Category: Blog

  • How Book Publishing Works

    Written by Guild Markets Manager: Chase Anderson

    Whether you’ve just finished your first book or your fiftieth, you have to make the same decision: how do you want to get it out into the world?

    Self-publishing is pretty self-explanatory: you’re responsible for putting the book together and publishing it, and all the steps–and skills, and costs–that entails. It allows you to retain full control of the process, but takes significantly more time and resources. But what if you just want to write and not worry about any of that?

    Traditional publishing, for hundreds of years, used to be the only option, and is still seen as the dream for many authors. But it can seem inscrutable to those unfamiliar with it, which can push underserved voices from submitting their books to agents and publishers.

    The purpose of this post is to explain how this half of the publishing world works, to arm you with the knowledge on how to safely navigate traditional publishers both big and small.

    ### SO YOU WANT TO BE STEPHEN KING

    If your dream is seeing your book on the shelves of Barnes and Noble, Waterstones, or Dymocks, you need to get your manuscript in front of an acquiring editor of a major publisher like Penguin Random House or HarperCollins. In the old days, they interred employees between stacks of mailed-in manuscripts to wade through the slush and pick out promising options to send upstairs.

    But, once writers started using literary agents to negotiate deals on their behalf, publishers realized they could save themselves the trouble and move the slushing over to the agents. While some publishers might have limited windows for unagented/unsolicited submissions for underserved groups, the only way for most to get their foot into the door is through an agent.

    Agents pick authors and projects they want to represent, which might entail feedback to strengthen the manuscript before showing it to editors. Once it’s ready, agents pitch your book to editors at publishers they believe will want it. They then ensure a contract from the publisher–or movie studio, or roller coaster manufacturer–is in your best interest, and they take a percentage of your earnings as compensation for their efforts.

    This allows publishers to focus on what they do best: make your manuscript into the best product possible (so they can make as much money as possible selling it to readers). They offer you an “advance” on your future earnings (royalties) and you work with their editors to make your book stronger, along with the regular grammar, punctuation, and typesetting stages of editing.

    One of their sales people will have a meeting with Barnes and Noble, where they pitch all their upcoming titles and argue that your book deserves space on their shelf instead of a Funko Pop. Their marketing team makes nice little graphics for social media and sends out review copies and press releases. As massive companies that put out dozens, if not hundreds, of books per year, they know this process in and out and have the connections to get your book in front of as many people as possible.

    ### BIGGER ISN’T ALWAYS BETTER

    Publishing, in all its forms, is a business, and the book is the product. This means the corporate beancounters determine how many risks they can afford to take per year, as the guaranteed money makers like James Patterson, Colleen Hoover, and celebrity memoir bankroll everything else. It would be great for everyone if every debut turns into a runaway success like Xiran Jay Zhao, but they expect most books not to turn a profit. 

    So books that are just outside the norm, whether it be in length, tone, subject matter, or the current political climate, will be harder to justify. Paying all those people to make a book a huge success isn’t cheap.

    For furry writers, this is especially the case; we’ve all heard “Aren’t animal stories for kids? So why is this so long/mature? Who is this for?” We know there’s a market of readers for these books, but it’s not as big as major publishers want. They need to sell thousands of copies to make money, so what can you do when your readership is only in the hundreds?

    ### THE SMALL BUT MIGHTY

    Small and indie presses do most of the same things that major presses do, but on a much smaller scale. They’ll put out maybe a dozen titles per year and have much smaller headcount; it isn’t uncommon for a press to be a single person who still has a day job.

    The smaller headcount means that they need to sell much fewer copies to turn a profit, so they can publish titles that have smaller readerships. But it also leads to two major drawbacks:

    1. They do not have the same cachet as a large press. It’s exceedingly unlikely that they’ll be able to get major reviewers or brick and mortar retailers to consider your book. Barnes and Noble is pretty confident they can sell that Star Wars LEGO set in Topeka, Kansas, but they don’t believe someone browsing the shelves will buy a book for a hyper-niche market.

    2. Small or no advances. Without authors of instant New York Times bestsellers, their cashflow looks quite different. They cannot afford to give you $5,000 upfront if they expect to only make $10,000 in sales across all titles in a year.

    But there’s also a number of benefits, too. You rarely need a literary agent to submit to them, so the barrier of entry is lower (and you don’t have to pay an agent’s fees, which means a higher royalty percentage for you). Your book won’t get lost among a bevy of new releases or a massive back catalog.

    And, for furry publishing especially, you get the benefit of a deep understanding and integration into the community. Furry presses and distributors vend at all of the major conventions, where they hand sell your book and how awesome you are to people who otherwise would’ve never known furry writing exists. As furs themselves, they know what types of stories furries like and how to market to them. Despite having a corporate ‘sona, this isn’t something Penguin would ever be able to do.

    ### AND THEN THERE’S THE BAD GUYS

    Malicious people–whether it be hackers, scammers, or shady businessfolx–succeed for two primary reasons: they manipulate emotions, and they take advantage of potential victims not knowing what is a “normal” interaction.

