Dhole Moments
Read post

Soatok’s Informal Guide to Threat Models

A practical, opinionated guide to threat modeling aimed at developers who want to build security intuition without formal methodology overhead. Covers the essential questions a threat model must answer, the importance of stating assumptions explicitly, and how to spot incomplete threat models — using Matrix's sparse threat model as a negative example. Also explores how threat modeling applies to real-world scenarios: passkey adoption to defeat credential stuffing, E2EE design challenges in decentralized systems like ATProto vs ActivityPub, and the ongoing IETF debate over pure vs hybrid post-quantum KEMs (ML-KEM). Argues that threat modeling skills help developers cut through technical FUD and make better architectural decisions early.

    #security#quantum-computing#cryptography#encryption#passkeys
Jun 30•18m read time•From soatok.blog
Post cover image
Table of contents
Threat Modeling For Neophytes9. Security Threat ModelHow Threat Models Help You Build Better StuffImpractical Uses For Threat ModelsClosing Thoughts
293 Impressions
Dhole Moments's image
Dhole Moments

Soatok is a blog or publication authored by Soatok Dhole, a security researcher and privacy advocate...

26 Followers

•

119 Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard