gold Stand Out</strong></p><ul><li><p>More Power &amp; Speed: Handles multi-gigabit traffic &#8212; perfect for fast broadband or busy networks.</p></li><li><p>Richer Features: Unlimited VLANs, multi-WAN, advanced segmentation, and more capacity for rules and threat entries.</p></li><li><p>Scalable and Long-Term: Extra ports and processing headroom mean it&#8217;ll grow with your needs.</p></li><li><p>Console Port &amp; More: Some Gold models even include extra connectivity for advanced setups.</p></li></ul><p><strong>&#128269; What Users Report</strong></p><ul><li><p>Many reviewers highlight deep network visibility and robust intrusion-prevention capabilities.</p></li><li><p>Its performance often means traffic shaping, VPNs, and segmentation don&#8217;t bottleneck the network even under stress.</p></li></ul><p>&#128073; Best for: Medium to large networks, professionals, home labs, and small businesses.</p><p><strong>&#127386; Purple vs. Gold &#8212; Head-to-Head</strong></p><p>TBC</p><p>(&#8230;to be continued&#8230;)</p>]]></content:encoded></item><item><title><![CDATA[ProtonMail: From Privacy Ideal to Something Else]]></title><description><![CDATA[Why I don&#8217;t trust the Swiss-based service anymore]]></description><link>https://digitalseatbelt.substack.com/p/protonmail-from-privacy-ideal-to</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/protonmail-from-privacy-ideal-to</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Wed, 31 Dec 2025 16:09:43 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/286dcc3c-d2a1-4b6e-9b74-7a9fed4e237f_1179x606.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I used to recommend ProtonMail without hesitation.</p><ul><li><p>End-to-end encryption.</p></li><li><p>Zero-access architecture.</p></li><li><p>&#8220;Even we can&#8217;t read your emails.&#8221;</p></li></ul><p>That was the promise&#8212;and for a long time, it felt real.</p><p>But my experience losing access to my account forced me to re-evaluate what &#8220;private&#8221; and &#8220;secure&#8221; actually mean in practice.</p><h4><strong>Losing Access Was the Easy Part</strong></h4><p>Like many privacy-focused users, I enabled strong security:</p><ul><li><p>Password manager</p></li><li><p>Unique credentials</p></li><li><p>Two-factor authentication</p></li></ul><p>Then life happened. A device was lost. 2FA was gone. No backup codes.</p><p>That part is on me.</p><p>What wasn&#8217;t expected was how account recovery worked.</p><h4><strong>The Recovery Questions That Changed My View</strong></h4><p>During the recovery process, I was asked questions along the lines of:</p><ul><li><p>Which services did you sign up to using this email?</p></li><li><p>What kind of emails did you receive?</p></li><li><p>Who did you communicate with?</p></li></ul><p>Think about that for a second.</p><p>To verify identity, I was expected to describe:</p><ul><li><p>My inbox contents</p></li><li><p>My digital footprint</p></li><li><p>My relationships with other services</p></li></ul><p>That immediately raises an uncomfortable implication:</p><blockquote><p>If these answers can be verified, then someone must be able to check them.</p></blockquote><p>Even if this is done indirectly, probabilistically, or through metadata alone, it contradicts the spirit of the original claim: &#8220;We have no visibility.&#8221;</p><h4><strong>Privacy in Marketing vs Privacy in Reality</strong></h4><p>I&#8217;m not saying ProtonMail employees are casually reading emails.</p><p>I&#8217;m not saying encryption doesn&#8217;t exist.</p><p>I am saying this:</p><p>True zero-knowledge systems don&#8217;t rely on human judgment of inbox history to restore access.</p><p>If account recovery depends on:</p><ul><li><p>Knowledge of email content</p></li><li><p>Awareness of services linked to the account</p></li><li><p>Behavioral profiling</p></li></ul><p>Then privacy has already been partially traded for usability, compliance, or risk management.</p><p>That trade-off may be intentional.</p><p>It may even be necessary at scale.</p><p>But it should be stated plainly.</p><h4><strong>Conformance Is Subtle, Not Dramatic</strong></h4><p>This isn&#8217;t about some sudden betrayal.</p><p>It&#8217;s about gradual alignment:</p><ul><li><p>With regulators</p></li><li><p>With mainstream users</p></li><li><p>With operational realities</p></li></ul><p>The product that once felt like a tool against the system now feels more like a hardened version within it.