Real talk: Do you actually know your threat model?

So I’ve been thinking about this lately - we all talk about security and privacy like we’re experts, but I genuinely think most of us haven’t sat down and asked ourselves: what am I actually protecting against?

Like, your threat model isn’t the same as mine. If you’re just worried about marketers profiling you, that’s one thing. If you’re concerned about government surveillance? If your employer might search your devices? If you’re dealing with an abusive ex? Those are completely different threat models, and they need completely different approaches.

What’s your actual threat model? What are you genuinely concerned about? And maybe just as interesting- what OS are you running right now? (Windows, macOS, Linux, something else?)

I’m not asking to judge anyone. I’m genuinely interested in whether people’s OS choices actually align with what they claim to be protecting against, or if we’re all just going through the motions.

Drop a comment if you feel like sharing. Or don’t. But maybe take 5 minutes and actually think about it for yourself first. Might be eye-opening.

2 Likes

Im gonna go broad strokes here…I am not really a wall of text type of forum poster.

I center my threat model around avoiding leaking or passively giving away data whether thats to services providers, via mass survellance, surveillance capitalism or public exposure.

This site has also made me more aware of passive attacks and supply chain attacks that are seemingly always going on so I have been working on improving my digital security.

I don’t worry about anonymity or targeted attacks in terms of those being realistic threats for my threat model.

2 Likes

My threat model is really low, mainly marketers, but when decided that upgrading my apple ecosystem is too expensive I’ve searched for android mobile with longest/best service - that is GrapheneOS. That’s how it started. Then for the laptop I’ve seen somwhere about QubesOS. “Hm… that’s intresting…”.
That’s how it began.
After 2 years I’ve stumbled at this forum.

Do you run qubes because its required by your threadmodel or for education/fun?

This may sound strange, but I don’t buy into the whole threat model idea.

I get how it’s a useful concept. Otherwise we have people labeling things as “secure”/“insecure” or “private”/“non-private” with limited explanation, which devolves into telling everyone to use grapheneos or cubesos over tor. Many people also have specific threats it’s very important to guard against.

However, I deal with limited direct threats, while my understanding and life circumstances are always evolving in ways I can’t predict. Therefore my thought process is more “How secure and private can I be without it becoming a stressor or inconvience?” and “Can I do so while using open source programs for software freedom reasons?”

I don’t know what the future may bring, so I’d like to err on the safe side when it’s not too much of a bother. This does lead to you eventually seeming like a privacy nut from a mainstream perspective. Learning a small amount and making small changes adds up over the years, even while doing far less than some.

1 Like

It started for fun, but now I can’t live without.
I don’t need it, but separation of all activities like separate disposables for general web browsing, banking, shopping, this forum, each with it’s own separate disposable vpn VM is nice. I like it even if it throttle my machine as there is no gpu system gfx, everything is drawn on cpu and llvmpipe, so every YouTube full screen (not recomended) videos are highy choppy and every movie higher than 1080p on full screen are also choppy. And if you don’t want to have problems and a lot of troubleshotting you must buy machine that is confirmed on a site to work and your machine should have 32GB+ RAM.

I think cybersecurity providers/vendors need a solid threat model to define the scope of their work with clients.

As an individual, I am facing two limitations:

  • I don’t know who will be governing my country in 10 years; right now, I may trust my government and not fear state surveillance because it is well restricted by law, but maybe someone fascist will gain power soon and it will be too late because my data will already be in their hands.
  • Building a solid threat model is almost as difficult as implementing measures to meet it; pigs and mosquitoes are actually killing much more people than sharks and spiders; this shows how bad humans are at assessing risks and threats (at least how bad I am, as I have a phobia about sharks and spiders).

So basically, I will continue doing everything I can, disregarding any threat-model consideration.

1 Like

That makes sense. Privacy is much easier to maintain when it doesn’t make everyday life too complicated.

1 Like
Summary

Should we really engage when OP is AI generated?

New account, first post.

Italics everywhere.

3 uses of genuinely.

100% on pangram.com

100% on gptzero.me

Drop a comment if you feel like sharing. Or don’t.

For what it’s worth, I am genuinely :wink: interested in seeing what people think of your question. Personally, I have a science-tech mindset and have always been bad at letters/literature. Plus, I am not young and AI is still something new to me. I am always baffled at how younger people can feel so easily and quickly when something is AI generated (I usually don’t).

That said, even if something is AI-generated, I tell myself it might:

  • come from someone who is not fluent at writing English, or just writing, whereas they do have a good question or good thoughts to contribute; or
  • still trigger a useful discussion.
1 Like

The threat model of the forum members are near similar: this is evident from the discussion topics—the best (from a privacy and security perspective) browser/password manager/VPN, and so on. Anonymity tools (Tor, Tails) are rarely discussed here.

1 Like

I’d assume this is the result of a sort of survivorship bias. Those with more extreme threat models may very likely get the high level information they need in a read-only capacity and aren’t trying to actively leave traces of online presence here.

1 Like