Your Personal Threat Model: Privacy Without Paranoia

“I want to be more private” is not a plan

People say this all the time. “I want to be more private online.” It sounds reasonable, and it is close to useless as a goal. Private from who? Your ISP, an advertiser, your employer, an ex, a government, the app itself? Those are six different problems with six different answers, and some of them barely touch each other. Until you name the who, you are just buying tools and hoping.

That is what a threat model fixes. It is the step where you work out what you are actually protecting, who you are protecting it from, and how much effort that is worth. This post walks you through it. If you landed here because a breach headline spooked you, or because you keep hearing “threat model” on podcasts and want an actual method, you are in the right place. By the end you will have a short list of things to do, and permission to ignore everything else.

What a threat model actually is

Strip the jargon and a threat model is an honest answer to three questions: what am I protecting, who am I protecting it from, and how much trouble is that worth. That is it. Security professionals do this for a living. It is not paranoid, it is triage. You already do the same thing in the physical world: you lock your car, you do not hire a bodyguard to sit in it.

Two words you will see a lot here. An asset is something worth protecting: usually information like your photos, your messages, your location history, sometimes access, like the login to your bank or your email. An adversary is whoever you are keeping it from. An adversary is not always some hacker in a hoodie. Sometimes it is a company doing exactly what its business model rewards. Sometimes it is a relative who means well.

The well-known version of this exercise is the EFF’s, in a guide they call Your Security Plan. It is good. It is also written for everyone on earth at once, so it stays abstract. We are going to get specific.

The five questions

Work through these about your own life, roughly in order. Keep your answers concrete. “Someone” is not an adversary. “My landlord” is.

What am I actually protecting?

List the things that would genuinely hurt to lose or expose. Photos. Private messages. Where you live. Where you are right now. Your contacts. Access to your money. Your legal name, if it is not already public. Notice that some of these matter far more to you than others. For most people a leaked browsing history is embarrassing at worst. A leaked home address, if the wrong person wants it, is a different category of problem.

Who am I protecting it from?

Line them up from least to most focused on you personally: advertisers and data brokers, the platforms themselves, opportunistic criminals running stolen password lists, an employer, a specific person you know, a government. Here is the useful part. An adversary needs both the want and the reach. Data brokers have enormous reach and zero personal interest in you. A jealous ex may have intense interest and almost no reach. You aim your effort at the cases where want and reach overlap.

How likely is this, really?

Possible is not the same as probable. Almost anything is possible. Getting swept up in mass data collection is basically guaranteed for anyone with a phone. Getting individually targeted by someone skilled is not, unless something in your life changes that: a bad divorce, a public role, a stalker, a job that paints a target on you. Plan for what is likely enough to be worth your Saturday.

How bad is it if they succeed?

Consequences have a range. Mild is a creepy ad or some embarrassment. Serious is drained accounts or a lost job. Severe is someone showing up at your door. The severity is what earns the effort, not the topic. The same piece of data, a home address, is a shrug for one person and a real danger for another.

How much hassle is it worth?

This is the question that actually decides your setup, and most guides bury it. Every control costs something: time, money, convenience, and the patience of the people around you who now have to use your weird messaging app. A setup you rage-quit after two weeks protects nothing. A modest one you stick with beats a maximal one you abandon. Be honest here. If you know you will not keep it up, do not start it.

Three people, same questions, different answers

Here is where the exercise clicks. Three people run the same five questions and come out with completely different to-do lists.

Maya just wants the tracking to stop

Maya is a marketing manager. No enemies, no stalker, she is just tired of being followed around the internet by ads and fed into ad-tech profiles. Her adversary is data brokers and ad networks. Her stakes are low: creepiness and profiling, not danger. Her patience for fiddling is close to zero. She wants to set it up once and forget it.

Her list: a privacy-respecting browser with a content blocker, a private search engine, a password manager, app-based two-factor, one afternoon opting out of the big data brokers, and a pass through her phone’s app permissions. Done.

What Maya can skip: Tor for daily browsing, a VPN bought because an ad promised “anonymity” (it does not deliver that), switching her phone to a hardened OS. None of it touches her actual problem. For her it is cost with no payoff.

Devang runs a small business

Devang’s stakes are money and legal exposure. This is his livelihood. His adversaries are credential-stuffing criminals and, in the back of his mind, an employee who left angry. He is willing to spend real time and money here, because the downside is his business folding.

His list: a password manager for the whole team, hardware security keys on the accounts that matter (email, banking, the domain registrar), personal and business identities kept fully separate, backups he has actually tested, and access limited so no single account can burn the whole thing down.

Devang is spending effort and money that would be silly for Maya. That is the point. Same questions, heavier answers, because his consequences are heavier.

Someone leaving a controlling relationship

This one stays high level, because the details matter too much to hand-wave. The adversary here has had physical access to the person’s devices, and knows their passwords, their security answers, their daily routine. The stakes are physical safety.

Run the same five questions and almost everything reshuffles. Shared accounts and family plans, location sharing, cloud photo backups, and stalkerware move straight to the top. And some ordinary advice turns dangerous: abruptly changing a password can tip the other person off that something is happening. If this is you, the right move is not a blog post’s checklist, it is a specialist. There are organizations built specifically for technology safety planning in abusive situations, staffed by people far better equipped for this than any general privacy guide, and reaching one of them first is worth more than anything on this page.

The stuff that survives every threat model

There is a floor that holds for almost everyone, whatever your five answers were. You can do this part before you have even finished thinking:

  • A password manager, with a unique password on every account.
  • Two-factor authentication using an app or a hardware key. Text-message codes are the weakest version, worth using only where nothing else is offered, since they can be stolen in a SIM swap.
  • Keep your devices and apps updated. Most real attacks use holes that were patched months ago.
  • Back up anything you cannot recreate. Photos especially.
  • Lock your screens with a real PIN or passphrase.

None of this makes you “safe,” because nothing does. It lowers your risk across basically every scenario, which is why it is worth doing no matter who your adversary is.

Where people go wrong

A few common ways this goes sideways:

  • Modeling for a movie plot instead of your life. If you are planning around nation-state spies and you are not a journalist, an activist, or a criminal, you are cosplaying, and you will burn out.
  • Buying tools before naming the problem. The tool is the last step, not the first.
  • Ending up with one giant undifferentiated to-do list and no sense of what matters most.
  • Treating the model as permanent. Your life changes, your model should too.
  • Copying a security researcher’s setup wholesale. Their threat model is not yours.
  • Thinking “private from advertisers” and “anonymous” are the same thing. They are not, and a VPN does not make you anonymous no matter what the sponsor read says.

Write it down, then get on with your life

Your threat model can be five lines in your notes app: what I am protecting, who I actually worry about, what is not my problem, what I am going to do about it, and what would make me revisit this.

That last line matters. Redo the exercise when something real changes: you move in with a partner, you go through a breakup, you start a job with a public profile, you have a kid, someone starts giving you trouble. Otherwise, leave it alone.

The goal was never to turn privacy into a hobby. It is to get a short, finishable list, do it, and go back to your life. That is the whole reason you name your adversary: most of the scary ones were never yours to begin with.

Leave a Comment