</p><p>More polished.</p><p>More compliant.</p><p>Less radical.</p><h2><strong>The Real Lesson</strong></h2><p>If you care deeply about privacy:</p><ul><li><p>Account recovery is the weakest link</p></li><li><p>Convenience always erodes absolutes</p></li><li><p>&#8220;Encrypted&#8221; doesn&#8217;t mean &#8220;unknowable&#8221;</p></li></ul><p>And most importantly:</p><blockquote><p>If losing access means answering questions about your digital life, then your provider knows more than you think&#8212;or at least needs to.</p></blockquote><p>I still respect what ProtonMail helped normalize.</p><p>But I no longer confuse privacy as a philosophy with privacy as a product feature.</p><p>They&#8217;re not the same thing anymore.</p>]]></content:encoded></item><item><title><![CDATA[Beginner-Friendly: How to Try Tails Safely (Step by Step)]]></title><description><![CDATA[If you&#8217;ve never used Tails before, the idea can feel intimidating.]]></description><link>https://digitalseatbelt.substack.com/p/beginner-friendly-how-to-try-tails</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/beginner-friendly-how-to-try-tails</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Sat, 27 Dec 2025 21:22:26 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/b2cea0b3-c5b6-4241-9ea1-e572b5c63159_1179x765.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>If you&#8217;ve never used Tails before, the idea can feel intimidating. It doesn&#8217;t have to be. You can try it safely, legally, and without risking your main computer by treating it like a temporary, read-only experience.</p><p>Here&#8217;s a calm, beginner-friendly way to do it.</p><p><strong>1. Use a Spare USB Stick</strong></p><p>Start with a dedicated USB drive (8&#8211;16 GB is fine).</p><p>Nothing on your computer&#8217;s hard drive will be touched.</p><p>Think of the USB as a temporary key, not a replacement OS.</p><p><strong>2. Use a Normal Computer (That Isn&#8217;t &#8220;Special&#8221;)</strong></p><p>You don&#8217;t need a burner laptop or exotic hardware.</p><ul><li><p>A regular PC or Mac is fine</p></li><li><p>You&#8217;re not installing anything permanently</p></li><li><p>When you shut down, the computer goes back to normal</p></li></ul><p>This is important psychologically: you&#8217;re testing, not committing.</p><p><strong>3. Boot, Don&#8217;t Install</strong></p><p>Tails runs by booting from the USB, not installing itself.</p><p>That means:</p><ul><li><p>No changes to your existing OS</p></li><li><p>No overwriting files</p></li><li><p>No lasting configuration</p></li></ul><p>If something feels uncomfortable, you can simply shut down.</p><p><strong>4. Start With the Defaults</strong></p><p>Tails is intentionally conservative.</p><p>For your first run:</p><ul><li><p>Don&#8217;t enable extra features</p></li><li><p>Don&#8217;t customize persistence</p></li><li><p>Don&#8217;t sign into personal accounts</p></li><li><p>Just explore</p></li></ul><p>The goal is to observe how it behaves, not to do sensitive work yet.</p><p><strong>5. Assume the Network Is Hostile</strong></p><p>Tails is built with this assumption already &#8212; you should mentally adopt it too.</p><ul><li><p>Treat Wi-Fi as untrusted</p></li><li><p>Expect monitoring</p></li><li><p>Avoid logging into real identities</p></li><li><p>Notice how Tails routes traffic carefully by default</p></li></ul><p>This mindset is part of the learning.</p><p><strong>6. Shut Down Properly</strong></p><p>When you&#8217;re done, shut Tails down normally.</p><p>This is the moment that makes everything click:</p><ul><li><p>Memory is wiped</p></li><li><p>Sessions disappear</p></li><li><p>Nothing persists unless you explicitly allowed it</p></li></ul><p>The machine forgets you &#8212; completely.</p><p><strong>7. Reflect Before Repeating</strong></p><p>After your first session, ask yourself:</p><ul><li><p>What felt different?</p></li><li><p>What felt slower &#8212; and why?</p></li><li><p>What did I not miss?</p></li><li><p>What did I suddenly become more aware of?</p></li></ul><p>That reflection is where most of the value lies.