you are on the clearnet. the addresses listed here only open inside the tor network - download the tor browser here »
AlphaBay.Market
last update: 17 min ago 255 onions tracked
home / news / security
13 May 2025 security 5 min read

Threat model thinking: deciding which protections you actually need

Most security guides hand you a checklist: use a password manager, enable two-factor authentication, route everything through Tor, encrypt every disk. Follow all of it and you will spend hours on protections you may never need, while missing the one that matters. Threat modeling flips the order: first decide what you are protecting and from whom, then choose the tools.

What a threat model actually is

A threat model is a short, honest description of four things: the assets you care about, the adversaries who might come after them, their capabilities, and what happens to you if a protection fails. The Electronic Frontier Foundation's Surveillance Self-Defense project is built entirely around this exercise, because "everyone's threat model is unique," from activists under state surveillance to people hiding from an abusive partner. It is not a product or a setting. It is a decision framework. The payoff is proportionality. Once you can name your realistic adversary, you can stop buying defenses against movie-plot villains and start fixing exposures that an actual attacker would exploit. That single shift separates working security from ritual.

Start with assets, not tools

Ask what would genuinely hurt if it leaked, was destroyed, or was forged. For most people the list is short: account credentials, private correspondence, financial records, location history, source identities, maybe medical files. Everything else is noise dressed up as risk.
  • Account logins that unlock email, since email usually resets everything else
  • Sensitive documents and message histories held on devices or in clouds
  • Metadata: who you talk to, when, from where
  • The physical devices themselves, which are trivially lost or seized
Ranking assets by real-world consequence, not by how easy they are to secure, is the discipline most checklists skip. It also tells you where to accept risk. A leaked shopping wishlist embarrasses nobody; a leaked contact book can end a career or worse.

Name your adversaries and their capabilities

Adversaries vary wildly in skill, budget, and persistence. A opportunistic thief wants resale value; a phishing crew wants credentials at scale; an employer wants compliance; a state agency can subpoena providers, plant malware, and wait years. Ross Anderson, the Cambridge security engineer who helped found security economics as a field, spent a career showing that optimal investment depends on whether anyone is actually targeting you -- mass automated attacks chase the weakest targets, while targeted attacks need high-value ones (see his economics and security resource page). Capability determines defense. Strong passwords defeat guessing but not keyloggers; Tor defeats network observers but not a compromised endpoint; encryption defeats interception but not compulsion. Match each control to a named adversary, or admit you are decorating.

Why security theater wastes your effort

Security theater is Bruce Schneier's term for measures that provide the feeling of improved security while doing little to achieve it. In his essay Beyond Security Theater, he argues that resources spent on visible rituals are taken from the invisible measures -- investigation, redundancy, response -- that actually work. Individuals play the same game against themselves.
Every hour spent hardening against an adversary who does not exist is an hour not spent closing a door that a real one would walk through.
The tell-tale signs are familiar: stacking five VPNs over Tor, rotating passwords weekly into patterns humans cannot remember, wiping metadata from photos nobody will ever see. These feel productive precisely because they are measurable. Effectiveness, unfortunately, is measured only against adversaries.

A worked example

Consider a freelance journalist covering organized crime. Assets: source identities above all, then drafts, then her own location history. Adversaries: local criminals with money and lawyers, plus routine mass surveillance she shares with everyone. Capabilities: bribery of insiders, targeted malware, legal pressure on cloud providers -- but probably not bulk traffic analysis of an entire city. Her threat model now writes its own recommendations. Signal with disappearing messages protects sources; full-disk encryption survives device seizure; separating work accounts limits blast radius if one is compromised. What it rules out matters just as much: obsessing over browser fingerprints is low value when the realistic attack is a poisoned document opened on an unpatched phone. Now rerun the same exercise as an ordinary shopper worried about data brokers. The assets are behavioral profiles, the adversary is commercial, and the highest-value moves become blocking third-party trackers and pruning old accounts -- not operational-security regimens designed for war zones. Same method, opposite conclusions. That is the point.

Revisit it, then act on it

Threat models decay as your work, visibility, and tools change, so EFF recommends treating the exercise as a recurring habit rather than a one-time audit. Write yours down in plain language: assets, adversaries, capabilities, acceptable losses. Then let it ruthlessly allocate your finite attention across the security notes here, our tor guide, or the faq. Security is not doing everything. It is doing the right few things, on purpose.

more notes

all news ›