Every solo developer's first security decision is unconscious: "I'm nobody. Why would anyone bother?" From there, every shortcut looks reasonable. No PIN. No HTTPS. 0.0.0.0 bound. Default ports. .env in the repo root, untracked but unencrypted. It works on my Mac, so let's just port-forward and use it from my phone.
Two mental frames most solo devs mix up
| Frame | Question it asks | What it misses |
|---|---|---|
| Targeted attack | "Who would hack me specifically?" | ~99% of compromises are opportunistic, not targeted |
| Opportunistic attack | "What surface did I expose, and what scanner finds it?" | This is the actual threat model for almost everyone |
The three real threats for you
- Mass internet scanners — Shodan, Censys, and a long tail of crawlers index every reachable IP daily. They do not care who you are.
- Lost devices — Your phone, with cached credentials and a Tailscale key, walks out of your hand at a coffee shop. The "attacker" is whoever found it.
- Your own slip-ups — An
.envcommitted to a public repo. A token pasted into the wrong chat. A debug endpoint left enabled.
The reframe that the rest of this quest hangs on: stop asking who would hack me, and start asking what surface did I expose, and how would I notice if someone touched it?