</p><h3><strong>A Final Safety Note</strong></h3><p>Trying Tails doesn&#8217;t mean:</p><ul><li><p>You&#8217;re doing anything illegal</p></li><li><p>You&#8217;re hiding something</p></li><li><p>You need to change your daily workflow</p></li></ul><p>It&#8217;s simply a learning exercise &#8212; like driving a manual car to better understand automatics.</p><h3><strong>Why This Matters</strong></h3><p>Once you&#8217;ve tried Tails even once, you&#8217;ll never look at operating systems the same way again.</p><p>You&#8217;ll notice:</p><ul><li><p>How much other systems remember by default</p></li><li><p>How rarely we question persistence</p></li><li><p>How powerful &#8220;temporary computing&#8221; can be</p></li></ul><p>And that awareness carries over &#8212; even when you go back to your regular OS.</p>]]></content:encoded></item><item><title><![CDATA[Evil Twin Attacks ]]></title><description><![CDATA[When the Wi-Fi Lies to You]]></description><link>https://digitalseatbelt.substack.com/p/evil-twin-attacks</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/evil-twin-attacks</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Wed, 26 Nov 2025 16:26:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/635c489b-abe4-4e4e-985e-a16e2413a4b5_1240x414.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Free Wi-Fi feels harmless. But sometimes, the network you connect to isn&#8217;t the caf&#233;, hotel, or airport at all &#8212; it&#8217;s an attacker.</p><p>That&#8217;s called an evil twin attack.</p><div><hr></div><h4><strong>What Is an Evil Twin Attack?</strong></h4><p>An evil twin is a fake Wi-Fi network that pretends to be a real one.</p><p>For example:</p><ul><li><p>&#8220;CoffeeShop_WiFi&#8221;</p></li><li><p>&#8220;Airport_Free_WiFi&#8221;</p></li><li><p>&#8220;Hotel_Guest&#8221;</p></li></ul><p>Your phone or laptop connects because the name looks familiar &#8212; or because the signal is stronger. From that moment on, all your traffic passes through the attacker first.</p><div><hr></div><h4><strong>What Can an Attacker Do?</strong></h4><p>Once you&#8217;re connected, an attacker may be able to:</p><ul><li><p>Capture login credentials</p></li><li><p>Steal session cookies</p></li><li><p>Intercept unencrypted traffic</p></li><li><p>Redirect you to fake login pages</p></li><li><p>Track what sites you visit</p></li></ul><p>Even when encryption is used, metadata and mistakes still leak valuable information.</p><div><hr></div><h4><strong>The Wi-Fi Pineapple (Yes, It&#8217;s really called that)</strong></h4><p>Devices like the Wi-Fi Pineapple, made by Hak5, are specifically designed to demonstrate how easy these attacks can be.</p><p>The Pineapple can:</p><ul><li><p>Broadcast multiple fake networks</p></li><li><p>Clone legitimate SSIDs</p></li><li><p>Automatically attract nearby devices</p></li><li><p>Perform man-in-the-middle attacks for testing and training</p></li></ul><p>It&#8217;s widely used by:</p><ul><li><p>Penetration testers</p></li><li><p>Security researchers</p></li><li><p>Red teams</p></li><li><p>Educators</p></li></ul><p>The important takeaway isn&#8217;t the gadget &#8212; it&#8217;s how low the barrier is.</p><div><hr></div><h4><strong>Why Evil Twins Work So Well</strong></h4><p>Evil twin attacks succeed because:</p><ul><li><p>Devices auto-connect to known networks</p></li><li><p>People trust familiar Wi-Fi names</p></li><li><p>Public spaces normalize insecure networks</p></li><li><p>Most users never verify what they&#8217;re connecting to</p></li></ul><p>The attack exploits human behavior, not technical weakness.</p><div><hr></div><h4><strong>How to Protect Yourself</strong></h4><p><strong>1. Avoid public Wi-Fi when possible: </strong>Especially for banking or sensitive accounts.</p><p><strong>2. Turn off auto-connect: </strong>Don&#8217;t let your device join networks without asking.</p><p><strong>3. Use a VPN (carefully): </strong>VPN helps, but only if it connects before anything else loads.</p><p><strong>4. Prefer mobile hot-spots: </strong>Your device is usually safer than public Wi-Fi.</p><p><strong>5. Watch for captive portals: </strong>Unexpected login pages are a red flag.</p><div><hr></div><h4><strong>The Bigger Lesson</strong></h4><p>Evil twin attacks remind us of a core security rule:</p><blockquote><p>Convenience is often the enemy of safety.</p></blockquote><p>Wi-Fi names can be faked. Signals can be spoofed. Trust should be earned &#8212; not assumed.