top of page

Threat Modeling for Everyday Privacy

  • 3 days ago
  • 7 min read

Published August 21, 2026

Privacy threat modeling is the practice of deciding what deserves protection, who or what may threaten it, how exposure could happen, and which defenses are worth their cost. The goal is not perfect secrecy. That is usually impossible. The goal is a proportional plan: spend the most effort on the harms that are both plausible and serious, then make the plan simple enough to keep using.

Claw & Riot has already argued that privacy is a form of practical autonomy in The Right to Be Unread. Threat modeling is the next move. It turns a righteous feeling—leave me alone—into decisions you can actually maintain.

Privacy Is Not a Binary

Privacy advice often arrives in two bad costumes. One says there is nothing to worry about because ordinary people are not important targets. The other says everything is compromised, so only total anonymity counts. Both flatten reality.

The Electronic Frontier Foundation defines a threat model as a way to decide which threats deserve serious attention by asking who may want your data, what they want, and how they might get it. That definition contains a merciful truth: you cannot protect against every adversary and every trick. You have to choose.

Choice does not mean surrender. It means refusing to spend three hours hardening a low-value account while your main email—the skeleton key for password resets—still relies on an old password and a forgotten recovery phone number.

The Five Parts of a Personal Threat Model

1. Assets: What Are You Protecting?

An asset is not just a file. It can be your location, identity documents, private conversations, creative work, account access, financial information, health information, contact network, reputation, or the boundary between parts of your life.

List assets by consequence, not by abstract sensitivity. A public nickname may be harmless for one person and the bridge between a protected identity and a hostile workplace for another. A location photo may be trivial after a vacation but dangerous in real time. Context changes the value of data.

2. Observers and Adversaries: Who Might Want It?

Do not begin with an all-seeing villain. Begin with realistic actors: a scammer looking for easy accounts, an advertising network assembling behavioral profiles, a data broker combining public and purchased records, an abusive acquaintance, a curious coworker, or an institution acting under its policies and legal authority.

These actors have different capabilities and incentives. A defense aimed at commercial tracking may do little against someone who knows your unlock code. A protection against opportunistic account theft may not address an app that collects data with your formal consent.

3. Access Paths: How Could Exposure Happen?

Map ordinary routes before exotic ones. Reused passwords, weak recovery settings, phishing, unattended devices, public posts, shared cloud folders, broad app permissions, old accounts, exposed notifications, and trusted people with more access than they need are common paths.

This is where threat modeling becomes concrete. “Protect my privacy” is fog. “Prevent a stolen password from taking over my primary email” is a design problem.

4. Harms: What Happens If the Threat Succeeds?

NIST’s privacy guidance treats privacy risk as the problems people may experience because of data processing. Those harms range from embarrassment and stigma to discrimination, economic loss, and physical harm. This matters because exposure is not the same as damage. The useful question is what the exposure enables.

Rank each scenario twice: likelihood and impact. A highly annoying but low-impact event may deserve a quick fix. A rare but catastrophic event may deserve a strong safeguard. A dramatic but implausible event should not consume the whole plan.

5. Constraints: What Can You Sustain?

Every protection has a cost: money, time, convenience, accessibility, social friction, or the risk of locking yourself out. A plan that requires perfect memory, constant vigilance, and six complicated tools will collapse.

Good privacy engineering respects the human operating the system. If a safeguard cannot survive fatigue, travel, illness, or a broken phone, revise it. Recovery is part of security.

Five Common Threat Tiers

A useful personal model separates threats into tiers instead of treating “the internet” as one creature.

Tier 1: Opportunistic Theft and Scams

The actor wants any easy victim, not you specifically. The main routes are phishing, reused credentials, malicious attachments, and unpatched software. Basic account hygiene has unusually high value here.

Tier 2: Commercial Tracking and Profiling

The FTC’s 2024 staff report described extensive collection, sharing, retention, and algorithmic use of personal information by major social and video services. The threat is not usually a stranger reading one secret message. It is accumulation: many ordinary signals becoming a durable profile.

Tier 3: Account Takeover

Here the target is access to a specific account, often because it controls money, identity, communications, or other accounts. Primary email and phone accounts deserve special attention because they frequently mediate recovery elsewhere.

Tier 4: Interpersonal Threats

An abusive partner, stalker, hostile relative, or harasser may know routines, devices, passwords, and social connections. Generic advice can be unsafe when changing access settings alerts the other person. People facing this tier should seek a safety plan from a qualified, trusted support organization rather than assuming a general checklist fits their situation.

Tier 5: Institutional Access

Employers, schools, platforms, service providers, and governments operate with different technical powers, contracts, policies, and legal authorities. The relevant response depends on jurisdiction and circumstances. This guide is not legal advice and does not offer instructions for evading lawful process.

