.::threat model::.

updated 2026-07 · 9 min read · index

before picking a single tool, know what you are defending against. a threat model is the written answer to that question. without one, privacy degrades into a gadget collection. you stack a vpn, three messengers and an exotic os, and end up exhausted without knowing whether the actual risk is covered. your model does not need to impress anyone. it needs to be honest, and written down where you will see it again.

the four questions

take a sheet of paper, or a local text file, and answer in order. professionals dress this up as assets, adversaries, capabilities and consequences. the plain-language version is identical.

  1. what am i protecting? your assets. conversations, a real-world identity, journalistic sources, browsing history, location, specific documents, money. be concrete. "everything" is not an answer and leads nowhere.
  2. from whom? your adversary, and their capability. an advertiser, an employer, an abusive ex, a scammer, a landlord, local police, a nation-state. each has wildly different reach, budget and legal power, and therefore demands wildly different countermeasures.
  3. what happens if it fails? the consequence. mild embarrassment, lost money, a lost job, harassment, physical danger, prison. severity is what tells you how much effort and inconvenience is rational.
  4. how much effort can i sustain, for years? your budget, in time and friction. a protection you abandon after a month protects less than an average one you keep for a decade. be realistic about the habits you will actually maintain.

a worked example

abstract lists do not stick, so walk one through. say your concern is an intrusive ex who has had physical access to your devices. assets: your location, your new accounts, your communications. adversary: someone non-technical but highly motivated, who may know your passwords, security answers, and habits, and who may have installed something while holding your phone. consequence: harassment, stalking, real physical risk, so severity is high and effort is justified. the model writes itself into a plan. assume current devices are compromised and start clean. change every password from a device they never touched. turn on two-factor with an app or key, not sms. check for account recovery emails and phone numbers you did not set, and move sensitive conversation to a fresh account on a messenger they do not know about. notice how the four answers produced specific actions, and how different they are from the plan a person "tired of ads" would write. that is the entire point. the model tells you what to do and, just as importantly, what to skip.

three profiles, to place yourself

profilemain adversarysensible priorities
tired of ads and profilingdata brokers, ad networks, platformscontent blocker, email aliases, phone permission cleanup, kill the ad id
exposed to an intrusive personsomeone with past or present device or account accessaccount lockdown and 2fa, clean devices, compartmentalization, outside human help
source, activist, or investigatora motivated, resourced adversary with legal powerstrict compartmentalization, tor, disappearing messages, metadata discipline, careful acquisition

most readers are firmly on the first row, and that is fine. the measures there are cheap, simple, and already change a great deal.

two principles that do a lot of work

data minimization. the safest data is the data that does not exist. before hardening how something is stored, ask whether it needs to be collected, kept, or shared at all. an account you never open, a field you leave blank, a photo you never upload. none of it can leak. this single habit prevents more harm than most tools.

attack surface. every app, account, device and connection is a way in. fewer of them means fewer things to secure, fewer things to patch, and fewer things to get wrong. deleting is a security action.

common mistakes

all or nothing. "google already knows everything, why bother." wrong, and defeatist. data collection comes off in layers, and every layer you remove has value. privacy is not a binary state you have lost, it is a slope you climb back up one step at a time.

the magic tool. a vpn moves trust from your isp to a vendor. it does not make you anonymous. distrust any product that promises disappearance in one click, and read what a tool actually does before relying on it.

fighting the wrong adversary. defending against an intelligence agency when the real threat is a nosy manager is a great deal of effort spent leaving the actual door wide open. rank by probability, not by fear.

then keep it alivea threat model is not written once. your life changes, your adversaries change, and the tools change, so revisit it when something significant shifts: a breakup, a new job, a move, a new law. reread your four answers, keep the two most probable risks, and address only those first. every other guide on this wiki assumes you have done this and follows the same order, cheap high-impact moves first, the rest later.

sources

[ home ]

.::  eof  ::.