Real talk: Do you actually know your threat model?

So I’ve been thinking about this lately - we all talk about security and privacy like we’re experts, but I genuinely think most of us haven’t sat down and asked ourselves: what am I actually protecting against?

Like, your threat model isn’t the same as mine. If you’re just worried about marketers profiling you, that’s one thing. If you’re concerned about government surveillance? If your employer might search your devices? If you’re dealing with an abusive ex? Those are completely different threat models, and they need completely different approaches.

What’s your actual threat model? What are you genuinely concerned about? And maybe just as interesting- what OS are you running right now? (Windows, macOS, Linux, something else?)

I’m not asking to judge anyone. I’m genuinely interested in whether people’s OS choices actually align with what they claim to be protecting against, or if we’re all just going through the motions.

Drop a comment if you feel like sharing. Or don’t. But maybe take 5 minutes and actually think about it for yourself first. Might be eye-opening.

4 Likes

Im gonna go broad strokes here…I am not really a wall of text type of forum poster.

I center my threat model around avoiding leaking or passively giving away data whether thats to services providers, via mass survellance, surveillance capitalism or public exposure.

This site has also made me more aware of passive attacks and supply chain attacks that are seemingly always going on so I have been working on improving my digital security.

I don’t worry about anonymity or targeted attacks in terms of those being realistic threats for my threat model.

2 Likes

My threat model is really low, mainly marketers, but when decided that upgrading my apple ecosystem is too expensive I’ve searched for android mobile with longest/best service - that is GrapheneOS. That’s how it started. Then for the laptop I’ve seen somwhere about QubesOS. “Hm… that’s intresting…”.
That’s how it began.
After 2 years I’ve stumbled at this forum.

Do you run qubes because its required by your threadmodel or for education/fun?

This may sound strange, but I don’t buy into the whole threat model idea.

I get how it’s a useful concept. Otherwise we have people labeling things as “secure”/“insecure” or “private”/“non-private” with limited explanation, which devolves into telling everyone to use grapheneos or cubesos over tor. Many people also have specific threats it’s very important to guard against.

However, I deal with limited direct threats, while my understanding and life circumstances are always evolving in ways I can’t predict. Therefore my thought process is more “How secure and private can I be without it becoming a stressor or inconvience?” and “Can I do so while using open source programs for software freedom reasons?”

I don’t know what the future may bring, so I’d like to err on the safe side when it’s not too much of a bother. This does lead to you eventually seeming like a privacy nut from a mainstream perspective. Learning a small amount and making small changes adds up over the years, even while doing far less than some.

1 Like

It started for fun, but now I can’t live without.
I don’t need it, but separation of all activities like separate disposables for general web browsing, banking, shopping, this forum, each with it’s own separate disposable vpn VM is nice. I like it even if it throttle my machine as there is no gpu system gfx, everything is drawn on cpu and llvmpipe, so every YouTube full screen (not recomended) videos are highy choppy and every movie higher than 1080p on full screen are also choppy. And if you don’t want to have problems and a lot of troubleshotting you must buy machine that is confirmed on a site to work and your machine should have 32GB+ RAM.

I think cybersecurity providers/vendors need a solid threat model to define the scope of their work with clients.

As an individual, I am facing two limitations:

  • I don’t know who will be governing my country in 10 years; right now, I may trust my government and not fear state surveillance because it is well restricted by law, but maybe someone fascist will gain power soon and it will be too late because my data will already be in their hands.
  • Building a solid threat model is almost as difficult as implementing measures to meet it; pigs and mosquitoes are actually killing much more people than sharks and spiders; this shows how bad humans are at assessing risks and threats (at least how bad I am, as I have a phobia about sharks and spiders).

So basically, I will continue doing everything I can, disregarding any threat-model consideration.

1 Like

That makes sense. Privacy is much easier to maintain when it doesn’t make everyday life too complicated.

1 Like

For what it’s worth, I am genuinely :wink: interested in seeing what people think of your question. Personally, I have a science-tech mindset and have always been bad at letters/literature. Plus, I am not young and AI is still something new to me. I am always baffled at how younger people can feel so easily and quickly when something is AI generated (I usually don’t).