Map the Data Lifecycle

Most privacy failures are not a single leak. They are a chain. A service collects information, infers something new from it, shares it, retains it, and eventually uses it in a decision. Your threat model gets stronger when you inspect each stage.

Collection: What enters the system—location, contacts, purchases, messages, device identifiers, or behavior?

Inference: What can be predicted from those inputs—routine, interests, relationships, health concerns, or financial stress?

Sharing: Which companies, contractors, people, or public audiences receive it?

Retention: How long does it remain, including backups and abandoned accounts?

Use: Does it personalize, rank, verify, advertise, price, moderate, investigate, or make a decision?

The FTC has explained that data minimization can mean collecting nothing, limiting collection to what a service needs, choosing less-sensitive data, or de-identifying what is collected. For an individual, the matching principle is simple: data that never enters a system cannot later be breached, sold, misunderstood, or retained forever.

A 30-Minute Personal Privacy Plan

You do not need to rebuild your digital life tonight. Start with one page and one half-hour.

Step 1: Name Your Crown Jewels

Write down the five things whose exposure or loss would cause the most real harm. Include the primary email account and its recovery method. Add the people who would be affected, not just the files.

Step 2: Write Three Scenarios

Use this sentence: “I am concerned that [actor] could access [asset] through [path], causing [harm].” Specific scenarios expose weak links. If you cannot fill in the actor or path, the fear may be too vague to prioritize.

Step 3: Apply High-Value Basics

CISA’s Secure Our World guidance emphasizes four broadly useful measures: recognize and report phishing, use strong passwords with a password manager, enable multifactor authentication, and update software. Apply them first to primary email, financial accounts, cloud storage, social accounts, and your phone account.

Prefer an authenticator app or security key when a service supports it and when you can maintain recovery options. Save backup codes somewhere protected and separate from the device. Check recovery email addresses and phone numbers. Remove obsolete sessions and devices.

Step 4: Reduce What Exists

Delete accounts you no longer use. Remove app permissions that no longer serve a purpose. Turn off unnecessary location history and contact access. Shorten retention where controls exist. Hide sensitive notification previews on locked devices. These actions reduce the number of paths you must defend.

Step 5: Record Recovery

Write down how you would recover if your phone vanished today. Identify where backup codes, important contacts, device backups, and account recovery instructions live. Test one recovery path before trusting it.

Three Privacy Positions—and Their Blind Spots

The Maximalist

The maximalist aims to minimize every trace. This can reveal hidden data flows and raise standards. Its weakness is cost: if every threat is critical, priorities disappear, and ordinary life becomes an endless security ceremony.

The Minimalist

The minimalist argues that convenience matters and most people are not individually targeted. This correctly notices that defenses have costs. Its weakness is confusing “not personally targeted” with “not processed, profiled, exposed, or scammed.”

The Proportional Model

The proportional model asks what harm is plausible, what would be severe, and which intervention changes the odds most. It accepts that different people need different protections. It also accepts that a good plan can be unfinished.

This layered view fits the tension explored in Serial Experiments Lain and the Quest for Transcendence: when networked identity and embodied life bleed into each other, the boundary is not restored by pretending one side is unreal. It has to be designed.

What Not to Do

Do not buy tools before naming the threat. A product is not a strategy.

Do not assume private-browsing mode makes you anonymous. It mainly changes what the local browser retains; websites, networks, and account providers may still observe activity.

Do not centralize every secret in an improvised document with no backup or access control.

Do not shame people for choosing convenience, accessibility, or connection. Privacy is supposed to protect human agency, not become another purity test.

And do not freeze. One repaired recovery setting is more valuable than a perfect plan that exists only in your head.

Privacy as Maintenance, Not Disappearance

A threat model should be revisited when your job, relationships, health, public visibility, devices, or living situation changes. The NIST Privacy Framework is designed around risk management rather than a one-time badge of compliance; personal privacy works the same way. Inventory, prioritize, protect, review.

The point is not to vanish from society. It is to decide which doors should be open, which should be locked, and who gets a key. If you like designs that wear the machinery instead of pretending it is invisible, explore Claw & Riot’s Glitchwear collection. The connection is aesthetic, not magical armor: clothing cannot secure an account, but it can make a visible language out of broken systems and chosen boundaries.

Discussion question: Which category of information would cause the most real-world harm if exposed—location, communications, identity, finances, or relationships—and which single protection would reduce that risk most?

Share your answer and join the conversation in the Claw & Riot Salon.

Recent Posts

See All

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating

 (C) 2024 iamnotnotacat llc. 2019-2025  iamnotnotacat, voidcat, and Claw and Riot are trademarks of iamnotnotacat llc. all rights reserved

bottom of page