EPISODE · Mar 23, 2020 · 27 MIN
Kim Wuyts — Privacy Threat Modeling
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
A system can protect data from attackers and still violate the privacy of the people using it. Kim Wuyts, a privacy researcher and contributor to LINDDUN, explains why privacy deserves its own threat modeling questions. She distinguishes security goals from harms to individuals, then walks through the framework’s approach to finding privacy risks in software designs. The conversation explores how linking ordinary pieces of information can identify a person, why non-repudiation can be undesirable in a privacy context, and what disclosure, awareness, and compliance mean for a design. Kim also discusses the relationship with privacy by design and offers a practical starting point for teams that already use diagrams and security threat modeling.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Kim Wuyts:→ Kim Wuyts on LinkedInMentioned in this episode:→ LINDDUN privacy threat modeling→ LINDDUN research and publicationsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Privacy threat modeling with Kim Wuyts01:44 Kim’s research background and LINDDUN04:08 How privacy differs from security05:55 Modeling harm to the data subject08:50 Using diagrams and the LINDDUN framework10:50 Linkability and identifying people from data14:32 Lessons from the AOL search-data release15:43 Non-repudiation as a privacy threat16:44 Detectability and privacy17:52 Information disclosure and the remaining categories20:14 The connection to privacy by design21:06 Getting started with LINDDUN23:46 Future directions for privacy threat modeling25:57 Kim’s closing advice
Embed this episode
What this episode covers
A system can protect data from attackers and still violate the privacy of the people using it. Kim Wuyts, a privacy researcher and contributor to LINDDUN, explains why privacy deserves its own threat modeling questions. She distinguishes security goals from harms to individuals, then walks through the framework’s approach to finding privacy risks in software designs. The conversation explores how linking ordinary pieces of information can identify a person, why non-repudiation can be undesira...
Ready to play
Kim Wuyts — Privacy Threat Modeling
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.