That said, even if something is AI-generated, I tell myself it might:

  • come from someone who is not fluent at writing English, or just writing, whereas they do have a good question or good thoughts to contribute; or
  • still trigger a useful discussion.
2 Likes

The threat model of the forum members are near similar: this is evident from the discussion topics—the best (from a privacy and security perspective) browser/password manager/VPN, and so on. Anonymity tools (Tor, Tails) are rarely discussed here.

1 Like

I’d assume this is the result of a sort of survivorship bias. Those with more extreme threat models may very likely get the high level information they need in a read-only capacity and aren’t trying to actively leave traces of online presence here.

3 Likes

If I would had high threat model then I wouldn’t make account and post anywhere in clearnet.

Nobody knows for sure. There’s the threats that actually concern you that’s the real threat environment, and then there’s the perceived threat environment. Everyone operates by the latter, either under, or overestimating. Both are bad in that one raises risk, other overhead. Both can increase stress which is also bad.

Having wondered about this for 15 years now, I’m sticking to what I’ve said for a while now: addressing the threat model is easiest to do by looking for categorical fixes.

Keeping your diary on your daily internet connected device involves a LOT of stress about keeping the machine up to date and hardened. Buying a 50 dollar laptop from craigslist and keeping an airgapped diary solves the problem almost categorically.

Same goes for endless Firefox privacy add-on tuning. Mullvad/Tor Browser solves that problem almost perfectly. Adding privacy to that is probably to the direction of Tails and war-driving, not analyzing Tor browser code or micro-adjusting nodes used or whatever.

Both examples above can overshoot but the difference is basically which laptop you take from desk and which browser icon you double click. There’s very little overhead between these choices.

So whatever you do, learn to find categorical fixes. That’ll keep you sane and safer in the long run.

I feel pretty safe with the notes on my phone.

2 Likes

But you are missing my point :slight_smile:

One could argue that what you have is a categorical solution to the problem, “which cloud provider should I trust my plaintexts with”. Storing the data on you device solves that problem easily without having to do a massive analysis on every option to ensure you’ve selected the most reputable company.

What I meant was the same but for different threat model. Say you’re the former medical advisor of Emutopia, and now your country is run by a fascist toddler who manages to compromise the nation’s intelligence establishment. At that position you probably care much more about that fascist accessing your diary and using it as political ammunition to shame you and draw attention away from the blunders of the fascist regime :slight_smile: A full-disk-encrypted, airgapped laptop with maybe distress passwords and hidden filesystems might sound really convenient and good option to figuring out where to physically hide a book of plaintext two inches thick.

So it boils down to who you are, and what particular things are worth moving to airgapped device. The above example shows it doesn’t have to be anything illegal. Granted, the fascist party might be tearing you for having CCleaner or it’s counterpart, BleachBit installed on your device, so Richelieu’s ‘six lines’ applies for privacy tools alone. But still, I don’t know, keep the diary on Tails on bootable microSD card. That’s easier to hide than decade of physical books, and it leaves no marks on your device, which is another categorical solution for a threat “I need to keep it hidden I’m hiding something”.

I think the thread makes an important point: a threat model should guide your tools, not the other way around. It’s easy to collect Qubes, VPNs, Tor, hardened templates, and firewall rules without clearly defining what problem each one solves.

My own threat model is mainly protection against ISP and commercial tracking, IP leaks, malicious websites, cross-contamination between identities, and limited application compromise. I’m not claiming protection against a global passive adversary or a targeted state-level attack.

That said, I’m not sure threat models should be treated as fixed categories. Risks and circumstances change, and sometimes a stronger setup is chosen for resilience, learning, or peace of mind, not because the person is hiding from an intelligence agency.

The best advice here is probably to look for simple, categorical protections instead of endlessly tuning every setting. Compartmentalization is useful, but only if it remains practical enough to use correctly. Otherwise, the setup itself becomes a source of mistakes and false confidence.

That’s exactly how I thought of it when I made my example for threat modeling for someone else. It’s best to find something enumerable (list of threats, list of assets, etc) to start with and then tackle each.

The real problem is that your data are out there, there is a whole data-broker eco-system harvesting and profiting your data. As long as the data is out there and easy to obtain, there will be people/party to find ways to get it for unsavory reasons (or threats to you), such as stalking ex, marketing, identify theft or other scams. It’s hard to prevent government from purchasing your data without warrant, or someone using flock cameras for the wrong reasons.