Cookie Policy

Last updated: 12 September 2026. Works alongside our Privacy Policy.

Cookies keep you logged into your comment account, remember your cookie choices, and tell me which security guides are actually being read versus which ones just look good on the homepage. Here is exactly what DefMek sets and why.

01. What a cookie actually is

A cookie is a small text file your browser stores when you visit a site, so the site can recognize you on your next visit or request. Some are essential to basic functioning, others exist purely to measure traffic or serve ads. I use "cookie" here loosely to also cover similar technologies like local storage and tracking pixels, since most people landing on this page mean all of the above when they search for a site's cookie policy.

02. The categories DefMek uses

Strictly necessary

Required for the site to function: keeping you logged into a comment account, remembering your cookie consent choice, and basic load balancing on Google's Blogger platform, which hosts this blog. These cannot be switched off through the cookie banner because the site will not work properly without them, but you can block them at the browser level if you would rather.

Analytics

I use an analytics tool to see aggregate traffic patterns: which guides get read, roughly how long people stay on a post, and which pages send readers away without finishing the article. This is configured to work with truncated or anonymized identifiers wherever the tool supports it, and it is not used to build a profile of any individual reader.

Advertising

DefMek plans to run advertising through Google AdSense once the site is approved. Once active, the ad network sets cookies to avoid showing you the same ad fifty times in a row and to make the ads on this site marginally more relevant than random. If you decline these, you will still see ads, they will just not be tailored to your browsing history.

Embedded content

Some posts embed a tweet, a screenshot from a vulnerability database, a code snippet host, or a video walkthrough. These embeds can set their own cookies from the third party's domain, governed by that third party's own policy, not mine. I try to flag these inline in a post where it is not already obvious from the embed itself.

CategoryTypical durationCan you opt out?
Strictly necessarySession to 12 monthsBrowser-level only
AnalyticsUp to 14 monthsYes, via the cookie banner
AdvertisingUp to 12 monthsYes, via the cookie banner
Embedded contentSet by the third partyDepends on the provider

Honestly

The advertising category is what will eventually fund the time that goes into researching and writing these guides, so I am not going to pretend I would rather you turned it off. But it is genuinely optional, the site works fine either way, and the banner is not designed to bury the "reject" button.

03. GDPR: how consent works for EU, EEA, and UK visitors

If you are visiting from the European Union, the European Economic Area, or the United Kingdom, the GDPR and the UK GDPR require that non-essential cookies, meaning analytics and advertising, only run after you have given clear, informed consent. For visitors in these regions, the cookie banner is configured to block analytics and advertising cookies until you actively accept them. Strictly necessary cookies still run regardless, since the site cannot function without them.

You can withdraw consent as easily as you gave it, at any time, using the "Cookie Settings" link in the footer. Withdrawing consent stops new analytics and advertising cookies from being set going forward, though it does not retroactively delete cookies already stored in your browser, which you can clear manually through your browser settings. Full detail on the legal basis for each type of processing, and your broader GDPR rights, including access, correction, deletion, and the right to complain to a supervisory authority, is covered in the Privacy Policy.

04. CCPA and CPRA: opting out for California visitors

If you are a California resident, the CCPA and CPRA give you the right to opt out of the "sale" or "sharing" of your personal information, a category that includes the kind of cross-context behavioral advertising that ad cookies like AdSense's are built for. DefMek does not sell personal information for money, but once AdSense is active, allowing advertising cookies to run may count as "sharing" under the law's definition.

You can opt out at any time, without creating an account or providing any personal information to do so, using the "Cookie Settings" link in the footer or the Google Ads Settings page. Opting out does not affect the strictly necessary cookies that keep the site running, and it will not be treated as a reason to deny you access to any content on this blog. Full detail on your other CCPA and CPRA rights is covered in the Privacy Policy.

05. Managing your preferences

You can change your cookie choices at any time using the "Cookie Settings" link in the site footer, which reopens the same banner you saw on your first visit. Most browsers also let you block or delete cookies directly through their settings menu, search your browser's help pages for "cookies" if you would rather manage it that way, though blocking everything may break parts of the site like comment logins.

06. Changes to this policy

If I add a new analytics or advertising tool that changes what is listed above, including once AdSense goes live, this page and the date at the top will be updated before the new cookies start being set, not after.

07. Questions

If anything on this page is unclear, or you want to know more about a specific cookie you noticed in your browser, reach out through the Contact page. I read every message myself.