Independent Tor encyclopedia Glossary
Glossary definition

Threat Model

A structured answer to who your adversary is, what assets you protect, and what failure looks like — the foundation of OPSEC and tool choice.

A threat model is a short, honest document — often just a paragraph — that answers four questions: What must stay secret? From whom? What can that adversary actually do? And what happens if the defense fails? Every serious security decision, from choosing Tor to choosing a phone, is downstream of those answers.

Why tools come second

Tor protects against an observer of the network: the ISP, the local censor, the website logging visitors. It does nothing against an adversary who controls the device, compels a provider, or reads the screen. Someone whose threat is ad tracking needs a different setup than someone whose threat is a state police agency — and the wrong model costs in both directions: exposure on one side, unusable complexity on the other.

The common failure

Copying a checklist written for someone else’s adversary. Checklists encode a threat model without stating it; following one meant for a journalist in a war zone — or for a casual privacy enthusiast — fits most people poorly. Writing the model down first, and revisiting it when circumstances change, is the foundation on which OPSEC and Anonymity tools build.

Category: Security

Back to the glossary A–Z