</p><p>Staying safe doesn&#8217;t mean being paranoid. It means being deliberate about what you connect to.</p>]]></content:encoded></item><item><title><![CDATA[Compartmentalised Email]]></title><description><![CDATA[Why Using Multiple Email Addresses Is a Smart Security Habit]]></description><link>https://digitalseatbelt.substack.com/p/compartmentalised-email</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/compartmentalised-email</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Sun, 26 Oct 2025 16:18:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/4e47ac44-0a91-4885-92d9-59a5e521c8c7_661x360.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most people use one email for everything &#8212; banking, social media, newsletters, work, sign-ups. That makes life convenient&#8230; and risky.</p><p>Using multiple email addresses is one of the simplest, highest-impact security habits you can adopt.</p><div><hr></div><h3><strong>The Core Idea: Segregation</strong></h3><p>Think of email like keys. You wouldn&#8217;t use the same key for your house, office, and storage unit. Multiple emails let you separate risk:</p><ul><li><p>One for banks and critical accounts</p></li><li><p>One for personal communication</p></li><li><p>One for sign-ups and newsletters</p></li></ul><p>If one gets compromised, the rest stay safe.</p><div><hr></div><h3><strong>Why It Matters</strong></h3><p><strong>1. Fewer account takeovers</strong></p><p>If a shopping site leaks your email, attackers can&#8217;t immediately reach your bank.</p><p><strong>2. Easier phishing detection</strong></p><p>A &#8220;bank&#8221; email arriving at your throwaway inbox is an instant red flag.</p><p><strong>3. Less spam, more control</strong></p><p>You can mute, rotate, or abandon a noisy address without disruption.</p><p><strong>4. Cleaner digital life</strong></p><p>Important messages don&#8217;t get buried under promotions.</p><div><hr></div><h3><strong>Keep It Simple</strong></h3><p>You don&#8217;t need dozens of inboxes. Start with three:</p><ul><li><p>Core (finance, government, recovery)</p></li><li><p>Personal (friends, family)</p></li><li><p>Disposable (sign-ups, trials)</p></li></ul><p>That alone dramatically reduces risk.</p><div><hr></div><h3><strong>The Bottom Line</strong></h3><p>Security isn&#8217;t about complicated tools &#8212; it&#8217;s about good defaults.</p><p>Multiple email addresses turn one fragile identity into several safer ones.</p><p>Small change. Big payoff.</p>]]></content:encoded></item><item><title><![CDATA[Burner Phones]]></title><description><![CDATA[Why They Still Matter in a Smartphone World]]></description><link>https://digitalseatbelt.substack.com/p/burner-phones</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/burner-phones</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Fri, 26 Sep 2025 16:11:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/c6c86b91-3c21-42e1-a490-5d2d5fd55afa_740x415.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><p>Burner phones might sound like something from crime dramas, but in reality they&#8217;re a simple, legal, and practical privacy tool for ordinary people. In a world where your phone number has quietly become a permanent ID, burner phones still serve a useful purpose.</p><p>This post explains what burner phones are, why people use them, and when they actually make sense.</p><p><strong>What Is a Burner Phone?</strong></p><p>A burner phone is usually:</p><ul><li><p>A cheap, prepaid phone</p></li><li><p>Bought without a long-term contract</p></li><li><p>Used for a specific purpose or short time</p></li><li><p>Discarded or powered down afterward</p></li></ul><p>It can be a basic feature phone or a low-cost smartphone. The key idea isn&#8217;t secrecy for wrongdoing &#8212; it&#8217;s separation.</p><p><strong>The Core Benefit: Separation</strong></p><p>Your primary phone number is tied to:</p><ul><li><p>Your name</p></li><li><p>Your bank</p></li><li><p>Your email</p></li><li><p>Your social accounts</p></li><li><p>Your contacts</p></li><li><p>Your location history</p></li></ul><p>A burner phone lets you separate one activity from the rest of your digital life. That alone reduces risk.</p><p>Think of it like using a guest email address &#8212; but for calls and texts.