Skip to content
Satnam SatoshiIn service of humanityFind your place ↗
Menu
Lesson 01 / 21 · Expert

Threat model before tools

Design around concrete failures and the people who must recover.

14 MIN WITH PRACTICEREAD → TRY → REFLECTNO WALLET NEEDED

By the end, you’ll be able to…

  • Separate assets, threats and controls.
  • Identify residual risk after a control is added.
Your learning map

Three questions to carry into this lesson.

01Separate assets, threats and controls.
02Identify residual risk after a control is added.
Use these goals to guide your reading. Try the paper exercise, then explain the result in your own words.

Name what needs protection

A custody design protects more than a balance. It may also protect privacy, access to operating funds, continuity after illness and the ability to explain decisions. List the asset, authorized people and consequence of failure. Avoid starting with a favorite device and inventing reasons it solves every problem.

Model distinct failures

Theft, accidental deletion, coercion, unavailable signers, misleading interfaces and a provider outage require different responses. A control can reduce one threat while increasing another. For example, a demanding approval threshold may resist one compromised signer but make urgent recovery harder. Geographic separation can reduce a shared physical failure while complicating access and maintenance.

Make assumptions testable

For a fictional community treasury, write who can prepare, authorize, reconcile and pause operations. Record the evidence a second person needs to reproduce the result. A tabletop exercise should include a missing device, an unavailable provider and an unexplained payment request. No real secrets or transfers are needed. The useful outcome is a list of unresolved dependencies, not a declaration that the system is institution grade because it uses several tools.

Your turn / A paper experiment

Practice on paper

A team introduces a second approval but both approvers share one laptop and one recovery account. What risk remains?

I’ve tried it — show the worked answer

A compromise or loss of that shared environment can affect both approvals. The nominal number of people does not establish independent control. Review the shared device, credentials, recovery route and ability to refuse separately.

Want to explore with buttons and instant feedback? Try the practice lab ↗

Think it through

Make a choice. Discover why.

Choose an answer and check the explanation. You can retry as often as you like. These are practice questions, not a test of mastery; answers are not saved or sent.

1. Can one control remove every threat?
  • Yes
  • No
Read the explanation

No. Controls have scope and tradeoffs.

2. Is a vendor label a substitute for a recovery exercise?
  • Yes
  • No
Read the explanation

No. Test the actual people, tools and information.

One idea to take with you

Start with failure stories, then choose controls with explicit limits.

Your learning, at your pace

Read every lesson freely. Optional progress tracking needs JavaScript and browser storage; it does not require an account or wallet.