Learn how security works, starting from zero.
Short lessons in plain language, each with something you can try. Most topics take one sitting, and you never need a degree or a special setup to follow along.
Try the oldest cipher
Julius Caesar is said to have shifted every letter in a message by a fixed number. Type something and move the slider.
Plain letter
Becomes
There are only 25 useful shifts, so anyone can try them all in a few seconds. That weakness is why modern encryption exists, and it’s where the lessons below begin.
Before you start
You don’t need to know how to code. If you can use a web browser and are curious about how things break, you have enough to begin.
The path below goes in order, and each stage builds on the last. If you already know a stage, skip it. If something feels shaky later, come back. Nobody is checking.
The beginner path
Five stages, from how a computer talks to another computer to how a team responds when something goes wrong.
1. How computers talk to each other
Every attack and every defense happens on a network. Start by understanding what actually travels between your laptop and a website.
6 topics, about 4 hours
- What happens when you open a website
- IP addresses and ports
- DNS in plain terms
- HTTP and HTTPS
- Routers, switches and firewalls
- Reading a packet capture in Wireshark
2. Linux and the command line
Most servers, and most security tools, live in a terminal. You’ll set up a safe virtual machine and get comfortable breaking things in it.
5 topics, about 5 hours
- Setting up a Linux virtual machine
- Moving around the terminal
- Files and permissions
- Users and processes
- Small shell scripts
3. The core ideas of security
The handful of concepts that show up everywhere: what you’re protecting, who might go after it, and how hashing and encryption fit in.
5 topics, about 4 hours
- Confidentiality, integrity and availability
- Passwords, hashing and salting
- Symmetric and asymmetric encryption
- Authentication versus authorization
- Threat modeling: thinking like an attacker
4. How attacks actually work
Once the basics are clear, attacks stop looking like magic. You’ll see how each one works and what makes it possible.
5 topics, about 6 hours
- Phishing and social engineering
- Password attacks
- SQL injection
- Cross-site scripting
- Types of malware
5. How defenders respond
The other half of the job: noticing something is wrong, working out what happened, and making sure it doesn’t happen twice.
4 topics, about 3 hours
- Reading logs and knowing what to look for
- A first look at incident response
- Patching and backups
- What a SIEM doesTypes of malware
Short reads
Want one answer instead of a whole path? Each of these stands on its own.
- What is a hash, and why can’t you reverse it? Beginner, 6 min
- How Phishing Emails Are Put Together Beginner, 7 min
- HTTP versus HTTPS Beginner, 5 min
- What a firewall does, and what it doesn’t Beginner, 6 min
- Linux file permissions, decoded Beginner, 8 min
- How SQL Injection Works? Intermediate, 10 min
- Cross-Site Scripting, Explained With One Example Intermediate, 10 min
- Public and private keys, using a mailbox Intermediate, 9 min
- Reading your first Wireshark capture Intermediate, 12 min
- Threat modeling a small web app Intermediate, 15 min
- What is a hash, and why can’t you reverse it? Beginner, 6 min
- How Phishing Emails Are Put Together Beginner, 7 min
- HTTP versus HTTPS Beginner, 5 min
- What a firewall does, and what it doesn’t Beginner, 6 min
- Linux file permissions, decoded Beginner, 8 min
- How SQL Injection Works? Intermediate, 10 min
- Cross-Site Scripting, Explained With One Example Intermediate, 10 min
- Public and private keys, using a mailbox Intermediate, 9 min
- Reading your first Wireshark capture Intermediate, 12 min
- Threat modeling a small web app Intermediate, 15 min
Words you’ll keep running into
Security has a lot of jargon. These six come up constantly, so here they are in plain English.
Vulnerability
A weakness in a system that someone could take advantage of.
Exploit
The method or code that actually takes advantage of a vulnerability.
Payload
The part of an attack that does the damage once the exploit gets in.
Hash
A fixed-length fingerprint made from some data. The same input always gives the same result, and you can’t work backwards from it.
Threat actor
Whoever is behind an attack, from a lone hobbyist to an organized group.
Zero-day
A vulnerability nobody has fixed yet, often because the vendor doesn’t know about it.
Learned something? Try it.
Reading only takes you so far. The practice section has small labs and challenges that match what’s covered here, with hints when you get stuck.