    A real example I’ve encountered: I was at a local reading, and was talking to a fellow writer. She was telling me about her book and her efforts in getting published. “I found this great agent,” she told me. “And if I pay him up front, he’ll try harder to pitch my book!”

    “Uhhhhhh, what?” I said. And I explained to her that agents get paid a percentage of your earnings, both the advance and royalties. They need to work hard to pitch your book in order to get paid. So, if you pay them up front…why would they try harder? They already made money off of you without having to do any work, so why risk putting in more effort for no return?

    She didn’t want to believe she almost got scammed, of course. No one likes to admit they’ve been tricked. No one likes to feel ashamed. But it happens to all of us; I have absolutely clicked phishing links before my morning coffee has kicked in. But once I notice the website I land on is sus, I leave before I can do any more damage, like entering in passwords or personal info.

    As a writer, you want people to like your book. You want people to tell you it’s amazing and that it deserves to be published. Bad guys know that you’ll become super excited when told these things, and, when you’re emotional, you’re less likely to stop and think things through. You’re less likely to question if these things are untrue. They may not ask immediately, but they will, at some point, ask you to do something against your best interest.

    Which, almost always, is sending them money. There has been maybe one scammer in all of history that had the intention of stealing someone’s manuscript to publish elsewhere, as publishing takes a lot of effort and doesn’t guarantee a big payout. It’s a lot easier for them to get you to send them money for services that will never happen, or that you shouldn’t need to pay for in the first place.

    ### WHAT TO WATCH OUT FOR

    Malicious people constantly change the names/emails/websites they use and the text of their messages, so listing known bad-actors will quickly age into uselessness. Instead I’ll list the techniques they use and some examples, as those are the most difficult for them to change. But the tl;dr is ”…and then they ask you for money.”

    * Messages from a publisher, agent, or editor out of the blue saying they really liked your book (especially an unpublished book) and are interested in it.

    * Needing to pay for services, such as representation, editing, cover design, marketing, appearance fees, etc.

    * Needing to purchase X copies of your book in order to be published or to keep the publisher from going under.

    * The terms of an agreement changing (e.g. My uncle works at Nintendo, I’ll pitch your book to him to be turned into a game. Oh, he said we need a treatment first, but my cousin will gladly do it for only $10,000.).

    * Any sort of pressure to act now, or else you’ll lose your opportunity. (Publishing moves very slowly. You can absolutely take a week or two to think things over.)

    * Any sort of pressure to keep the offer and/or threats secret.

    * Any sort of hostility if you ask for more time/space to think it through or when asking questions.

    If you’re familiar with banking, tech support, or investment scams, you’ll notice some similarities. Many unpublished mainstream writers are older and aren’t part of larger writing communities or organizations, so scammers see them as likely to fall for flattery and intimidation tactics. But anyone, of any age and at any point in their career, can be victimized by a scam. You need to be lucky every time spotting and dodging scammers. Scammers only need to get lucky once.

    ### BUT WHAT ABOUT…?

    There are “vanity presses” and publishing services, where you pay for things like cover design and distribution. It’s common for self published authors to pay for someone else to edit their book or handle the marketing, for example.

    However, the self published author knows up-front that they want to pay for a service and begin discussions with that in mind. They don’t get blindsided with, “Oh, actually I’m not gonna make you a cover for free. Gimme $5,000.”

    Printing your book at FedEx is technically a vanity press; FedEx really doesn’t care what happens after it’s printed as long as you pay them first. If you see a press that says, upfront and clearly on their website, that they’ll publish your book if you pay $W,XYZ, then you have the right to enter that contract. But it’s important to keep in mind that what makes them money is the services, not making a book people want to buy.

    Before you sign that check, do some research: Do their covers look nice? Do their titles have any reviews on Amazon? Do they focus more on selling books, or services? If you google them, what comes up? Have other authors had good experiences?

    Just because a publisher doesn’t say upfront they won’t ever charge you fees doesn’t mean they aren’t a vanity press; many publishers assume this is an unspoken rule, like, “Please don’t set our store on fire or punch the staff.” If, after being accepted, you’re told you need to pay for services (either as a normal part of their business or that you or your book is an exception), that’s extremely not cool of them.

    There are presses that only charge some of their would-be-authors, especially for editing. This is also extremely uncool, and it makes it harder for word to get out that they do this, because authors compare notes. If you were singled out for paying fees, it can increase the negative feelings that keep people from speaking out, which is the one thing they don’t want you to do.

    ### HELP! I THINK I’VE BEEN SCAMMED!

    It’s awful that this happened to you. It doesn’t mean that you’re naive, or a bad writer, or deserved this. It means you’re human, with human emotions that a not very nice person took advantage of. They’re in the wrong here, not you.

    You can try to initiate a chargeback with whatever service you used to transfer the money, but that might be impossible (services like Zelle and PayPal Friends and Family post warnings that they cannot undo transactions because they’re so commonly used for scams). The best thing you can do is share your story; while not furry-specific, SFWA’s [Writer Beware](https://writerbeware.blog/about/) has a tipline for potential scams and shady publishers.

