Internet Architecture Board

It is necessary to make assumptions about the threats originating from each role, and to correctly capture that within the threat model. Today threat models are often incomplete (e.g. a 'private browsing' threat model that only captures threats from other users), and if some parts are ommitted or missed, then threat modelling will be useless. ................
................