Most privacy advice online is a list of tools: use Tor, use a VPN, use Signal, use a password manager. Almost none of it starts with the one question that actually determines which of those tools matter to you — and skipping that question is exactly why so many people either over-protect themselves in ways that make daily life harder for no real benefit, or under-protect themselves against the one thing they should actually be worried about.

What Threat Modeling Actually Means
Threat modeling is a concept borrowed from security engineering. Teams building software systematically ask what could go wrong before deciding how to defend against it. The Electronic Frontier Foundation has popularized a simplified, individual-focused version of it through their Surveillance Self-Defense project. It comes down to five questions worth asking in order: What do you want to protect? Who do you want to protect it from? How likely is it that you’ll actually need to protect it? How bad are the consequences if you fail? And how much trouble, inconvenience, or cost are you realistically willing to accept to prevent that outcome? Answer those honestly, in that order, before you install a single piece of software. Then the rest of your decisions get dramatically easier to make.
Why “Just Use Tor” Isn’t a Complete Answer
Tor protects a specific, well-defined thing extremely well. It hides the link between your IP address and the sites you visit. It does this by routing your traffic through three encrypted relays, so that no single point on the path knows both who you are and what you’re accessing. That’s a genuinely huge win if your threat model involves a curious ISP building a browsing profile. The same is true if it involves a government blocking access to independent news. It’s also true for a network operator logging every site employees or students visit. Tor does very little, though, against other kinds of threats. If your device is already compromised with keylogging malware, Tor can’t protect you. Nor can it help against a physical adversary who has your unlock code. The same goes for a browser extension quietly exfiltrating your data, regardless of which network you’re connected through. No single tool covers every threat simultaneously. That’s exactly why treating “just use Tor” as one-size-fits-all advice misses the point of this whole exercise.
A Journalist’s Threat Model Isn’t Yours
A war correspondent worried about a hostile government intercepting communications with a confidential source has a very different threat model. It’s built around a well-resourced, technically sophisticated, state-level adversary who may have legal authority, surveillance infrastructure, and time on their side. Someone who simply doesn’t want their internet provider building an advertising profile from their ordinary browsing history has a completely different, much lower-stakes threat model. Even so, both people might reasonably reach for some of the same tools. Both are legitimate reasons to use privacy software, but they call for very different levels of operational effort. Treating every situation like the first one leads to burnout, wasted time, and eventually abandoned good habits, because the overhead becomes unsustainable. Treating every situation like the second one leaves genuinely at-risk people dangerously under-protected. That’s because the precautions that are merely convenient for one person can be the precautions that keep another person alive.
Working Through a Concrete Example
Take someone in a country where independent journalism is heavily restricted, who wants to read foreign news coverage without drawing official attention. Their answer to “what am I protecting” is straightforward: which websites they visit. Their answer to “who from” is specific: a government-affiliated ISP that logs and reports unusual browsing patterns. The likelihood is high, since this is a routine, everyday activity rather than a one-time event. The consequences of being flagged range from inconvenient to genuinely serious, depending on the country. Given all of that, a reasonable amount of effort is: install Tor Browser, use it consistently for this specific activity, and possibly rely on bridges if the network itself is blocked at the ISP level. That’s a proportionate response, not an overreaction and not an underreaction either, because each answer in the five-question framework pointed toward roughly the same, moderate level of precaution.
Common Mistakes People Make in Both Directions
Overreacting usually looks like adopting an elaborate, multi-layered security setup: a chain of VPNs, a hardened operating system, compartmentalized identities across dozens of accounts. That kind of setup is for a threat model that never justified the complexity to begin with. Most people abandon it within a few weeks, because it’s simply too much friction to sustain for daily use. Underreacting usually looks like the opposite. It means treating a genuinely serious risk, like communicating with a source who could face real legal or physical danger if exposed, with the same casual level of care someone might use to avoid targeted advertising. Both mistakes come from skipping the threat-modeling step entirely and reaching straight for a tool, rather than working out first what that tool actually needs to accomplish, and for whom.
Applying This to Onion Sites Specifically
Before visiting any onion site, it’s worth pausing to ask what you’re actually trying to achieve. The answer changes how much caution is genuinely warranted. Reading a censored news outlet’s onion mirror is a comparatively low-stakes activity with a straightforward answer: use Tor Browser normally, at its default security settings, and that’s sufficient. Communicating with a source as a journalist is a different story. So is coordinating sensitive work as an activist in a hostile environment. Both are meaningfully higher-stakes, and both call for real additional care: separate devices reserved only for that purpose, separate pseudonymous identities that never cross over with your everyday accounts, and more deliberate operational discipline about what information touches which identity. The tool is identical in both cases. The amount of caution that actually makes sense is not, and treating both situations identically either wastes effort in the low-stakes case or leaves real risk unaddressed in the high-stakes one.
The Practical Takeaway
Resist the instinct to copy someone else’s security checklist wholesale off a forum or a listicle, no matter how thorough it looks. Instead, spend a few honest minutes actually answering the five questions for your own specific situation. Then choose tools that match what you actually found. That might mean nothing more elaborate than Tor Browser’s default settings for reading the news, or it might reasonably mean quite a bit more for higher-stakes work. The right amount of caution is whatever amount matches your actual, honestly-assessed risk. It is very rarely the maximum available, and it is very rarely zero either.