A practical, opinionated guide to threat modeling aimed at developers who want to build security intuition without formal methodology overhead. Covers the essential questions a threat model must answer, the importance of stating assumptions explicitly, and how to spot incomplete threat models — using Matrix's sparse threat model as a negative example. Also explores how threat modeling applies to real-world scenarios: passkey adoption to defeat credential stuffing, E2EE design challenges in decentralized systems like ATProto vs ActivityPub, and the ongoing IETF debate over pure vs hybrid post-quantum KEMs (ML-KEM). Argues that threat modeling skills help developers cut through technical FUD and make better architectural decisions early.

Table of contents
Threat Modeling For Neophytes9. Security Threat ModelHow Threat Models Help You Build Better StuffImpractical Uses For Threat ModelsClosing Thoughts293 Impressions