Kim Wuyts — Privacy Threat Modeling episode artwork

EPISODE · Mar 23, 2020 · 27 MIN

Kim Wuyts — Privacy Threat Modeling

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A system can protect data from attackers and still violate the privacy of the people using it. Kim Wuyts, a privacy researcher and contributor to LINDDUN, explains why privacy deserves its own threat modeling questions. She distinguishes security goals from harms to individuals, then walks through the framework’s approach to finding privacy risks in software designs. The conversation explores how linking ordinary pieces of information can identify a person, why non-repudiation can be undesirable in a privacy context, and what disclosure, awareness, and compliance mean for a design. Kim also discusses the relationship with privacy by design and offers a practical starting point for teams that already use diagrams and security threat modeling.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Kim Wuyts:→ Kim Wuyts on LinkedInMentioned in this episode:→ LINDDUN privacy threat modeling→ LINDDUN research and publicationsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Privacy threat modeling with Kim Wuyts01:44 Kim’s research background and LINDDUN04:08 How privacy differs from security05:55 Modeling harm to the data subject08:50 Using diagrams and the LINDDUN framework10:50 Linkability and identifying people from data14:32 Lessons from the AOL search-data release15:43 Non-repudiation as a privacy threat16:44 Detectability and privacy17:52 Information disclosure and the remaining categories20:14 The connection to privacy by design21:06 Getting started with LINDDUN23:46 Future directions for privacy threat modeling25:57 Kim’s closing advice

Episode metadata supplied by the publisher feed · Published Mar 23, 2020

Embed this episode

A system can protect data from attackers and still violate the privacy of the people using it. Kim Wuyts, a privacy researcher and contributor to LINDDUN, explains why privacy deserves its own threat modeling questions. She distinguishes security goals from harms to individuals, then walks through the framework’s approach to finding privacy risks in software designs. The conversation explores how linking ordinary pieces of information can identify a person, why non-repudiation can be undesira...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Kim Wuyts — Privacy Threat Modeling

0:00 27:36

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 27 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on March 23, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!