    I’ve submitted to them before, as I have been involved with publishers that ghosted authors without paying them, sending contributor copies, or reverting rights. And it always sucks when it happens! Unfortunately, if you work in publishing long enough, you’re going to encounter a bad actor, either one who set out to be a scammer or who meant well but got overwhelmed by the realities of publishing.

    If something happened with a furry-specific publisher, you can privately message a Guild Officer and share your concerns.

    Even if you just want a gut check or an extra set of eyes on a contract, one of the reasons why I’m here is to give you the tools you need to succeed, and that includes the knowledge and confidence to advocate for yourself. Your stories are important and deserve to be handled by someone who sees you as the artist you are, and not just a walking paycheck.

    ### GLOSSARY OF TERMS

    Some words mean specific things with publishing, such as:

    * Acquiring Editor: The person at a publisher who chooses what stories to buy to fulfill the company’s goals. For large publishers, final decisions are usually made by upper management. For small presses and literary journals, it’s often the same person who is the head of the organization and handles other editorial duties.

    * Advance: A “loan” a publisher gives a writer for their manuscript. For each book sold, an author earns a certain percent of it as income, known as royalties, which are reported by the publisher and paid on a set schedule. An advance is an amount that is “borrowed” against future royalty earnings, any royalties accrued greater than the advance (and, therefore, sent to the author) means the book has earned out. Most books do not earn out, and this is part of the math that determines what advances an author might get. If a book does not earn out, the author doesn’t have to pay back the difference.

    * Example: A publisher gives an author a $10,000 advance for a book that earns $5 in royalties per book sold. The first 2,000 books sold have their royalties “paying back” the “loan” that was the advance, so the author does not get issued royalty checks. If 2,001 or more books sell, then the book has earned out and the author receives additional income. If it sells 2,000 copies or less, the author only ever gets the initial $10,000.

    * Agent: A person who represents a writer to sell and negotiate specific rights, such as English publishing, foreign language publishing, film adaption, roller coaster adaption… A person with an agent is agented, and an agent submitting a work on the writer’s behalf is an agented submission. A writer submitting directly to a publisher is an unagented submission. Agents get paid a percentage of author earnings, both advance and royalties, and is the only way they earn income; brand-new agents who have not sold any books do not make any income and often work another job.

    * Publisher: A traditional publisher invests only their money into acquiring and publishing books; authors only receive money, not pay money. A vanity publisher will publish a book only if a writer pays all of the costs: some differentiate themselves by not accepting every customer, but they’re still vanity publishers. A hybrid publisher fronts some of the costs of book production, but they require the writer to “invest” some of their own money, too. Publishing services are offered by a company for authors to handle some parts of self-publishing for them.

    * Note: Each has its own use case. If you want to print a couple dozen copies of a cookbook for the family reunion, then a vanity publisher is your best option. If you can’t be bothered to find a cover designer or figure out how to format eBooks, then publishing services can help you in self-publishing. Many vanity and hybrid publishers won’t call themselves that due to the negative connotations, so you have to determine what type of publisher they are by looking at their site. Regardless of what you choose, any ethical publisher that requires author payment must be up front about it

    * Rights: The legal ability to do something with a book. If a publisher only sells books in the US and Canada, they need North American English language rights. If a publisher has worldwide distribution (such as through Gumroad or itch.io), then they need worldwide English language rights. The rights a publisher is buying from you, and how much they pay for it, is spelled out in the contract. Good contracts should include information on rights reversion, where you get your rights back (and can then sell them elsewhere, if you so choose).

    * Example 1: A publisher wants to buy your English-language short story to sell in their physical and digital magazine for 8 cents per word. But their contract states you are also giving them merchandising rights, all forms of media/publishing, both current and future, and all foreign language rights. Signing the contract gives them the right to turn your story into a movie, translate it and publish it in High Valyrian, or make a Funko Pop of the characters, and you won’t see any additional income. It’s good practice to ask what plans a publisher has to exercise each right, in each form and language; if they have no plans, then they don’t need those rights. If they make plans in the future, they can issue a new contract then (and write you a new check).

    * Example 2: A publisher wants to buy your book to sell both physically and digitally. They want the exclusive right to be the publisher of your book, but there is no rights reversion clause. If the press goes defunct (such as the owner dies, closes the press, or decides to ghost everyone), then, legally, you can’t sell your book elsewhere (either to another publisher or to self-publish it). Contracts exist to protect both parties in case the worst happens, so having, in writing, what should happen if a publisher stops functioning is good practice.

    * Note: Generally, you do not need a lawyer to review publishing contracts, as they tend to be simple (comparatively). Contracts that are more complex and involve larger amounts of money are usually handled by a literary agent and their legal counsel. The [SFWA Contract Committee](https://sfwa.org/sfwa-committees/contracts-committee/) is a free resource that includes annotated model contracts and other resources a writer can use to judge a contract.

    * Solicitation: An editor or agent asking a writer specifically to submit to them. This might happen if you meet them at a convention or take part in a pitch event on social media. Most of the time, you’re sending unsolicited submissions. Major presses usually do not accept unsolicited, unagented submissions, but most small and indie presses take mostly unsolicited, unagented submissions.

    Original post written by F.K.

