Cappa Blog

Privacy you can understand. Notes you can find.

Clear, careful explanations of how encryption protects what you write, what a server can and cannot see, and how to write and organize notes that stay useful for years.

Security & privacy

What encryption protects, what it cannot, and what a server learns about you.

Security & privacy12 min read

How long should a master password be?

How long should a password be? For a master password, aim for 16+ random characters or six random words. Here is why, with honest crack-time estimates.

Security & privacy10 min read

Can your notes app read your notes?

Is Notion private? Can Google Keep, Apple Notes or Evernote read your notes? A fair, sourced comparison of who holds the key in 10 notes apps.

Security & privacy12 min read

Can AI crack your passwords?

Can AI crack passwords? A reality check on PassGAN and the 51% headline, what AI really changes for attackers (phishing, voice clones) and how to stay safe.

Security & privacy10 min read

What are passkeys, and will they replace passwords?

What are passkeys and how do they work? A plain guide to passkeys vs passwords, phishing resistance, syncing, losing your phone and what passkeys can't replace.

Cryptography, simply

The building blocks behind private apps, explained without the math.

Cryptography, simply12 min read

Post-quantum cryptography explained simply

What is post-quantum cryptography? ML-KEM, ML-DSA and hybrid key exchange explained simply, where you already use them, and the 2029 to 2035 migration timeline.

Markdown & notes

Write faster, format less and organize notes you will actually find again.

Markdown & notes10 min read

Zettelkasten vs PARA, explained simply

Zettelkasten vs PARA: how the Zettelkasten method and the PARA method work, what each is good for, common mistakes, and a simple way to combine both.