Skip to content
Blog

Threat modelling for self-hosters, in four questions

Most privacy advice is written for an adversary you do not have. How to work out what you are actually protecting against, before spending money.

NimbusVPS engineering··7 min read·#privacy#security#guide

The privacy conversation online tends to collapse into a single implied adversary: a well-resourced state intelligence service with unlimited patience. It is a useful thought experiment and a terrible basis for spending decisions, because the countermeasures that make sense against it are ruinously inconvenient against anything else.

Four questions. Answer them honestly and you will spend less money and be better protected.

1. What are you protecting?

Be specific. "My privacy" is not an asset. These are:

  • The contents of a document archive
  • The association between a pseudonym and your legal name
  • The IP addresses of people who connect to your service
  • The continued availability of a site under legal pressure
  • Your home address, given a domain you registered

Different assets need different defences, and some of them are cheap.

2. Who wants it, and what can they actually spend?

Ranked by how commonly they matter, not by how dramatic they are:

  • Automated commercial collection. Data brokers, ad networks, breach aggregators. Zero targeting, infinite scale. Defeated entirely by not being in the database.
  • An individual with a grudge. Some technical skill, a lot of time, no legal power. Defeated by clean OPSEC — WHOIS privacy, no certificate leaks, no reused identifiers.
  • A commercial rival or a litigant. Money for lawyers, no police powers. Defeated by jurisdiction: make the subpoena land in a country where they have no standing and no counsel.
  • Local police, routine investigation. Legal power, limited resources per case. Defeated by there being nothing to hand over.
  • A state service targeting you specifically. Effectively unlimited. Not defeated by a hosting choice. If this is genuinely you, hosting is not your first problem.

Almost everyone reading this is in the first three. Buy for those.

3. What is the actual consequence of failure?

Embarrassment, financial loss, job loss, prosecution, physical danger — these are wildly different, and they justify wildly different inconvenience budgets.

Someone whose worst case is a marketing database should not be routing all administration through Tor. Someone whose worst case is physical danger should not be economising on a jump host. Match the effort to the consequence, in both directions.

4. What inconvenience will you actually sustain?

This is the question that decides whether your threat model survives contact with a Tuesday.

A security practice you abandon after three weeks is worse than one you never adopted, because you will believe you are protected. Tor-only SSH adds 300 ms to every keystroke round trip. Separate identities require separate browsers, separate wallets and constant vigilance. Some people sustain that indefinitely. Most do not.

Pick the strongest thing you will still be doing in six months.

Worked answers

A developer self-hosting Nextcloud and a VPN. Asset: personal files. Adversary: commercial collection and breaches. Consequence: embarrassment. Sustainable effort: low.
→ A no-KYC provider in any location, paid with any coin, full-disk encryption, keys-only SSH. Done. Buying Seychelles and routing through Tor is spending real money and daily friction against an adversary that does not exist.

A journalist hosting a document archive. Asset: source protection and continued availability. Adversary: a corporate litigant. Consequence: source exposure, which is severe. Sustainable effort: high.
Iceland for the Media Act source protection, Monero payment, Tor-only administration, no certificate that names anything real, backups in a second jurisdiction.

A small business in a region mainstream providers will not serve. Asset: business continuity. Adversary: none in the security sense — the problem is being refused service. Consequence: cannot operate. Sustainable effort: low; they have a business to run.
→ Any of our locations, any coin, normal security hygiene. What they needed was a provider that would take their money, not a privacy architecture.

The pattern

Three very different customers. Two of them need almost nothing beyond a provider that does not collect identity. One needs a genuine architecture.

Work out which you are before you buy. It is a five-minute exercise that routinely saves people several hundred dollars a year and a great deal of daily friction — and, for the third customer, occasionally saves something considerably more important.

Disagree with something here?

Email [email protected]. When we correct a published article, the correction is noted on the article itself rather than quietly edited in.

Or just deploy a server

Deploy in the next five minutes.

Pick a location, size the box, pay in crypto. No account signup wall, no ID, no waiting on a human.

7-day money-back guarantee · No KYC · Cancel any time from the panel