<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Chris Worth</title><link>https://chrisworth.dev/skill-tag/security/</link><description>Recent content in Security on Chris Worth</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 13 Nov 2025 13:00:00 -0600</lastBuildDate><atom:link href="https://chrisworth.dev/skill-tag/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Leaving Gmail: Practical, Secure Alternatives That Respect Your Privacy</title><link>https://chrisworth.dev/posts/leaving-gmail-secure-alternatives/</link><pubDate>Thu, 13 Nov 2025 13:00:00 -0600</pubDate><guid>https://chrisworth.dev/posts/leaving-gmail-secure-alternatives/</guid><description>&lt;p>Most people think Gmail is &amp;ldquo;secure enough&amp;rdquo; because it has good spam filtering and supports MFA. That&amp;rsquo;s not the same thing as privacy, ownership, or control. And once you understand what Gmail actually collects and how dependent your digital life has become on a single commercial identity provider, it becomes clear that staying on Gmail is a long-term liability.&lt;/p>
&lt;p>This isn’t about paranoia. It’s about reducing exposure, tightening control over your data, and choosing an email setup that aligns with how you want to operate in the next decade.&lt;/p></description></item><item><title>Modern Password Security: Why Everything You Were Taught Is Wrong</title><link>https://chrisworth.dev/posts/enterprise-password-security-best-practices/</link><pubDate>Tue, 11 Mar 2025 09:00:00 -0600</pubDate><guid>https://chrisworth.dev/posts/enterprise-password-security-best-practices/</guid><description>&lt;p>I spent years following password rules that made security worse. Change passwords every 90 days, use uppercase, lowercase, numbers, and symbols, never reuse passwords. Under those rules, &amp;ldquo;Spring2025!&amp;rdquo; rotating to &amp;ldquo;Summer2025!&amp;rdquo; rotating to &amp;ldquo;Fall2025!&amp;rdquo; is fully compliant, and that&amp;rsquo;s exactly the problem: the rules select for compliance, not for unpredictability.&lt;/p>
&lt;p>I checked passwords built that way against breach databases anyway, out of habit more than doubt. Every single one appeared in credential dumps available to anyone willing to look. The rules designed to protect me were training me to be predictable.&lt;/p></description></item></channel></rss>