Advice is dispensed as though everyone faced the same adversary. The measures that protect against an opportunist are different from those that matter against somebody who knows you, and different again from an adversary with legal authority. A method for working out which set applies to you, and why copying somebody else's precautions usually wastes effort.
The missing question
Security advice arrives as a list of imperatives with no subject.
But a measure is not strong or weak by itself. It is strong or weak against a particular adversary, holding particular resources, wanting a particular thing.
Until you have named that adversary, you cannot evaluate a single item on the list — which is why so much good advice produces so little improvement. It is applied uniformly to situations that are not uniform.
Four adversaries, four different answers
The opportunist. Wants a target, not you. Tries doors and moves on when one resists. Stopped by ordinary measures and by not being the easiest thing available — a genuinely low bar that a great deal of advice is quietly aimed at.
The automated attack. Not aimed at you at all. It reached you because your address was in a list somebody bought. Stopped by unique credentials and a second factor, and by nothing personal whatsoever; discretion is irrelevant to a process that never looked at you.
Somebody who knows you. A former partner, a relative, a colleague, a flatmate. They have or have had physical access, they know the answers to your recovery questions because those answers are facts about a life they shared, and they may still be on the authorised list. This is the case ordinary advice serves worst.
An adversary with authority or scale. An organisation that can compel a provider, or one with the resources to make difficulty irrelevant. Individual habits do not reach this. The only thing that does is the data not existing in a reachable place, which is a decision made at design time by whoever built the system.
Why the third is the one advice fails
Nearly every default in consumer technology assumes that people in your household are trusted, because for most people most of the time they are, and building for the exception would make the ordinary case worse.
So the shared account, the location sharing, the family plan, the device backup that restores onto a second phone, the recovery contact, the browser signed in on the tablet in the kitchen — each is a convenience built on an assumption that was true when it was configured.
Which means a relationship ending is a security event, and one that arrives with no checklist. There is rarely a single place that lists everything currently sharing your account, and the work of unwinding it falls on the person with the least capacity to do it at that moment.
Stated plainly and without drama: this is the most common serious adversary most people will ever have, and the technology is not designed for it.
What proportionality actually means
Every measure costs something. Time, convenience, or the real risk of locking yourself out permanently.
A measure that is correct against one adversary can be a net loss against another. Hardware keys and no recovery path are right for some people and are how other people lose a decade of photographs.
The common failure is not too little security. It is effort spent where the adversary is not — hours hardening against automated attacks while the recovery question is a maiden name three people know.
The asset question
What would actually hurt to lose, sorted into three kinds.
Financial and recoverable. Unpleasant, bounded, insurable, and usually somebody else's liability in the end.
Permanent, because the data cannot be changed. Date of birth, biometrics, the fact of having been somewhere. No reset exists.
Disclosure that damages a relationship, a job or a safety situation. Not financial at all, frequently the highest stakes on the list.
People protect the first reliably, the second occasionally, and the third almost never — partly because it is the one that requires admitting what it is.
Working out your own
Three steps, half an hour.
Name the two or three people or organisations who would want this and could plausibly get it. Specific ones, not categories.
List what each already has. Physical access. Knowledge of you. Membership of a shared plan. A device that is still signed in somewhere.
Then check which of your existing measures would actually stop them.
Most people find the honest list is short, and that it does not correspond to what they have been doing. That mismatch is the whole return on the exercise.
What almost everybody should do regardless
Unique credentials, so that one breach stays one breach.
A second factor on anything whose loss would matter.
Devices kept current, which is dull and does more than most of what is more interesting.
A recovery path you have actually tested, rather than one you assume works.
And a recovery path that does not run through somebody whose relationship to you might change — the single measure on this list that most people have not considered and that costs nothing to change today.
Close
Security is a relation between a defender and an adversary. Advice naming only one of them is incomplete by construction.
The question is not what you should do. It is who, specifically, you would be doing it about.
