EPISODE · Jan 4, 2017 · 28 MIN
Adam Shostack -- Think like an Attacker or Accountant?
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to practice it. Chris and Robert add examples from development teams, while Adam extends the discussion to infrastructure and operations. They close with practical ways to ask better questions, build a shared understanding of a system, and make security thinking accessible without demanding a new identity.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Adam Shostack:→ Adam ShostackMentioned in this episode:→ Start With WhyFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Rethinking “think like an attacker” with Adam Shostack01:25 Adam’s security origin story03:34 Why the hacker mindset instruction can fail07:15 When security conversations make developers feel excluded08:02 Rethinking how security is taught11:22 Giving teams a practical way to participate14:16 Treating developers as experts in their own systems17:08 Explaining why security matters20:37 A developer’s perspective on security thinking22:26 Applying the approach beyond software teams25:49 Practical actions for more inclusive security work
Embed this episode
What this episode covers
What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to p...
Ready to play
Adam Shostack -- Think like an Attacker or Accountant?
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.