  • FWG Newsletter July 2026

    The Summer sun beamed its wonderful light through June and straight into the next month! Welcome to July, everyfur! Pride month may be over, but our strong Pride shines along with the sun, showing its beautiful colors until the end of time! 

    A big reminder that if you want to support the FWG more, then we not only have a Paypal… but we have a Patreon that you can subscribe to as well! Any support towards the guild really helps with future endeavors. So, thank you for donating if you do!

    FWG Paypal: https://www.paypal.com/donate/?hosted_button_id=2ACUCFGMBZY4A

    FWG Patreon: patreon.com/furrywritersguild

    Now, this next topic has to do with Book Publishing and how to navigate it without having any trouble! The next Blog post after this one was created by our Guild Markets Manager: Chase Anderson! This is mainly to help out newer authors navigate through their publishing journey. Though of course it is free for anyone to view right here on the site! Thank you so much, Chase!

    Lastly, I’d like to remind all of you lovely furs that you can do it. There will be hard times, times where everything seems to be falling, times where your goals seem impossible to reach… but I just want you to remember that you have the ability to fight and keep going. Never give up on yourself or your dreams! Write that story that you’ve been thinking about for ages. You are the voice for your stories— let your voice be heard! You can do this. There are many that believe in you, and that includes me!

    Keep on writing!

    -Flash Kitterson

    Here are the open markets from your Guild Markets Manager: 

    July open markets:

    Still open from June:

    ### Short fiction, nonfiction, and poetry:

    * #OHMURR Fall 2026 – 2,000 – 6,000 word for fiction/essays, 1 – 2 pages of poetry, unknown length for book reviews, 100-300 word hookup stories, pays $20 for fiction and essays, until Sept 20  https://ohmurrmag.carrd.co/#submissionguidelines

    * Children of the Night – short stories of 5,000-20,0000  words, pays 0.5 cents/word, open until full  https://armouredfoxpress.wixsite.com/website/furry-call-for-submissions

    * Dinner at Yiffany’s – short stories under 15,000 words, no close date announced  https://www.dinneratyiffanys.com/story-submission-guidelines/

    * Rho Iota Phi – short stories of 3,000 – 12,000 words, pays 0.5 cents/word, closes Oct 31  https://armouredfoxpress.wixsite.com/website/furry-call-for-submissions

    * This is Halloween – short stories of 3,000 – 12,000 words, pays 0.5 cents/word, open until full  https://armouredfoxpress.wixsite.com/website/furry-call-for-submissions

    * The Voice of Dog – short stories under 10,000 words, currently no close date announced 
    https://thevoice.dog/?page=rules

    ### Books and longer works:

    * Bewere – 30,000 – 120,000 words for fiction and nonfiction, unknown length for games and others, no close date announced  https://bewere.net/submissions.php

    * Doppelfoxx Publishing – unknown lengths/types, opens June 15, no close date announced  https://doppelfoxxpublishing.com 

    * Fenris Publishing – 30,000 – 120,000 words for fiction and nonfiction, unknown length for games and others, no close date announced  https://www.fenrispublishing.com/submissions.php

    * FurPlanet (comics/magazines only) – unknown lengths, currently no close date announced  https://furplanet.com/shop/custom.aspx?recid=8

    * Transcendent Fiction Publishing – unknown lengths for comics, graphic novels, art books; 30,000 – 12,0000 words for novels, novellas, and single-author collections; currently no close date announced  https://www.tfpublishing.com.au/submission-guidelines

    ## Opens on July 1:

    * Plott Hound – original flash fiction and short stories under 5,000 words, reprint fiction under 10,000 words, nonfiction essays 1,000 – 2,500 words, pays 8 cents/word for original fiction, $20 for reprint flash, $100 for reprint shorts, and $100 for essays, closes July 15 https://plotthoundmag.com/submission-guidelines/

    Please check out the latest book releases from our members:
    Tethers Torn [Book 2], by Utunu, Released March 2026.
    Archon [Book 2], by Mark Smith, Released March 27th, 2026.
    Disaster Queers: Night at the Museum, by Alison Cybe, Released April 1st, 2026.
    Howling Dead, by Vincenzo Pasquarella, Released April 13th, 2026.
    Space Dragons: Cosmic Survivors, by Veo Corva, Released April 20, 2026
    Travels, by Erin Lee, Released April 26th.
    A Rodent of Unusual Size, by Rebecca Cascane, Released April 26th.
    The Morning After, by J.F.R. Coates, Released April 26th.
    Weasel Under the Sun (A Stone & Cooke Mystery), by Kyell Gold, Released May 2026.
    Game Of Life, by Rob MacWolf & Alex Vance, Released June 15th, 2026.
    Lesser Gods: Retribution, by Alex Frey, Released June 16th, 2026.
    UPCOMING!!
    The Moonhound, by K.C. Shaw, Releases October 2026.

    FWG Members- remember to use the Promotion Tip Line!
    https://forms.gle/keTnEt1UG59qMqZ29

    Original post written by F.K.

