Microsoft's STRIDE model is a 6-letter checklist that lets you scan any system for the kinds of attacks it might face. It is overkill for enterprise threat modeling and perfect for solo work — because you can run it in 60 seconds in your head.
| Letter | Threat | Solo-dev example |
|---|---|---|
| Spoofing | Pretending to be someone else | Anyone hitting your endpoint without auth is trivially "you" |
| Tampering | Modifying data in transit or at rest | HTTP (no S) lets a coffee-shop attacker rewrite your API responses |
| Repudiation | Doing something then denying it | No audit log = no way to know what happened during the lost-phone window |
| Information disclosure | Leaking data you didn't mean to | Open /admin; verbose error stacks; .env in repo |
| Denial of service | Crashing or overloading you | Anyone on the internet can spam your Ollama endpoint and burn your VRAM |
| Elevation of privilege | User becomes admin | "Anyone who reaches the app" = "anyone who can do everything an admin can" |
The 60-second drill
For each surface you ship, walk the six letters out loud. The output is a quick list of the gaps you accept and the ones you do not. You don't have to fix all six — you have to see all six.