</p><p><strong>Legitimate Reasons People Use Burner Phones</strong></p><ol><li><p><strong>Reducing Spam &amp; Data Leaks</strong></p></li></ol><p>Phone numbers are constantly leaked, sold, and reused.</p><p>Using a burner number for:</p><ul><li><p>Online sign-ups</p></li><li><p>Marketplaces</p></li><li><p>One-time verifications</p></li></ul><p>keeps your main number cleaner and quieter.</p><ol start="2"><li><p><strong>Personal Safety</strong></p></li></ol><p>Burner phones are commonly used by:</p><ul><li><p>Journalists</p></li><li><p>Activists</p></li><li><p>People leaving abusive situations</p></li><li><p>Online sellers meeting strangers</p></li><li><p>Travelers in unfamiliar places</p></li></ul><p>If a number gets shared or compromised, it can simply be abandoned.</p><ol start="3"><li><p><strong>Travel &amp; Temporary Use</strong></p></li></ol><p>When traveling:</p><ul><li><p>A local prepaid SIM or burner phone avoids roaming fees</p></li><li><p>Limits exposure if the phone is lost or stolen</p></li><li><p>Keeps your primary device safe</p></li></ul><p>If something happens, the damage is contained.</p><ol start="4"><li><p><strong>Professional Boundaries</strong></p></li></ol><p>Freelancers, founders, and consultants often use burner numbers to:</p><ul><li><p>Keep work and personal life separate</p></li><li><p>Avoid clients having permanent access</p></li><li><p>Shut down a number after a project ends</p></li></ul><p>This is about mental health as much as security.</p><ol start="5"><li><p><strong>Low-Tech Reliability</strong></p></li></ol><p>Basic burner phones:</p><ul><li><p>Have long battery life</p></li><li><p>Fewer attack surfaces</p></li><li><p>No app tracking</p></li><li><p>No constant internet connection</p></li></ul><p>In emergencies, simplicity is a feature.</p><p><strong>What Burner Phones Don&#8217;t Do</strong></p><p>It&#8217;s important to be realistic.</p><p>Burner phones do not:</p><ul><li><p>Make you invisible</p></li><li><p>Protect against all surveillance</p></li><li><p>Automatically guarantee anonymity</p></li><li><p>Replace good security habits</p></li></ul><p>They are risk-reduction tools, not magic cloaks.</p><p><strong>Burner Phones vs Apps</strong></p><p>Some people use virtual numbers or apps instead. These are convenient, but:</p><ul><li><p>They rely on accounts</p></li><li><p>They can be suspended</p></li><li><p>They log metadata</p></li><li><p>They&#8217;re tied to app ecosystems</p></li></ul><p>Physical burner phones still win on simplicity and independence.</p><p><strong>When a Burner Phone Makes Sense</strong></p><p>A burner phone is useful when:</p><ul><li><p>You want temporary contact</p></li><li><p>You don&#8217;t trust how a number will be stored</p></li><li><p>You need clear separation</p></li><li><p>You want something disposable, not permanent</p></li></ul><p>If you&#8217;re asking &#8220;Do I really need my real number for this?&#8221; &#8212; the answer is often no.</p><p><strong>The Bigger Picture</strong></p><p>Privacy isn&#8217;t about hiding &#8212; it&#8217;s about control.</p><p>Burner phones give you:</p><ul><li><p>Choice</p></li><li><p>Flexibility</p></li><li><p>Fewer permanent digital footprints</p></li></ul><p>In a world where everything defaults to permanent, temporary tools are powerful.</p><p>Bottom line:</p><p>You don&#8217;t need to be paranoid to care about privacy. Sometimes, the simplest solution is just&#8230; a second phone.</p>]]></content:encoded></item><item><title><![CDATA[Using Linux vs Other Operating Systems]]></title><description><![CDATA[My Experience with Tails and Amnesiac Computing]]></description><link>https://digitalseatbelt.substack.com/p/using-linux-vs-other-operating-systems</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/using-linux-vs-other-operating-systems</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Wed, 27 Aug 2025 20:17:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/a5f14ab2-6c18-4ef3-962a-aeac58ca0f89_1179x600.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Most people choose an operating system for convenience. I started thinking about operating systems because of what they remember about you.</p><p>That&#8217;s where Linux &#8212; and especially Tails &#8212; changed how I think about security entirely.