  • Moms of Furries @ CFF

    Moms of Furries @ CFF

    Did you know The Moms of Furries will be hosting their Young Furry Chill Space™ at CFF this year? Carrie and Joelle are so excited to bring their expertise and fun to the con! You’ll be able to find their minor focused space in our Meadow and you’ll see them hosting special events over the weekend!

    To learn more visit their website: https://mofurries.com/home

    Original post written by Ahmar Wolf

  • NO TACTICAL GEAR @ Anthrocon

    NO TACTICAL GEAR @ Anthrocon

    A friendly reminder from our Safety team: we do not allow attendees wearing tactical or tactical-style gear, or any accessories that may be perceived as real. Props brought into the convention space must also be inspected and peace-bonded.

    More details: https://anthrocon.org/standards-of-c

    Original post written by Ahmar Wolf

  • Soatok’s Informal Guide to Threat Models

    Soatok’s Informal Guide to Threat Models

    After a long day of exhausting conversations about Hybrid Post-Quantum Cryptography, random jackasses trying to play gotcha with endpoint attacks against end-to-end encrypted messaging apps, and message board discussions in the wake of dumb politicians pushing more “age verification” bullshit on us all, it’s become abundantly clear to me that the phrase “threat model” is a foreign concept to most people.

    Except, y’know, as a buzzword.

    Comic. Panel 1: Person in a DEFCON shirt says
    Art by Embyr.

    For context, this was commissioned during the era of anti-vaccine losers claiming to “do their own research” briefly co-opting the word “threat model” as a buzz word.

    I just still find it kind of funny even without this context.

    To be up front: If you’re here looking for an academic resource with over 100 citations on how to write a formal threat model document for your new startup which involves multiple blockchains, this probably isn’t the gay furry blog for you. Maybe start with STRIDE and system theory.

    But if you’re looking to build an intuition for what questions a good threat model should answer, and you’re starting from zero, you’re probably in the right place.

    So let’s talk about threat modeling.

    Threat Modeling For Neophytes

    Purple protogen (Neophyte) smiling.
    Their name is Neophyte, if you didn’t get the joke.

    Art: Harubaki

    At a high level, don’t overthink this too much.

    While a threat model is a formal cybersecurity process that some infosec folks actually specialize in, you can run informal threat models in the design and architecture phases of developing a new product or service and no one can stop you. You might just end up with a better result.

    A threat model should, at minimum, answer these basic questions:

    1. What are we even protecting to begin with?
      • If you can’t answer this, you have a lot of ground work to do.
    2. Who/what wants to harm what we’re protecting?
      • Hackers, activists, cyber-stalkers, social media harassment networks
      • Natural disasters / bad karma
      • Underpaid and overworked employees who get fed up
      • Idiotic legislatures paid by large corporate lobbyists to pass stupid laws that hurt everyone
      • Nation State Adversaries!!!!1oneon
    3. How might (2) attack (1)?
      • Attack scenarios go here
      • Murphy’s Law goes here
    4. What will we do to prevent (3) from happening?
      • Murphy’s Law also goes here!

    And, like, okay. If you can check those off, you can call your document a threat model in some sense.

    However, this is often useless in practice because some crucial details are omitted.

    1. How are the assets (1) related / connected?
    2. What assumptions are we making, especially with (4) and (5)?
      • I’ll say more about this below.
    3. What threats are we deliberately not addressing?
      • You literally cannot address every possible attack that any person will ever imagine in the unforeseeable future, so don’t pretend to.

    Too many people take assumptions (6) for granted, ironically, but it’s incredibly important to be as clear about what your assumptions are.

    If one of your assumptions is wrong, then your model is incomplete (at best), or your list of accepted risks (7) needs to be reconsidered.

    For example: The Invisible Salamanders attack breaks abuse reporting in some end-to-end encrypted messaging designs, but only if you introduce abuse reporting.

    The attack is possible because one of the assumptions that went into the AEAD schemes in question (AES-GCM, ChaCha20-Poly1305) is that there is only one valid key for a given message. The second you introduce multiple valid keys for a given message (or confused deputies for that matter), you’ve gone outside the security guarantees of your algorithm–which, as an attacker, makes for a fun trick.

    Being clear about your assumptions allows you to identify your own unknown unknowns. You don’t have to be perfect.

    In fact: Threat models are supposed to be living documents, not point-in-time snapshots. Update them whenever you deem appropriate.

    Art: CMYKat

    Example: My Own Work

    You may or may not already be aware that I’m working on delivering key transparency to the Fediverse. The work is being tracked on publickey.directory if you’re curious about the state of it after this blog post goes live.

    This work began with a specification, which includes a prominently featured threat model.

    The threat model is organized into the following sections:

    1. Assumptions (stated up front)
    2. Assets
    3. Actors (both attackers and people we want to protect), given role names
    4. The risks, which have one of four statuses attached
      • Prevented by design: Attack simply won’t work lol 😀
      • Mitigated: Attacks shouldn’t succeed, unless an assumption is wrong. Most interesting for researchers to focus on.
      • Addressable: There’s a way to mitigate the risk, but it requires effort or care. Operators should be aware of this.
      • Open: This is a risk we cannot or will not mitigate. These are the attacks that will succeed.

