When I'm doing security related thinking at work (or at home), understanding that if a powerful nation state's security forces become "interested" in what you're doing means you've already lost, takes the pressure off striving for perfection and trying to design systems that are secure against "the global passive observer" who's already NSL-ed your TLS cert provider and your cloud host. I admire what Signal/WhisperSystems build, but the project we're building at work that's topologically equivalent to just another CRUD app can't afford and doesn't need to be secured against the NSA or any of their Fiveeyes henchmen.
I think this is my favourite piece of his, "This world of ours":
https://www.usenix.org/system/files/1401_08-12_mickens.pdf