# Who Are We Kidding with Attacker-Centered Threat Modeling?

DevFeed: [Who Are We Kidding with Attacker-Centered Threat Modeling?](<https://devfeed.tech/articles/who-are-we-kidding-with-attacker-centered-threat-modeling-37123.md>)

Original publisher: [Read original article](<https://shostack.org/blog/who-are-we-kidding-with-attacker-centered-threat-modeling/>)

Author: adam

Published: 2019-10-23T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [iOS](<https://devfeed.tech/topics/ios.md>)

Tags: [advice](<https://devfeed.tech/tags/advice.md>), [apple](<https://devfeed.tech/tags/apple.md>), [customers](<https://devfeed.tech/tags/customers.md>), [design](<https://devfeed.tech/tags/design.md>), [ios](<https://devfeed.tech/tags/ios.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary argues that threat modeling should not begin with a fixed list of attackers or an instruction to think like an attacker. That approach can miss threats involving children, family members, and former or estranged partners, including technology-facilitated domestic abuse. It urges security designers to consider how people with limited access might misuse systems and how design choices can affect customers.

## Source excerpt

Don't go into Threat Modeling with this mindset.