    This threat model isn’t perfect, of course. I didn’t perfectly relate the assets and actors to each other in a human-readable graph. There might be blind spots in the risks section I never considered. I might have forgotten to write down some assumption that matters for the security of the system.

    If you can look at my project’s threat model and see its shortcomings, you probably understand the assignment well enough to write your own.

    But enough thinly-veiled shameless self-promotion. You won’t learn much only looking at my example of fur-in-the game. We also need an example of a bad threat model doc, and boy howdy do I have one ready.

    Bad Example: Matrix’s Threat Model

    I’ve picked on Matrix before (twice), so if you’ve read those blogs, this won’t be news to you.

    This is Matrix’s threat model (latest, v1.18):

    9. Security Threat Model

    9.1 Denial of Service

    The attacker could attempt to prevent delivery of messages to or from the victim in order to:

    • Disrupt service or marketing campaign of a commercial competitor.
    • Censor a discussion or censor a participant in a discussion.
    • Perform general vandalism.

    9.1.1 Threat: Resource Exhaustion

    An attacker could cause the victim’s server to exhaust a particular resource (e.g. open TCP connections, CPU, memory, disk storage)

    9.1.2 Threat: Unrecoverable Consistency Violations

    An attacker could send messages which created an unrecoverable “split-brain” state in the cluster such that the victim’s servers could no longer derive a consistent view of the chatroom state.

    9.1.3 Threat: Bad History

    An attacker could convince the victim to accept invalid messages which the victim would then include in their view of the chatroom history. Other servers in the chatroom would reject the invalid messages and potentially reject the victims messages as well since they depended on the invalid messages.

    9.1.4 Threat: Block Network Traffic

    An attacker could try to firewall traffic between the victim’s server and some or all of the other servers in the chatroom.

    9.1.5 Threat: High Volume of Messages

    An attacker could send large volumes of messages to a chatroom with the victim making the chatroom unusable.

    9.1.6 Threat: Banning users without necessary authorisation

    An attacker could attempt to ban a user from a chatroom without the necessary authorisation.

    9.2 Spoofing

    An attacker could try to send a message claiming to be from the victim without the victim having sent the message in order to:

    • Impersonate the victim while performing illicit activity.
    • Obtain privileges of the victim.

    9.2.1 Threat: Altering Message Contents

    An attacker could try to alter the contents of an existing message from the victim.

    9.2.2 Threat: Fake Message “origin” Field

    An attacker could try to send a new message purporting to be from the victim with a phony “origin” field.

    9.3 Spamming

    The attacker could try to send a high volume of solicited or unsolicited messages to the victim in order to:

    • Find victims for scams.
    • Market unwanted products.

    9.3.1 Threat: Unsolicited Messages

    An attacker could try to send messages to victims who do not wish to receive them.

    9.3.2 Threat: Abusive Messages

    An attacker could send abusive or threatening messages to the victim

    9.4 Spying

    The attacker could try to access message contents or metadata for messages sent by the victim or to the victim that were not intended to reach the attacker in order to:

    • Gain sensitive personal or commercial information.
    • Impersonate the victim using credentials contained in the messages. (e.g. password reset messages)
    • Discover who the victim was talking to and when.

    9.4.1 Threat: Disclosure during Transmission

    An attacker could try to expose the message contents or metadata during transmission between the servers.

    9.4.2 Threat: Disclosure to Servers Outside Chatroom

    An attacker could try to convince servers within a chatroom to send messages to a server it controls that was not authorised to be within the chatroom.

    9.4.3 Threat: Disclosure to Servers Within Chatroom

    An attacker could take control of a server within a chatroom to expose message contents or metadata for messages in that room.

    (Yes, I excerpted the whole section in the scrolling box above.)

    A few things you might notice, scrolling through this:

    1. This is just a list of different attack types.
    2. There is no list of assumptions.
    3. There is no list of assets, nor their relationships to other assets.
    4. The list of attacks is woefully incomplete.
    5. Bonus observation for anyone that read it live from the Matrix website: It has largely remained unchanged since v1.1 (published in 2021), despite both my vulnerability disclosures and two additional cryptographic attacks by Lotte.

    As annoying as this is, and as tempting as it might be to fail Matrix entirely, at least they have a threat model.

    Signal, by contrast, gives you a bunch of technical specifications and expects you to figure the threat model out for yourself. This is one of the many things about Signal that annoys me.

    So to Matrix’s threat model author, I award the following:

    poorly drawn star with the words
    Matrix’s Threat Model?
    I give it a C-.

    A shitty threat model beats not having a threat model.

    How Threat Models Help You Build Better Stuff

    There are a lot of infosec truisms that you’ll hear early in your career. Things like, “Defenders have to get it right all the time, attackers only need to get it right once.”

    Yeah, but well-equipped defenders can decide the terrain. Put that in your Art of War pipe and smoke it.

    Every security practitioner from here to seclists preaches defense-in-depth, but doing actual defense in depth means understanding your threat model well enough to force attackers into predictable dead ends.

    Let me give you a practical example, then a more interesting one.

    Preventing Credential Stuffing

    Credential stuffing is a stupid simple attack that’s unreasonably effective in most real world scenarios.

