// network engineering · anonymity · privacy
Hard networks.
Soft footprint.
Engineering guides on network security, anonymity, and self-hosted privacy infrastructure. For builders who want to understand the stack — not just buy a sticker.
// what we cover
Four topic clusters.
Network Hardening
Kernel, firewall, sysctl, and access-control playbooks for anyone running their own network edge.
Anonymity Engineering
DNS, IPv6, fingerprinting, traffic analysis — the gap between 'private-ish' and actually unlinkable.
Self-Hosted Privacy
Run your own WireGuard, Tailscale, Headscale, or sing-box stack from a $5/month VPS.
Corporate Networks
Zero-trust architecture, mesh VPNs, and secure access for distributed teams without SaaS lock-in.
// latest
Recent articles.
Self-hosted WireGuard on a $5 VPS in 2026
End-to-end setup with hardened sysctl, multi-client config, and DNS hygiene that doesn't leak.
Xray Reality vs WireGuard: when to use which
Two protocols, two threat models. A field guide for picking the right tool for your network.
Network OPSEC checklist for engineers
DNS leaks, IPv6 leaks, mDNS, NetBIOS — the things that betray you before encryption matters.
// stay in the loop
Get one good post per week.
New guides on network hardening, anonymity, and self-hosted privacy. No spam, unsubscribe anytime.