Reference
Glossary
Jargon is the barrier, not the concepts. Anything a lesson uses is defined here, and marked inline where it first appears so you never have to leave the page to find out what a word means.
- Browser fingerprint
- A near-unique profile of your device built from the small ways your browser differs from everyone else's — no cookies required.A browser fingerprint is assembled from dozens of small signals: your screen size, fonts, timezone, graphics hardware, language and more. Combined, they are often unique enough to recognise you across sites and sessions without any stored identifier — which is why deleting cookies does not make you a stranger, and why a rare, "hardened" setup can stand out more, not less.
- Compartmentalisation
- Keeping separate parts of your life in separate identities that share nothing — so a breach or a link in one cannot spread to the others.Compartmentalisation is the discipline of separate identities with no shared username, email, device habit or payment method between them. Its value is containment: if one identity is exposed or compromised, the walls stop it reaching the rest. The hard part is not creating the compartments but never letting them touch — one careless cross-post can collapse them into one.
- Cookie
- A small labelled note a website asks your browser to keep and hand back on your next visit — how a site remembers you between pages.A cookie is set by a site and returned on later requests to that site. Its own site's cookies (first-party) are what keep you logged in. The tracking problem is third-party cookies: the same advertiser embedded on many sites sets one cookie that follows you across all of them. This is the mechanism browsers are now dismantling — which pushes trackers toward fingerprinting.
- Credential stuffing
- Taking username-and-password pairs leaked from one site and trying them automatically on hundreds of others, betting that people reuse them.When a site is breached, the stolen email-and-password pairs are traded and then replayed against banks, email and shops by the million. It works because reuse is common: one old breach becomes a key to everything that shares the password. A unique password per site defeats it entirely.
- DNS
- The internet's phone book: it turns a name you type, like example.com, into the numeric address a computer connects to.Every time you visit a site, your device first asks a DNS server for its address. By default that question is sent in the clear to a server chosen by your ISP, so even when the page itself is encrypted, the lookup quietly announces where you are going. This is one of the leaks a VPN is supposed to close and often does not.
- EXIF
- Hidden data a camera writes inside a photo file — often including the exact time and GPS coordinates the picture was taken.EXIF is metadata embedded in an image by the device that made it. It can include the camera model, the settings, the timestamp and, on a phone with location on, the precise place. It travels with the file unless something strips it, which is why a photo shared as a raw file can quietly reveal a home address.
- End-to-end encryption
- Encryption where only the sender and the recipient can read a message — not the app's company, not the network, not anyone in between.With end-to-end encryption (E2EE) a message is scrambled on your device and unscrambled only on the recipient's, so the service carrying it holds only ciphertext it cannot read. It is the difference between a service that protects your messages from itself and one that merely protects them from outsiders while reading them itself.
- Forward secrecy
- A property where stealing today's keys does not unlock yesterday's messages — each conversation is protected even if a key later leaks.Forward secrecy means the keys that encrypt your messages are constantly replaced and old ones discarded, so a key compromised tomorrow cannot decrypt the messages you sent today. It is why a well-designed messenger limits the damage of a future breach to the moment of the breach, not your entire history.
- IP address
- The number that identifies where your traffic comes from on the internet — roughly, which door it should be delivered back to.An IP address is assigned by whoever provides your connection. On its own it usually points at a household or a coffee shop rather than a person, but combined with the records your ISP keeps it can often be traced to an account. Hiding it is what a VPN or Tor actually does; it is also only one of the many ways you are identified online.
- ISP
- Your internet service provider — the company whose wire or signal you use to reach the internet, and which can see every site you connect to.Because all your traffic passes through the ISP, it sees the address of every server you talk to, and in many countries is required to keep those records and hand them over on request. Encryption hides the contents of a page from them; it does not hide which site you visited unless you also hide the lookup and the destination address.
- Metadata
- Data about your data — not what you said, but who you said it to, when, from where, and how often.Metadata is usually more revealing than content and far harder to hide. Who you called, for how long, and from where can map your whole life without a single word of the conversation being known. Encryption protects content; protecting metadata is a separate and much harder problem.
- OSINT
- Open-source intelligence — finding out about someone using only public information: profiles, posts, records, and the links between them.OSINT is the discipline of assembling public fragments into a picture: a reused username, an old profile, a photo's caption, a data-breach record. No hacking is involved, which is exactly why it is so effective and so hard to defend against — the information was published, usually by the person themselves, and cannot be un-published.
- PID
- A process ID — the unique number the system gives each running process so you can refer to exactly one of them.Every process has a PID. It is how you point at a specific running program to inspect it or stop it, even when several copies of the same program are running. Find the PID, and you can act on precisely that one and no other.
- Password manager
- An encrypted vault that generates and remembers a different strong password for every account, so you only have to remember one.A password manager removes the reason people reuse passwords: memory. It creates a long random password per site, stores them encrypted behind one strong master passphrase, and fills them in for you. It is the single highest-impact change most people can make to their security, and it makes a breach of one site stay contained to that site.
- Path
- The address of a file or folder in the system's single tree — the sequence of folders to reach it, separated by slashes.An absolute path starts from the root, /, and names every folder down to the target, like /home/wren/notes.txt. A relative path starts from wherever you currently are. Both point at the same tree; the only difference is where they begin. Getting comfortable with the difference is most of what "not getting lost in the terminal" means.
- Permissions
- The rules on each file saying who may read it, change it, or run it — split between its owner, its group, and everyone else.Every file carries three sets of three permissions: read, write and execute, for the owner, the group, and everyone else. They are how a system shared by many users stops one from reading or wrecking another's files, and they are the first thing to check when something "will not run" or a secret is exposed.