    Why? Because people reuse passwords.

    Why do people reuse passwords? Because they can only be assed to remember so many passwords, and asking them to create a unique, secure password for your app is laughable.

    To mitigate this risk, there was a long period of time when password managers were the right answer to this problem. These days, they’re still okay (but not Lastpass), but passkeys are better.

    Why? Because passkeys are a more user-friendly (note: not totally user friendly) way to get users to use asymmetric cryptography for authentication. In the best case, they’re using hardware security tokens (e.g., SoloKeys or YubiKeys). In the average case, their OS or password manager is providing this for them.

    Following a chain of “why?” questions like this is one way to get a feel for the threats inherent to a (deeply flawed) security control. But it does come with the inherent risk of falling into rabbit holes, so be careful with that.

    If you want to avoid credential stuffing and related trivial attacks:

    1. Design your application to require passkeys.
    2. Require users to enroll multiple passkeys (or at least one for backup purposes).
    3. Give administrators a way to break glass add a new passkey for another user if they lose all their credentials. Log these actions in a way the administrators cannot censor.
    4. Do not support passwords for authentication at all if you can avoid them.

    As an added bonus, passkeys are not phishable either–due to the protocol cryptographically binding each credential to a domain name during registration.

    Whatever it costs you to onboard your users to passkeys, you’ll save loads more on the support burden caused by credential stuffing and phishing (and completely avoid the ill-advised “phishing tests” that don’t measurably improve outcomes).

    By removing the unreasonable expectation of humans to memorize, and also never reuse, a high-entropy secret for your service, you kill off multiple classes of attack and improve usability. A good threat modelling exercise can lead to this discovery independent of my blog post.

    Security at the expense of usability comes at the expense of security.

    Avi Douglen

    The next example is more interesting, but also a little more advanced.

    Soatok wearing scotch taped glasses with a speech bubble that reads,
    Art: CMYKat

    Distributed End-to-End Encryption

    There are currently two proposals for end-to-end encryption for direct messages that are being discussed by cryptography experts and decentralization nerds:

    1. The ActivityPub E2EE specification, which aims to deliver private DMs for Fediverse software (e.g., Mastodon).
    2. Projects like Germ Network that want to do the same for ATProto (e.g., BlueSky).

    Both projects have, at some point, considered using MLS as their E2EE conversation key management protocol.

    However, there are two important caveats with MLS in a non-centralized system that make security less straightforward.

    1. MLS specified an abstract concept called an Authentication Service which the SimpleX lead misunderstood in publicly embarrassing ways.

      My proposal for key transparency is one way to solve this problem without creating a centralized authority.

    2. Message ordering is important for the security of ratcheting trees, which underpin the epochs in MLS.

    For ActivityPub, if they adopt key transparency for the first caveat, they just need to be explicit how to handle races from multiple proposed KeyUpdate messages, especially across different servers. Not trivial, but solvable.

    But the situation is trickier for ATProto / BlueSky.

    Why ATProto Makes This More Difficult

    ATProto doesn’t have instances like the Fediverse does. This is partly because ATProto was designed by Bitcoin-pilled developers on Jack Dorsey’s payroll who decided that having “global state” was a good service design choice. And blockchain is the worst kind of global state to stabilize because you have many writers.

    Instead of just building a thing that clients use to encrypt messages they pass to their instance (like with ActivityPub), you basically have to treat everything as peer-to-peer (or damn close to p2p, anyway) when making your security analysis.

    This means you need to figure out another complex protocol to guarantee message ordering in a distributed system (e.g., something like the Raft consensus algorithm), or you skip MLS in favor of pairwise E2EE and forego the group abstraction entirely.

    Soatok yelling at his computer
    Art: AJ

    How Threat Modelling Helps

    If you consider the confidentiality of messages passed between users to be a security goal of your project, and you want your hosting to be decentralized, the blockchain-inspired design of ATProto is actually an impediment towards using the most efficient group key agreement protocol standardized today.

    Yes, it is an impediment that several excellent engineers are currently cleverly working around today, but you could have avoided their mistakes when you were still at the drawing board.

    Soatok glitching out
    Art: AJ

    Impractical Uses For Threat Models

    Okay, if you’ve read this far, hopefully you understand:

    1. What a threat model is
    2. What a good threat model should encapsulate
    3. How to spot bad threat models
    4. How threat modelling can help you build better stuff

    And that’s all practical, useful stuff, but it can get a bit dry and boring.

    What if I told you that leveling up your threat modelling skills could make you better at sniffing out bullshit in technical discussions?

    Threat Modelling for Post-Quantum Cryptography

    I recently wrote a blog post about hybrid post-quantum constructions, which talked about signatures rather than Post-Quantum KEMs.

    As luck would have it, there’s a Last Call happening on the TLS working group mailing list at IETF right now, which Daniel J. Bernstein unhelpfully decided to try to astroturf by summoning Twitter randos and other conspiracy theorists to bark condemnation towards.

    I’m not exaggerating. Posts like this precipitated DJB’s post:

    I vehemently object to the NSA’s proposition.

