Threat model thinking: deciding which protections you actually need
Most security guides hand you a checklist: use a password manager, enable two-factor authentication, route everything through Tor, encrypt every disk. Follow all of it and you will spend hours on protections you may never need, while missing the one that matters. Threat modeling flips the order: first decide what you are protecting and from whom, then choose the tools.
What a threat model actually is
A threat model is a short, honest description of four things: the assets you care about, the adversaries who might come after them, their capabilities, and what happens to you if a protection fails. The Electronic Frontier Foundation's Surveillance Self-Defense project is built entirely around this exercise, because "everyone's threat model is unique," from activists under state surveillance to people hiding from an abusive partner. It is not a product or a setting. It is a decision framework. The payoff is proportionality. Once you can name your realistic adversary, you can stop buying defenses against movie-plot villains and start fixing exposures that an actual attacker would exploit. That single shift separates working security from ritual.Start with assets, not tools
Ask what would genuinely hurt if it leaked, was destroyed, or was forged. For most people the list is short: account credentials, private correspondence, financial records, location history, source identities, maybe medical files. Everything else is noise dressed up as risk.- Account logins that unlock email, since email usually resets everything else
- Sensitive documents and message histories held on devices or in clouds
- Metadata: who you talk to, when, from where
- The physical devices themselves, which are trivially lost or seized
Name your adversaries and their capabilities
Adversaries vary wildly in skill, budget, and persistence. A opportunistic thief wants resale value; a phishing crew wants credentials at scale; an employer wants compliance; a state agency can subpoena providers, plant malware, and wait years. Ross Anderson, the Cambridge security engineer who helped found security economics as a field, spent a career showing that optimal investment depends on whether anyone is actually targeting you -- mass automated attacks chase the weakest targets, while targeted attacks need high-value ones (see his economics and security resource page). Capability determines defense. Strong passwords defeat guessing but not keyloggers; Tor defeats network observers but not a compromised endpoint; encryption defeats interception but not compulsion. Match each control to a named adversary, or admit you are decorating.Why security theater wastes your effort
Security theater is Bruce Schneier's term for measures that provide the feeling of improved security while doing little to achieve it. In his essay Beyond Security Theater, he argues that resources spent on visible rituals are taken from the invisible measures -- investigation, redundancy, response -- that actually work. Individuals play the same game against themselves.Every hour spent hardening against an adversary who does not exist is an hour not spent closing a door that a real one would walk through.The tell-tale signs are familiar: stacking five VPNs over Tor, rotating passwords weekly into patterns humans cannot remember, wiping metadata from photos nobody will ever see. These feel productive precisely because they are measurable. Effectiveness, unfortunately, is measured only against adversaries.