← all articles

How to build a threat model without becoming paranoid

threat-model privacy consumer-security passwords

A finished one first, because the method reads like homework and the artifact takes thirty seconds to understand.

A filled in page

Someone with a job, a phone, a bank app, and no particular enemies.

Assets: the main email account, the bank app, a work account with client information in it, six years of photos, and scans of the identity documents saved in a notes app because that was convenient at the time.

Adversaries taken seriously: automated credential stuffing, and a phone that gets lost or lifted.

Adversaries accepted and ignored: advertisers, a government, and anybody who would have to pick this person out specifically.

Decisions: password manager, a hardware key on the email account, an app code or a key on the bank, a device passcode instead of four digits, updates installing themselves, photos backed up off the phone, and the identity documents moved out of notes into something encrypted.

That is a complete threat model. Half a page. Twenty minutes to write, and every line on it is something a person can finish this evening.

Compare that against a thirty item checklist, which produces a feeling of inadequacy and no completed items.

The four questions that produce that page

What do I have that is worth taking.

Who would want it.

How much trouble would they go to.

What happens to me if they get it.

Answer those in writing. On paper or in a file, never in your head, because the mental version is where this quietly dissolves.

Writing matters for one reason. It forces you to name a specific adversary. A general atmosphere of danger produces no decisions. A named adversary produces a list with an end to it.

Your asset list is shorter than you think

Be literal. Not “my privacy”. Actual things.

The email account goes at the top for almost everybody, because it is the master key. Every other account resets through it. People guard the bank app and leave the thing that can rewrite their bank login behind a password they picked in 2019.

Then whatever has money attached to it. Photos, which people undervalue until they think about what is actually in the camera roll. Messages. Identity documents, which in Singapore means an identity number that plenty of companies still treat as a secret despite half the country having seen it.

Five or six lines is normal. Short is the point, because a short list is one you can defend.

Be honest about who is coming

This is where people go wrong in both directions at once.

Ranked by how likely they are to touch you: a script that has never heard of you, working through leaked passwords against every account it can reach. Somebody who now has your phone in their hand. A person you know, uncomfortable to write down and a real category in domestic situations. A company buying and modelling your behaviour. And an attacker who wants you in particular.

Nearly all actual harm sits in the first two. Nearly every article you have read was written about the last one.

That mismatch is why the advice feels enormous and delivers so little. You are following instructions built for a threat you do not have.

The effort ladder

Here is the concept that makes the whole exercise tractable, and the one I wish somebody had shown me earlier.

Your defences only have to cost more than your realistic adversary is willing to spend.

The script spends nothing. It tries a password, fails, moves to the next address in the file. A unique password beats it outright. Total victory over your most probable attacker for the price of installing one app.

The phone thief spends minutes. They want the resale value of the handset, so a real lock screen sends them there instead of into your accounts.

Somebody who knows you spends hours and starts with your birthday, your first pet, your mother’s maiden name. They can answer your security questions better than you can.

A targeted attacker spends whatever it takes, and if that is genuinely your situation, a blog post is the wrong place to be reading.

So the rational move is to spend heavily at the bottom of the ladder, where almost all the real damage lands, and stop pretending you are hardening against a state.

Five things, one afternoon

If your honest answer was scripts and a stolen phone, the work is short and boring.

A password manager, with a different password on every account. Credential reuse on a site that later got breached is the most common way people lose accounts, and this one change removes nearly all of it.

A second factor on the email account and on anything holding money, from an app or a hardware key. I am biased here, because I work with mobile lines for a living, so I will say only that a phone number moves between people more easily than most assume, and leave it there.

A real lock on the phone. A proper passcode, with a fingerprint or face on top so you are not typing it forty times a day.

Automatic updates on everywhere, including the router if it can manage it. Free, and it prevents more genuine harm than the rest of this list combined. Also the one people switch off, because a restart at the wrong moment is annoying.

A backup of the things you would grieve, which is mostly photos, kept somewhere other than the device holding the originals.

Five. One afternoon. That covers the overwhelming majority of what happens to people. The tools I use for the middle three are here, tested rather than ranked by affiliate payout.

What I deliberately left off

Worth naming, because these are the ones the internet argues about.

A VPN for everyday browsing. Useful for particular jobs. Close to irrelevant against the two adversaries above, and sold as though it were the foundation of the building.

Exotic operating systems and stripped down phones. Real benefit, real cost in daily friction, and pointless while your email password is one you chose at university.

Full disk encryption on the laptop. Sensible, already on by default on most modern hardware, and rarely the gap anybody walks through.

None of that is bad advice. It sits further up the ladder than your risk does, and doing it first is how people end up with an exotic setup and a reused password on the account that controls everything else.

When you are holding somebody else’s data

Plenty of people cross this line without noticing their situation changed.

A freelancer with a client list. A landlord holding copies of tenants’ documents. Anybody running a small side business with customer records in a spreadsheet.

The moment you hold information about other people, the arithmetic stops being about your own comfort. A breach lands on people who never got a vote on your security habits.

Two things change. The account holding that data now needs the strongest protection you have, whatever your feelings about it, because it is the most valuable thing you own. And you need to know in advance what you would do on the day it goes wrong, because deciding then is far worse than deciding now.

There is a legal layer too, sitting outside your preferences. In Singapore, holding personal data about other people carries duties under the Personal Data Protection Act, and those duties are indifferent to how careful you feel.

So if a line on your page says other people’s information, treat it differently from everything else on the page.

Write down what you will not defend against

This is what separates a threat model from a wish list.

A model is only useful if it lets you say no. Write down the threats you are choosing to accept, then be at peace with them.

Mine includes a government with a legal order. I keep proper records, I operate legally, and building for that adversary would cost me more than the risk justifies. So it went on the page as accepted and I stopped thinking about it. One line, and it bought back a lot of attention.

Yours might be a company profiling your shopping, or a former colleague who could theoretically guess your birthday.

Writing the accepted risks down is what stops them nagging at you, and the nagging is what makes people burn out and give up entirely. Security fatigue is a genuine failure mode. Somebody who attempts everything abandons all of it inside a month. Somebody doing five things forever ends up meaningfully safer than that person.

It expires on events, not on dates

A model has a shelf life, and the trigger is a change in circumstances rather than a date on a calendar.

Money starts arriving through an account. You become publicly visible. A relationship ends badly. You take a job that makes you interesting to somebody. You start holding other people’s data, which is what happened to me and what forced this whole exercise.

Each of those adds an adversary, and a new adversary means going back to the page. Once a year otherwise, to catch what shifted without announcing itself.

What I got wrong for two years

I secured everything at the same level. It felt responsible. It was a mistake in two directions at once.

A forum login from 2014 got the same ceremony as the account that can reset my business email. The trivial ones absorbed attention they never deserved, which made the routine tiring enough that I cut corners on busy days. The accounts that genuinely mattered sat at the same level as the junk, underprotected relative to what they were worth.

I believed the important accounts were well defended. They were averagely defended, because I had spread one fixed quantity of effort evenly across things of wildly different value.

Sorting the list by what it would cost me to lose took twenty minutes and changed more than the previous two years of being generally careful did.

from the team
Want a real mobile IP, not a datacenter VPN endpoint?

Shared VPN exit nodes get flagged and blocked. Singapore Mobile Proxy runs real 4G/5G mobile IPs that give you a residential-grade address carriers still trust.

see how it works →
read on
More from The Privacy Wire

VPN and tool reviews, realistic opsec guides, and privacy news for people who want to protect their data.

browse all articles →