    Patrick Timothy Dalrymple
    Founder & CEO, LYRIA

    IETF TLS mailing list archive

    Or, possibly the silliest one so far:

    Do not publish this document. Enabling state SIGINT harms everyone.

    – Willow

    IETF TLS mailing list archive

    Aside from the obviously unreasonable people (and unwelcome sex pests like Jacob Appelbaum who I refuse to communicate with), I did ask many of the folks DJB summoned to the thread to elaborate on what specific security concerns they had.

    Unsurprisingly, they were following the same black-and-white thinking (“hybrids good! pure PQ bad!”) that I suspected, but you always got to probe in case there’s an unexpected reason!

    To apply our understanding of threat modelling to this situation, we need to establish some facts.

    1. ML-KEM is not a NSA design.
      • Its principal submitter was Peter Schwabe, who collaborated with Daniel J. Bernstein on the NaCl cryptography library and lives in Germany.
      • The other submitters live all over Europe.
    2. Information theory rules out a ML-KEM backdoor.
    3. ML-KEM was chosen for standardization by a very public decade-long international effort.
    4. NIST / FIPS / NSA demands non-hybrid ML-KEM / ML-DSA in classified systems.
      • If there was a NOBUS backdoor in these algorithms, it would be patently fucking stupid for them to be in a hurry to move everything over to those algorithms.

    Anyone who disagrees with these facts is simply rejecting reality. To that avenue of discourse, I say simply, PoC || GTFO.

    The IETF discussion in question is about publishing an RFC that establishes a code point for non-hybrid ML-KEM.

    The non-hybrid RFC draft is marked Recommend=N, while the hybrid KEM RFC will be marked Recommend=Y. This is because hybrid KEMs are preferred over non-hybrid KEMs. If the IETF produces an RFC that specifies ML-KEM, there will be no reduction in security to system configured to always use hybrid KEMs.

    Google Chrome already supports non-hybrid ML-KEM. If the IETF effort fails to produce an RFC, there will be no real benefit.

    So you might be wondering, “What’s the point of an RFC if it seemingly doesn’t do anything?”

    Well, it does do something, just not for most of us: If you’re an organization whose engineers are being told by lawyers that a) you must adhere to CNSA 2.0 and/or FIPS 140-3 (or possibly other weird rules), and b) any designs you specify must have a stable IETF RFC number rather than merely be an Internet Draft, then this unblocks you from a lot of bullshit red tape.

    Is that a stupid problem to have? Absolutely.

    Is that a common problem for some business verticals, especially who sell to government customers? Certainly.

    Objecting to the RFC for ideological reasons effectively only leaves those people out in the rain without an umbrella. This is the exact opposite of harm reduction.

    But what about technical objections? Isn’t Hybrid PQ+T better than pure PQ?

    Well, this is where your threat modelling skills need to come in. If we use Q-Day as the short-hand for “once a cryptography-relevant quantum computer is built by an adversary”, we can think through the risks clearly.

    Reminder: The risk we face for KEMs is Harvest Now, Decrypt Later rather than “wait for Q-Day to happen then break crypto”.

    • Pure ECDH (no PQ) is broken retroactively at Q-Day, regardless of whether other attacks materialize.
    • Pure PQ is not broken at Q-Day, assuming the PQ algorithms are not broken first.
    • Hybrid PQ+ECDH is a hedged bet against an algorithm break before Q-Day, but is utterly fucking useless over Pure PQ once Q-Day occurs.

    DJB has been whipping up people who haven’t participated in any of the background discussion to object to Pure PQ in favor of Hybrid PQ+ECDH, and his call to action is full of NSA FUD and other fearmongering.

    But here’s the rub: If you’re actually worried about the security of ML-KEM, why would ECDH + ML-KEM help if, on Q-Day, the ECDH contribution is effectively zero security?

    Arguing for ECDH + ML-KEM today is acknowledging that ML-KEM is actually a secure algorithm to choose in the long run, modulo rare implementation flaws (most which are catchable by robust test vectors).

    If you really chew on this problem, it should be clear that PQ+PQ hybrids are the only way to hedge your bets in a way that will remain resilient to a cryptography relevant quantum computer. Optional: Throw ECDH in there to ensure the status quo security is perserved.

    None of the people opposing the RFC have, to my knowledge, advocated for ML-KEM + HQC + ECDH three-way hybrids, when that would be the most intellectually honest thing to argue for.

    • ML-KEM is a lattice-based KEM, and is believed by world-class cryptography experts to be impervious to quantum attacks.
    • HQC is a code-based KEM, and is believed by world-class cryptography experts to be impervious to quantum attacks.
    • ECDH is what we already use today, but is susceptible to quantum attacks.

    But, really, the objections to this RFC are often silly and generally poorly thought out… which makes these threads a great opportunity to exercise your bullshit detector.

    Closing Thoughts

    There are many guides on the Internet that will give you a formal treatment of threat models and the methodologies that are useful to approaching them. But where’s the fun in that?

    Hopefully, you will walk away from this blog post with a vague smoke test for the quality and efficacy of a threat model document, and maybe even feel inspired to tackle this topic more seriously.

    Original post written by Soatok