2:50+ in 
I totally agree.. that cable and privacy is not a threat model.. its a hack threat model.. and as Tom said in the video.. that one is way to expensive to target a random person. 
For a hack attack on a random person for “fun” not a real legit targeted person/company, then a “bad USB” is a cheaper way.. as you can get one around $10 and up. drop one on the parking-lot and someone not using their brain is curious and plugs it in. 
6:10+ in 
I totally agree again on the wigle net, its easier way to find someones home. and from a privacy perspective.. then google is the threat model and data-brokers
But.. sometimes it is a but. 
Lets look on it from a OSINT perspective. One data point is not a privacy threat.. it is when it is a lot of data points you can put together it becomes a privacy threat.
This can be seen as CVE’s.. you have 10 CVE’s and none of them alone is a real threat as they have a low score… But when doing a multi step attack the chain becomes a breach..
One by itself is not a threat.. its when you have a lot of data-points the privacy gets broken.
Wifi and BLE can also be used to track someone and keep a distance.. as a stalker or an agency.
Some phones do have rotating mac addresses and that makes it harder. Someone on defcon had made a neat device for this.
Google, Microsoft, Facebook, Apple, Amazon do a lot of data collection and some of them even near by device scanning to pick up ssid and devices. (its in their data collection/privacy policy for everyone to read)
Microsoft said all telemetry is anonymous.. But after the hacker got caught and the news got flooded about Windows GDID identified the hacker.. so the telemetry is no longer anonymous.
The hacker court CASE NUMBER: 25 CR 812 PDF https://www.justice.gov/usao-ndil/media/1450651/dl
The US agency’s is using massive data collection provided by data-brokers etc for warrant-less searches… and even people working with OSINT is using this.
This is about privacy as it is about your data you put out there.
So does Google, Microsoft, Facebook, Apple, Amazon selling your data.
no.. but they can hand over it if they get a warrant.
What is a treat… that is if they get a big data-breach and their big databases ends up on darknet.
People install apps that share data.. your pictures, your contact list etc and you are the person agreeing to share it… But have you asked all your friends that is in your contact list if they are okay with you sharing their data??? 
So what is a privacy threat… its not one thing alone a lot of data points abused by someone who know how to find it online for Doxing, Stalking, Scams etc
(David Bombal on Youtube has a few really good OSINT videos where he have guests working with it and have courses about OSINT)..
So threat model for getting hacked is one thing… (and this is important as security is what keeping your data on your device and not ends up on darknet.) lol
Threat model for privacy is another as privacy isn’t about being hacked or getting malware.
Its only about your data that you leave out there and how it can be abused by those that dont want you well.
And privacy is a bit like security.. its not one thing alone.. it is a chain of steps that makes security.. in the same way it is a chain of steps that makes privacy.
Sorry for my long rant
(its almost 6AM here soon, so I’m tired).
I just wanted to share my perspective of the first minutes topic of privacy,
Now I’m going to continue the stream as i pressed pause 40 minutes in to write this. 
I love to watch Tom’s streams when I’m unwinding this late and before i hit the bed. 
It would be fun to see a walk-through video of Tom’s home-lab and studio setup he has now.

Take care folks and stay safe. 