
Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335
17 June - 1 hour 8 minsWhat makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models.
Resources:
https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems,...

Existential Dread, MCP, Cloudflare, ESXI, QR Codes, Salt Typhoon, Aaran Leyland... - SWN #495
33 mins
18 July Finished

AI meltdowns, Gigabyte, NCSC, Rowhammer, Gravity Form, Grok, AsyncRat, Josh Marpet... - SWN #494
30 mins
15 July Finished

Getting Started with Security Basics on the Way to Finding a Specialization - ASW #339
1 hour 7 mins
15 July Finished

Monzy Merza, How Much AI is Too Much, and the Weekly News - Monzy Merza - ESW #415
1 hour 43 mins
14 July Finished