Weighing mainstream and alternative accounts…
Two lenses on the same evidence, given equal space. Source weight and the primary source ratio show what each rests on.
What every lens accepts.
Specific positions people hold on this question. Say whether you agree, add evidence, or submit a view of your own.
Deeper threads worth pulling on next.
Investigated
Privacy threat modeling aims to identify conditions that could cause privacy harm and reduce those risks during system design and development, extending beyond technical security to organizational, legal, and policy concerns. Frameworks such as LINDDUN provide systematic threat categories, analysis guidance, and links to privacy-enhancing technologies; newer models seek broader shared vocabularies and coverage of benign actions and system behavior. Researchers and practitioners also argue that the field remains difficult: methods may not clearly explain how to discover threats, can miss interdependent harms, and may enable checkbox or performative compliance. The central disagreement is whether structured threat modeling is mainly a useful practical discipline whose limits can be managed, or whether its subjectivity and blind spots can make risk assessments misleading without stronger governance and broader analysis.
Two lenses on the same evidence, given equal space. Source weight and the primary source ratio show what each rests on.
Lens adapted to this topic: Why threat modeling is useful and how to apply it
The mainstream view treats privacy threat modeling as a practical privacy-engineering and risk-management discipline. Analysts define what or whom to protect, examine data flows and system contexts, identify privacy-specific harms, and select mitigations. Frameworks make analysis more systematic and can bring privacy considerations into design, while assessments should be adapted to the application and supplemented by legal, organizational, and policy review.
0 agree · 0 disagree (50% agree)
Lens adapted to this topic: Critiques of privacy threat modeling and its assumptions
The dissenting view does not reject examining privacy risks, but questions whether current threat-modeling and assessment practices can reliably capture them. Privacy harms are context-dependent, difficult to observe, and often distributed across ecosystems and affected people. Vague methods, analyst discretion, unknown threats, weak incentives, and limited auditing may turn a formally completed assessment into performative compliance or false reassurance.
0 agree · 0 disagree (50% agree)
What every lens accepts.
Specific positions people hold on this question. Say whether you agree, add evidence, or submit a view of your own.
How it works: Agree/disagree is about the view. Evidence is scored on helpfulness, verified primary sources, and flags. New submissions are reviewed.
No perspectives on record yet.
Every investigation starts with one voice. Be the first to put a viewpoint — and the evidence behind it — on the record.
Deeper threads worth pulling on next.