</p><h3><strong>The Hidden Difference Between Operating Systems</strong></h3><p>Windows and macOS are built around a simple assumption:</p><blockquote><p>This is your computer. It should remember everything.</p></blockquote><p>That includes:</p><ul><li><p>Files</p></li><li><p>Wi-Fi networks</p></li><li><p>Logs</p></li><li><p>Application history</p></li><li><p>Metadata</p></li><li><p>Usage patterns</p></li></ul><p>For everyday use, that&#8217;s fine.</p><p>For privacy and threat-aware use, it&#8217;s a liability.</p><p>Linux can behave differently &#8212; and Tails takes that idea to its logical extreme.</p><h3><strong>What &#8220;Amnesiac&#8221; Actually Means</strong></h3><p>Tails describes itself as an amnesiac operating system, and that&#8217;s not marketing fluff.</p><p>In practice, it means:</p><ul><li><p>It runs entirely from a USB stick</p></li><li><p>It uses your computer&#8217;s memory, not its hard drive</p></li><li><p>When you shut it down, everything disappears</p></li><li><p>No files, logs, or traces are left behind by default</p></li></ul><p>The first time you experience this, it&#8217;s unsettling &#8212; and then incredibly freeing.</p><h3><strong>My Experience Using Tails</strong></h3><p>Using Tails feels less like &#8220;owning&#8221; a computer and more like borrowing one responsibly.</p><p>You become aware of things you normally ignore:</p><ul><li><p>What network you&#8217;re on</p></li><li><p>What applications really need internet access</p></li><li><p>What data actually needs to persist</p></li><li><p>What doesn&#8217;t</p></li></ul><p>There&#8217;s no silent accumulation of digital residue. Each session starts clean.</p><p>That mindset alone changes your behavior &#8212; even when you&#8217;re not using Tails.</p><h3><strong>Linux vs Windows / macOS (Philosophically)</strong></h3><p>This isn&#8217;t about one OS being &#8220;better.&#8221; It&#8217;s about intent.</p><ul><li><p>Windows / macOS<br>Designed for permanence, integration, and convenience. Great for productivity. Weak by default for privacy.</p></li><li><p>Linux (general)<br>Gives you choice. You decide what runs, what logs, what persists.</p></li><li><p>Tails (specific)<br>Assumes the environment is hostile. Assumes the computer isn&#8217;t yours. Assumes traces are dangerous.</p></li></ul><p>Those assumptions matter.</p><h3><strong>Why Amnesia Is a Feature</strong></h3><p>In security, fewer traces mean:</p><ul><li><p>Less forensic footprint</p></li><li><p>Less historical exposure</p></li><li><p>Less damage if a device is seized, stolen, or compromised</p></li></ul><p>Tails forces a question most systems never ask:</p><blockquote><p>Do I actually need to keep this?</p></blockquote><p>Most of the time, the answer is no.</p><h3><strong>What Tails Is (and Isn&#8217;t) Good For</strong></h3><p>Good for:</p><ul><li><p>Sensitive research</p></li><li><p>Travel</p></li><li><p>Journalism</p></li><li><p>Activism</p></li><li><p>Learning how systems really work</p></li><li><p>Resetting your mental model of computing</p></li></ul><p>Not ideal for:</p><ul><li><p>Daily productivity</p></li><li><p>Gaming</p></li><li><p>Long-term projects</p></li><li><p>Heavy customization</p></li><li><p>Anything that relies on persistence by default</p></li></ul><p>It&#8217;s a tool &#8212; not a lifestyle OS.</p><h3><strong>The Real Lesson Linux Taught Me</strong></h3><p>Tails didn&#8217;t just change what OS I use. It changed how I think.</p><p>It made me realize that:</p><ul><li><p>Persistence is optional</p></li><li><p>Convenience always has a cost</p></li><li><p>&#8220;Normal&#8221; computing leaks more than people realize</p></li><li><p>Security is often about subtraction, not addition</p></li></ul><p>Once you experience an operating system that forgets you completely, it&#8217;s hard not to question why others remember so much.</p><h3><strong>Final Thought</strong></h3><p>You don&#8217;t need to run Tails every day to benefit from it.</p><p>But everyone who cares about privacy should experience amnesiac computing at least once &#8212; if only to understand how different the defaults could be.</p>]]></content:encoded></item><item><title><![CDATA[Testing Out GrapheneOS ]]></title><description><![CDATA[I kept losing phones and decided to try out a secure device]]></description><link>https://digitalseatbelt.substack.com/p/testing-out-grapheneos</link><guid isPermaLink="false">https://digitalseatbelt.substack.com/p/testing-out-grapheneos</guid><dc:creator><![CDATA[The Digital Seatbelt]]></dc:creator><pubDate>Fri, 11 Jul 2025 00:41:00 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/cdf05f76-9a6c-47f9-9ab8-1232b2df79d1_1179x868.