Adam Shostack -- Think like an Attacker or Accountant? episode artwork

EPISODE · Jan 4, 2017 · 28 MIN

Adam Shostack -- Think like an Attacker or Accountant?

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to practice it. Chris and Robert add examples from development teams, while Adam extends the discussion to infrastructure and operations. They close with practical ways to ask better questions, build a shared understanding of a system, and make security thinking accessible without demanding a new identity.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Adam Shostack:→ Adam ShostackMentioned in this episode:→ Start With WhyFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Rethinking “think like an attacker” with Adam Shostack01:25 Adam’s security origin story03:34 Why the hacker mindset instruction can fail07:15 When security conversations make developers feel excluded08:02 Rethinking how security is taught11:22 Giving teams a practical way to participate14:16 Treating developers as experts in their own systems17:08 Explaining why security matters20:37 A developer’s perspective on security thinking22:26 Applying the approach beyond software teams25:49 Practical actions for more inclusive security work

Episode metadata supplied by the publisher feed · Published Jan 4, 2017

Embed this episode

What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to p...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Adam Shostack -- Think like an Attacker or Accountant?

0:00 28:59

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 28 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on January 4, 2017.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!