Adam Shostack — Threat modeling layer 8 and conflict modeling episode artwork

EPISODE · Jul 10, 2019 · 35 MIN

Adam Shostack — Threat modeling layer 8 and conflict modeling

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What if a system works exactly as designed but gives people new ways to harm one another? Adam Shostack explores threat modeling at layer eight: the human interactions that technical security reviews can overlook. He begins by defining success as better decisions and designs, then applies the familiar four threat modeling questions to social features and abuse. The conversation uses photo sharing, real-name policies, and content rules to show why context matters and why no single technical control settles every conflict. Adam introduces his conflict modeling project as a way to collect useful knowledge about those tradeoffs. He also asks who should participate, encouraging teams to bring broader expertise into decisions that affect people using their systems.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Adam Shostack:→ Shostack + AssociatesMentioned in this episode:→ Conflict Modeling project→ Attack Trees by Bruce SchneierFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling human conflict with Adam Shostack02:35 Recent threat modeling work04:32 What successful threat modeling looks like07:26 What threat modeling layer eight means11:38 Applying the four questions beyond technology14:24 Social features, real names, and abuse18:51 Building shared knowledge about conflict21:01 Modeling threats to a photo-sharing feature23:36 Who should make decisions about human harm?27:44 Getting started with conflict modeling29:41 The project’s intended resources and outcomes31:42 Context-sensitive content rules33:38 Closing thoughts and ways to contribute

Episode metadata supplied by the publisher feed · Published Jul 10, 2019

Embed this episode

What if a system works exactly as designed but gives people new ways to harm one another? Adam Shostack explores threat modeling at layer eight: the human interactions that technical security reviews can overlook. He begins by defining success as better decisions and designs, then applies the familiar four threat modeling questions to social features and abuse. The conversation uses photo sharing, real-name policies, and content rules to show why context matters and why no single technical co...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Adam Shostack — Threat modeling layer 8 and conflict modeling

0:00 35:56

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 35 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on July 10, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!