# Soatok’s Informal Guide to Threat Models - Dhole Moments

**URL:** https://discuss.privacyguides.net/t/soatok-s-informal-guide-to-threat-models-dhole-moments/40129
**Category:** General
**Created:** 2026-08-23T16:43:19Z
**Posts:** 10

## Post 1 by @overdrawn98901 — 2026-08-23T16:43:19Z

> **[Soatok’s Informal Guide to Threat Models - Dhole Moments](https://soatok.blog/2026/06/30/soatoks-informal-guide-to-threat-models/)**
>
> After a long day of exhausting conversations about Hybrid Post-Quantum Cryptography, random jackasses trying to play gotcha with endpoint attacks against end-to-end encrypted messaging apps, and me…

---

## Post 2 by @securitybrahh — 2026-08-24T12:14:28Z

Threat model feals like a psyop

Why wouldn’t you want maximum security and privacy?

What’s the threat model GOS is defending against?

---

## Post 3 by @overdrawn98901 — 2026-08-24T12:43:14Z

> [@securitybrahh](#):
>
> Why wouldn’t you want maximum security and privacy?

max privacy is likely living off the grid and off the land as a hermit in the woods without any connectivity and probably no human interaction.

increased privacy of security often comes at the cost of ease of usability. if you protect against things you actually don’t care about, youve made your life harder for no good reason.

---

## Post 4 by @securitybrahh — 2026-08-24T12:49:33Z

> [@overdrawn98901](#):
>
> max privacy is likely living off the grid and off the land as a hermit in the woods without any connectivity and probably no human interaction.

I would highly disagree connectivity can be privacy preserving. It just means that you trust different people with different things - that’s what I call trust modelling.

> [@overdrawn98901](#):
>
> increased privacy of security often comes at the cost of ease of usability

I would disagree with this as well. GOS is highly usable. Security mostly depends on how secure you are against your immediate environment.

---

## Post 5 by @overdrawn98901 — 2026-08-24T12:58:50Z

> [@securitybrahh](#):
>
> that’s what I call trust modelling.

… Threat modelling also deals with trust boundaries, so I think youve just misunderstood what threat modelling is, or just rebranded one part of the whole.

> [@securitybrahh](#):
>
> I would disagree with this as well. GOS is highly usable. Security mostly depends on how secure you are against your immediate environment.

Not every case of usability tradeoff is the equivalent of hacking your leg off. I switched from iOS to GOS. It was a friction and cost me time and effort to learn how I want to set up. Maps and GPS locking isn’t as good as before. Friends were perplexed and annoyed with green bubbles (I setup open bubbles to get around this). Disabling Google play services breaks some apps, and switching profiles is way more annoying than 1 profile. And the most annoying is visual voice mail isn’t working for me.

---

## Post 6 by @securitybrahh — 2026-08-24T13:01:13Z

> [@overdrawn98901](#):
>
> I setup open bubbles to get around this

Open bubbles?

> [@overdrawn98901](#):
>
> visual voice mail

Visual voice mail?

---

## Post 7 by @overdrawn98901 — 2026-08-24T13:07:27Z

> [@securitybrahh](#):
>
> Open bubbles?

> **[Be a blue bubble on Android | OpenBubbles](https://openbubbles.app/)**
>
> Finally, be a blue bubble on Android. Chat everywhere, seamlessly.

> [@securitybrahh](#):
>
> Visual voice mail?

The thing where you don’t have to call your phone provider to listen and manage voice mails as a phone call but rather you can do so as a GUI in the phone. I have to listen to voice mails like it’s the early 2000s right now.

Below is random marketing image of what visual voice mail is (I don’t even need the text translation, just the management of it is better)

 ![image](https://forum-uploads.privacyguidesusercontent.com/original/3X/8/2/822dd48bd7200b89cd907fb53e06fc87c5d083fd.jpeg)

---

## Post 8 by @fria — 2026-08-24T13:11:43Z

There are certain things you can do that will serve one threat model but harm another. Like for example, if you don’t want your passwords to get hacked, writing them down on a piece of paper will keep them secure from that. But if you have a nosy roommate, that’s probably the worst thing you can do.

“Maximum privacy” just doesn’t make sense as a concept when you don’t define what you’re protecting and from who at least. Most people generally have similar concerns so a lot of the time you don’t have to think about it as much, but not always.

I think if you don’t do any threat modeling you run into situations where the tools you use aren’t designed to protect against a threat when you assume they are, like adding someone to a Signal group and getting mad when they can see your Signal messages, to pick a completely random example. Or assuming Signal will somehow protect you against Cellebrite because it’s a “private” messenger for example.

---

## Post 9 by @securitybrahh — 2026-08-24T13:23:15Z

> [@overdrawn98901](#):
>
> The thing where you don’t have to call your phone provider to listen and manage voice mails as a phone call but rather you can do so as a GUI in the phone. I have to listen to voice mails like it’s the early 2000s right now.

I thought voicemails are client amenity not a server thing.

Can look into jmp.chat

---

## Post 10 by @overdrawn98901 — 2026-08-24T13:24:44Z

> [@securitybrahh](#):
>
> I thought voicemails are client amenity not a server thing.

I thought so too

> **[Carrier functionality - GrapheneOS usage guide](https://grapheneos.org/usage#carrier-functionality)**
>
> This is a guide covering some aspects of using GrapheneOS. See the features page for a list of GrapheneOS features. | Usage instructions for GrapheneOS, a security and privacy focused mobile OS with Android app compatibility.