- Phishing
- Tricking you into handing your credentials to an impostor — a fake login page or message that looks like the real thing.Phishing does not break the lock; it convinces you to open it. A message or page impersonates a service you trust and asks you to sign in, capturing what you type — including a one-time two-factor code, if the attacker relays it to the real site immediately. It is why hardware security keys, which refuse to authenticate to the wrong site, matter for accounts that hold real value.
- Pipe
- The "|" that connects two commands, sending the output of the first straight in as the input of the second.A pipe joins programs into an assembly line: each command reads what the previous one produced, does its one job, and passes the result on. It is the mechanism behind the Unix philosophy of small sharp tools, and it is why a handful of simple commands can answer questions no single one of them was built for.
- Process
- One running program — a single instance of something the computer is doing right now, with its own identity and resources.A process is a program in motion: the browser you have open, the shell you are typing in, the server answering requests are each one or more processes. The system runs many at once, gives each an id, and lets you see and control them. Understanding processes is how you answer "what is this machine actually doing?" and "why is it slow?".
- Root directory
- The single folder, written /, that everything else lives inside — the top of the one tree the whole system is arranged as.Unlike systems with separate drive letters, a Unix-like system has exactly one tree, and / is its base. Every disk, device and file appears somewhere inside it. This single-tree idea — that everything has one place in one hierarchy — is the organising principle the rest of the system builds on.
- Shell
- The program that reads the commands you type and asks the operating system to carry them out — your conversation with the machine.A shell is a text interface to the operating system: you type a command, it runs it and shows the result. Bash and zsh are common ones. It feels intimidating because it says nothing until asked, but that same plainness is why it is precise, scriptable, and the same across almost every server on the internet.
- Signal
- A short message sent to a process to tell it something — most commonly, to stop.Signals are how you communicate with a running process from outside it. The gentle one asks it to shut down cleanly and save its work; the forceful one ends it immediately with no chance to tidy up. Knowing the difference is the whole of stopping programs safely.
- Standard streams
- The three channels every command has: input (stdin), normal output (stdout), and errors (stderr), kept separate on purpose.Every command reads from standard input, writes results to standard output, and sends error messages to a separate standard error. Keeping errors on their own channel is what lets you pipe the results onward without the complaints getting mixed in, and redirect each independently.
- TLS
- The encryption behind the padlock — it scrambles the contents of a page between your device and the site so nobody in between can read it.TLS (the S in HTTPS) protects the contents of your traffic from anyone on the path: your ISP, the coffee-shop network, a VPN provider. It does not hide which site you are talking to, and it says nothing about whether the site itself is trustworthy with what you send it.
- Terminal
- The window that shows a shell — the place where you type commands and read their output.Strictly, the terminal is the display-and-keyboard surface and the shell is the program running inside it, but in everyday use people say "the terminal" for both. It is the oldest interface a computer has and, for many tasks, still the fastest and most exact.
- Threat model
- Four honest answers: what you are protecting, from whom, what happens if it fails, and how much trouble you will go to.Threat modelling is the step almost everyone skips, and skipping it is why people buy tools they do not need and ignore the ones they do. It is not a technical exercise. Writing down who you are actually worried about — an advertiser, an abusive ex, an employer, a government — changes the answer to every question that follows, because those adversaries have wildly different budgets, powers and levels of interest in you specifically.
- Tor
- A network that bounces your traffic through three volunteer relays so no single one knows both who you are and what you are visiting.Tor spreads trust across three independent relays instead of the one a VPN asks you to trust completely: the first knows your address but not your destination, the last knows the destination but not your address. It is slower than a VPN and the right tool for a very different threat model — when you need no single party to be able to link you to what you did.
- Two-factor authentication (2FA)
- A second proof of identity beyond your passphrase — usually a code or a hardware key — so a stolen passphrase alone cannot open your account.Two-factor authentication pairs something you know (a passphrase) with something you have (a one-time code from an app, or a physical security key). An attacker who learns your passphrase still lacks the second factor. The factors are not equal: an app code resists a leaked-password list but can be phished in real time, while a hardware security key is bound to the real site and cannot be handed to an impostor.
- VPN
- A tunnel that moves your traffic’s exit point. It shifts trust from your ISP to the VPN company — it does not make you anonymous.A VPN is a genuinely useful tool for a narrow set of problems: hostile local networks, an ISP that sells browsing records, and geographic restrictions. It is not an anonymity tool. Your traffic still leaves somewhere, that somewhere is a company with servers and a jurisdiction, and you have chosen to trust it instead of your ISP. Whether that is an upgrade depends entirely on which of the two you were worried about.
- grep
- The search tool: it reads lines and prints only the ones that match a pattern you give it.grep filters text to the lines that match. Fed a file it searches the file; placed after a pipe it searches whatever the previous command produced. It is the single most-reached-for tool on the command line, because "show me only the lines that matter" is the most common thing you ever want.
- root
- The all-powerful administrator account on a Unix system, allowed to do absolutely anything — including irreversible damage.root (the superuser) bypasses every permission check. That makes it necessary for real administration and dangerous for everything else: a mistake as root has no guard rails. The discipline of modern systems is to work as a normal user and borrow root's power briefly, through sudo, only when a task needs it.
- sudo
- "Do this one command as the superuser" — a controlled, logged way to borrow administrator power for a single action rather than living with it.sudo runs a single command with elevated privileges after checking you are allowed to, and records that you did. It is the modern alternative to logging in as root: you stay an ordinary user, and reach for full power deliberately, one command at a time, leaving a trail.