
Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316
4 February - 1 hour 11 minsThreat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's been successful, and what's failed, when they've approached this practice. Akira Brand joins to talk about her direct experience with building threat models with developers.
Speculative data flow attacks demonstrated against Apple chips with SLAP and FLOP, the design and implementation choices that led to OCSP's demise, an appsec angle on AI, updating the threat model and recommendations for implementing OAuth 2.0, and more!
Visit https://www.securityweekly.com/asw for all the latest episode...

AI Zombie Lawyer, Scattered Spider, ASUS, Mainframes, GrayAlpha, Backups, Josh Marpet - SWN #486
36 mins
17 June Finished

Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335
1 hour 8 mins
17 June Finished

$200,000 Zoom Call, Microsoft, Zero-Click, China & HD With $649 million of Bitcoin - SWN #485
28 mins
13 June Finished

Security Money: The Index is Up, CISOs Need to Get Out, and Are You Burning Out? - BSW #399
56 mins
11 June Finished