Learn

284 articlesCategory: All
Basics

What Is a Trust Model?

When thinking about anonymity, it is dangerous to think only, "If I use this tool, I will be safe."

If you use a , the information visible to the ISP changes. However, the VPN provider becomes a new point of trust. Cloud services are convenient, but you need to trust the cloud provider and the people you share with. When using SecureDrop or anonymous posting services, trust in the submission destination and operators is also involved.

A trust model is a way to organize which actors you are willing to show particular information to.

This article explains the basics of trust models in anonymity. Threat models and trust models are closely related, so they are covered in detail in "Threat Models and Trust Models."

What is a trust model?

A trust model is a way to organize "whom you trust" and "what that actor can see."

In anonymity, information rarely disappears completely. In many cases, the actor who can see it changes.

Tool or situationTrusted actorInformation that may be visible
Normal connectionISP, destination serviceDestination IP, source IP, login information
VPNVPN providerConnection source, VPN usage, information related to communication destinations
Tor's design, node distributionVisible information is divided between entry and exit
Cloud sharingCloud provider, people you share withFiles, owner, sharing history
Anonymous posting destinationService operatorPost content, logs, submission time

Instead of thinking "no one can see it," look at "who can see it now."

VPN trust model

A VPN changes the IP address visible to the destination to the VPN server.

However, in exchange, you trust the VPN provider. This is why you check its logging policy, operator, jurisdiction, app, audits, and transparency reports.

ActorWhat is visible when using a VPNCaution
ISPConnection to the VPN serverThe final destination is harder to see directly
VPN providerInformation needed to provide the serviceCheck the logging policy and operation
Destination siteVPN server IPs and logins remain
The userManages post content and loginsOperational mistakes create correlation

A VPN is not a tool that removes the need for trust.

It is a tool that changes where trust is placed.

Tor trust model

Tor does not gather the communication route into a single VPN provider. Instead, it divides roles among multiple relay nodes.

The entry node knows the user's connection source, but does not directly know the final destination. The exit node knows the destination, but does not directly know the user's original IP.

ActorVisible informationCaution
Entry nodeUser's connection sourceDoes not directly see the final destination
Middle nodePart of the routeHard to see the whole picture
Exit nodeDestinationCan see content if communication is plaintext
Destination siteTor exit nodeLogins and cookies remain
ISPThe fact that Tor is being usedTor use itself may stand out

Tor is designed to distribute trust.

Even so, if you identify yourself through login state or post content, anonymity becomes weaker.

Procedure for checking a trust model

Check the trust model before choosing a tool.

QuestionWhat to check
Whom do you want to protect against?ISP, destination, workplace, service operator, investigator
What do you not want visible?IP, post content, files, people involved, time
Who may see it?VPN provider, cloud, submission destination
Will logs remain?Server, app, DNS, internal organization logs
What is the impact of failure?Consultation, whistleblowing, activism, source protection

In high-risk activity, there are situations where it is better not to judge the trust model alone.

When whistleblowing, source protection, or physical safety is involved, consider consulting lawyers, support organizations, or trusted professionals.

Common misunderstandings

A common misunderstanding about trust models is thinking that you can reduce trust to zero.

In reality, in many situations you trust some actor: a VPN provider, Tor's design, a cloud provider, an email service, a submission destination, or a consultation contact. In anonymity, you consciously choose that trust.

MisunderstandingCorrect view
With a VPN, no one can see anythingThe VPN provider becomes a new point of trust
With Tor, post content is hidden tooCommunication route and post content are separate
Private cloud sharing is safeOwner names and sharing history remain
Removal request destinations are always safeYou may provide additional information for identity verification
You can tell any consultation contact anythingLook at the actor's reliability and confidentiality

When you are conscious of where trust is placed, tool selection becomes more realistic.

Think of trust in stages

In a trust model, do not treat an actor as only trusted or not trusted.

Think in stages about which information may be visible, which information you do not want to show, which actors can receive legal demands, and which actors can make operational mistakes.

StageWhat to think about
Low trustGive as little information as possible
Limited trustGive only necessary information
Operational trustEntrust part of it to use the service
Trust including legal riskConsider jurisdiction and disclosure demands
Human trustLook at the confidentiality of consultation contacts or recipients

For anonymity, being aware of where you place trust is more important than making trust zero.

Review the trust model

A trust model is not something you decide once and finish.

Service terms, logging policies, operators, app specifications, and the countries or regions you use can change. If you continue anonymous activity, periodically review the VPN, email, cloud, submission destinations, and consultation contacts you use.

What to reviewReason
Logging policyThe information stored may change
OperatorThe business operator or jurisdiction may change
App specificationsLeaked information or permissions change
Payment methodCorrelation with real-name information changes
Consultation contactCheck confidentiality and safety

A trust model is related not only to service selection, but also to choosing consultation contacts.

For removal requests, legal consultations, news tips, and consultations with support organizations, check what information the other party receives, how they store it, and whom they share it with.

How to read tool introductions

When reading articles about VPNs, Tor, cloud services, or anonymous submission tools, always check the trust model.

What does the tool hide? Who can see what? How far do you trust the operator? Do logins or post content remain? If you choose based only on "recommended" without looking at this, your purpose and countermeasure will drift apart.

Question when readingReason
What changes?Understand the tool's effect
What remains?Avoid overtrusting it
Whom do you trust?Understand where trust moves
How are logs handled?Think about later matching
Does it fit your purpose?Avoid too much or too little

A trust model also becomes a checking axis when reading articles.

Summary

A trust model is a way to organize whom you trust and what that actor can see.

Anonymity tools often do not erase information completely, but change who can see it.

With a VPN, the VPN provider becomes a new point of trust. With Tor, trust is distributed across multiple nodes. Cloud services and anonymous posting destinations also involve trust in the provider or operator.

For anonymity, check not the tool name, but where trust moves.

Related tools

Public IP Check

WhatIsMyIP

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://www.whatismyip.com/

Open external site
Anonymous communication

Tor Project

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://www.torproject.org/

Open external site
VPN service

Proton VPN

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://protonvpn.com/

Open external site
VPN service

Mullvad VPN

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://mullvad.net/

Open external site
Whistleblower submission

SecureDrop

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://securedrop.org/

Open external site
Whistleblower platform

GlobaLeaks

An external resource related to this article. Open it only when it fits your situation and threat model.

Why it is listed: It can help with the article topic, but it is outside Anonymity Sense and should be checked before use.

URL : https://globaleaks.org/

Open external site

Related articles