One author, on the record

Every guide on this site is researched and written by me, Luiz Torres, a software developer. I don't use ghostwriters and I don't publish anything I haven't verified myself. That has an honest downside — there is no second reviewer catching my mistakes before publication — which is exactly why the correction policy below exists and why every factual claim must point somewhere you can check.

The rules each article must pass

  • Claims trace to primary sources. Password guidance follows NIST SP 800-63B; passphrase math is benchmarked against the EFF wordlists; breach statistics come from disclosed incidents and Have I Been Pwned. If I can't source a claim, I cut it.
  • The math is shown, not asserted. Entropy figures and crack-time estimates appear with the formula that produced them, so a reader can recompute and disagree.
  • Dates are real.The published and updated dates on each article reflect when it actually shipped, taken from the site's version history — not a content calendar.
  • No pay-to-play. When an article names a product (a password manager, an authenticator app, a hardware key), nobody paid for the mention and there are no affiliate links. The site earns from display ads only, which are unrelated to what the articles say.

What these guides are not

They are general education for everyday users, written by an engineer — not a security consultancy and not advice tailored to your threat model. If you are a journalist, an activist, or anyone facing a targeted attacker, you need guidance beyond what a website can give you.

Found an error? Tell me and I'll fix it

Corrections outrank everything else I do on this site. Email contact@passwordmake.com (or use the contact page) with a link to the article and the sentence you think is wrong. If you're right, I'll fix the article and update its "updated" date; if I can't verify it either way, I'll say so rather than leave a shaky claim standing.