SecretNote.eu

Threat Modeling for Privacy: Build Your Personal Risk Assessment

A person reviewing a layered privacy risk assessment diagram on a glowing screen in a modern workspace.

Threat modeling is the process of figuring out exactly who or what you're protecting your privacy from, what they might want, and what you can realistically do to stop them. Instead of buying every security tool and hoping for the best, you build a personal threat model: a short, honest map of your actual risks so you spend energy where it matters. The core question is simple but powerful: who are you hiding from, and what happens if they win?

What Is Threat Modeling

Threat modeling started in software security, where engineers map how an attacker could break into a system before they write defenses. The same logic works for your personal life. You're not asking "how do I get more private?" in the abstract. You're asking "what specific bad thing could happen, who would cause it, and is it worth defending against?"

The payoff is focus. Perfect privacy doesn't exist, and chasing it burns you out. A good privacy risk assessment tells you which threats are likely and damaging (defend hard), which are unlikely but catastrophic (defend some), and which are annoying but harmless (ignore). The Electronic Frontier Foundation's Surveillance Self-Defense guide calls this making a security plan, and it's the foundation everything else rests on.

The Five Questions Behind Every Threat Model

You don't need software or a spreadsheet to start. Answer these five questions honestly and you already have a working model:

  • What do I want to protect? Your assets. Messages, photos, location, bank access, your legal name, your home address.
  • Who do I want to protect it from? Your adversaries. An ex, a scammer, an employer, a data broker, a government.
  • How bad is it if I fail? The consequence. Embarrassment is not the same as physical danger or losing your job.
  • How likely is it I'll need to protect it? Real probability, not movie-plot fear.
  • How much trouble am I willing to go through? Your effort budget. A defense you won't actually use is worthless.
Key insight: Likelihood times consequence equals priority. A high-consequence threat that's extremely unlikely may rank lower than a mild threat you face every single day.

Who Are You Hiding From

"Who are you hiding from" is the question that changes everything else. Different adversaries have wildly different capabilities, and defending against a bored ex is nothing like defending against a well-funded agency. Sizing up your adversary keeps you from either under-protecting or wasting months on threats you'll never face.

Adversary Capability Typical goal
Scammers / opportunists Low, automated, mass-targeted Money, credentials, resale of data
Data brokers / advertisers Legal tracking at massive scale Build a profile, sell your attention
Ex-partner / stalker Knows you personally, may have device access Location, contacts, control
Employer / institution Controls networks and accounts you use Monitoring, policy enforcement
State-level actor Very high, legal and technical Surveillance, identification

Most people massively overestimate the state-level threat and ignore the everyday ones. For the average person, the realistic adversaries are automated attacks and quiet commercial tracking. That's why reused passwords fall to credential stuffing attacks and why your browser fingerprint quietly follows you across sites, no spy agency required.

Build Your Personal Risk Assessment

Turn the five questions into a working document. Do it once, then revisit it when your life changes (new job, breakup, move, public role).

  1. List your assets. Write down everything worth protecting. Be specific: "DMs with my therapist," not just "messages."
  2. Name an adversary for each. An asset with no realistic adversary needs no defense. Cross it off.
  3. Score likelihood and consequence. Rate each pairing low, medium, or high on both axes.
  4. Sort by priority. High likelihood plus high consequence goes to the top of your list.
  5. Match a defense to each top item. Only now do you pick tools, and only for threats that earned it.

When you reach the defense step, match the tool to the threat. Weak account logins? Move to phishing-resistant sign-in with passkeys instead of passwords. Worried a stored message could leak later? Use zero knowledge encryption so the service can't read your data even if compelled, and forward secrecy so a future key breach doesn't unlock your old conversations. For sensitive communication habits in general, the privacy best practices guide covers the day-to-day defaults worth adopting.

Watch for interfaces nudging you toward oversharing. Dark patterns can quietly undo good decisions by making the private option the hard one to find.

Three Real Threat Models

Abstract advice is useless. Here's how the same framework produces three completely different plans.

  • The privacy-conscious regular user. Adversary: scammers and data brokers. Priorities: strong unique passwords, a password manager, two-factor authentication, and blocking trackers. State surveillance is not on the list, and that's fine.
  • The person leaving an abusive relationship. Adversary: someone who knows their passwords, birthday, and habits, and may have had physical access to their phone. Priorities: new accounts on a device the ex never touched, checking for installed monitoring apps, and locking down location sharing. This is a high-consequence, high-likelihood situation.
  • The journalist or activist. Adversary: a resourced institution or state. Priorities: end-to-end encrypted messaging, source-protection metadata hygiene, compartmented devices, and ephemeral messages that resist forensic recovery. Highest effort budget because the consequences are severe.

None of these people needs the others' setup. The activist's tooling would exhaust the regular user, and the regular user's defaults would fail the person in danger. That mismatch is exactly what threat modeling prevents.

Common Mistakes to Avoid

  • Defending against everyone at once. You'll build nothing. Pick your top two or three adversaries first.
  • Copying someone else's setup. A Reddit power user's config solves their threats, not yours.
  • Ignoring likelihood. Fear of nation-states while reusing one password on 40 sites is backwards.
  • Choosing tools you won't use. A clunky defense you abandon after a week protects nothing.
  • Treating it as one-and-done. Your threat model expires. Revisit it after any major life change.

Start small. Write your five answers on paper tonight, rank two threats, and fix the top one this week. A rough model you act on beats a perfect one you never finish.

Personal privacy risk assessment and threat modeling overview

Turn your personal threat model into real protection

Once you've mapped who you're hiding from, send the sensitive things with an encrypted note that self-destructs after reading, so a leaked inbox or chat log has nothing left to give up.

Create a secret note →

Threat modeling is figuring out what you want to protect, who might try to take it, how bad it would be if they succeeded, and what defenses are worth the effort. It replaces vague privacy anxiety with a focused, realistic plan tailored to your actual risks.

Yes, even a five-minute version helps. Without one, you either overspend energy on unlikely threats or ignore the everyday ones like weak passwords and tracking. A quick personal threat model shows you where your limited time and attention will actually make a difference.

List realistic adversaries by capability: scammers, data brokers, an ex, an employer, or a government. Most people face automated attacks and commercial tracking, not state surveillance. Match each asset you care about to the specific person or group most likely to want it.

Revisit it whenever your life changes in a meaningful way: a new job, a breakup, a move, a public role, or a new device. Your adversaries and assets shift with your circumstances, so a model built a year ago may no longer match your real situation.

Usually not. Copying someone else's configuration solves their threats, not yours, and often adds friction you'll abandon. Their high-effort tooling may exhaust you while missing the everyday risks you actually face. Build defenses around your own assets, adversaries, and effort budget instead.