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>I Installed GrapheneOS&#8212; First Impressions</strong></p><p>I didn&#8217;t install GrapheneOS because it looked cool. I installed it because I wanted to know what happens when a phone OS is built with the assumption that everything will try to spy on you.</p><p>After running it as a daily driver, here&#8217;s the honest take.</p><h2><strong>Installation: Serious, but Clean</strong></h2><p>The install process was refreshingly no-nonsense. No sketchy scripts, no weird flashing rituals. It felt more like provisioning a secure device than modding a phone.</p><p>That tone carries through the whole OS:</p><p>you&#8217;re expected to know what you&#8217;re doing, but you&#8217;re never fighting the system.</p><p>Once it booted, the first thing I noticed wasn&#8217;t what was missing &#8212; it was how quiet everything felt.</p><h2><strong>First Boot: No Noise, No Assumptions</strong></h2><p>There&#8217;s no Google account prompt.</p><p>No &#8220;helpful&#8221; onboarding.</p><p>No services waking up behind your back.</p><p>You start with a clean slate and build upwards. That changes your mindset immediately. You stop thinking &#8220;what do I turn off?&#8221; and start thinking &#8220;what do I actually need?&#8221;</p><p>That alone is powerful.</p><h2><strong>Daily Use: Boring in the Best Way</strong></h2><p>Most apps worked exactly as expected. Messaging, banking, browsers &#8212; all fine. But the difference is control.</p><p>For example:</p><ul><li><p>I could install Google Play only for the apps that needed it</p></li><li><p>Then restrict its network access</p></li><li><p>Limit background activity</p></li><li><p>Revoke sensors entirely</p></li></ul><p>Google became just another app.</p><p>That&#8217;s a wild feeling the first time you do it.</p><h2><strong>Permissions Finally Mean Something</strong></h2><p>On GrapheneOS, permissions aren&#8217;t polite suggestions.</p><p>If an app doesn&#8217;t get network access, it simply doesn&#8217;t talk.</p><p>If it doesn&#8217;t get sensors, it&#8217;s blind and deaf.</p><p>If it doesn&#8217;t get storage, it gets nothing.</p><p>I caught myself checking permissions more, not less &#8212; because it was finally worth checking.</p><h2><strong>Security You Can Feel (Even If You Can&#8217;t See It)</strong></h2><p>There&#8217;s a subtle confidence that comes from knowing:</p><ul><li><p>Apps are hard-sandboxed</p></li><li><p>Memory exploitation is significantly harder</p></li><li><p>Attack surfaces are reduced by default</p></li><li><p>The OS is designed to fail safely</p></li></ul><p>Nothing flashy pops up saying &#8220;you are secure.&#8221;</p><p>It just&#8230; stays stable. Predictable. Uninteresting.</p><p>That&#8217;s exactly what you want.</p><h2><strong>Trade-Offs (Because There Are Some)</strong></h2><p>Let&#8217;s be honest:</p><ul><li><p>Some apps expect Google everywhere</p></li><li><p>Push notifications can require setup</p></li><li><p>You&#8217;ll think more about app choices</p></li><li><p>Convenience takes a small hit</p></li></ul><p>But none of this felt painful. It felt intentional &#8212; like choosing Linux over macOS, or Tails over a mainstream OS when privacy actually matters.</p><h2><strong>Would I Run It Again?</strong></h2><p>Yes &#8212; without hesitation.</p><p>GrapheneOS feels like a phone for people who understand that security isn&#8217;t a feature, it&#8217;s a posture. You trade a bit of convenience for clarity, control, and a radically reduced trust surface.</p><p>After using it, going back to stock Android feels&#8230; noisy.</p><h2><strong>Final Thought</strong></h2><p>Installing GrapheneOS changed how I think about phones.</p><p>Not as personal assistants &#8212; but as attack surfaces that need boundaries.</p><p>If you care about:</p><ul><li><p>Compartmentalization</p></li><li><p>Real permission enforcement</p></li><li><p>Optional trust instead of mandatory trust</p></li></ul><p>GrapheneOS isn&#8217;t extreme.</p><p>It&#8217;s what a modern secure phone should look like.</p>]]></content:encoded></item></channel></rss>