Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316 episode artwork

EPISODE · Feb 4, 2025 · 1H 11M

Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316

from Application Security Weekly (Audio)

Threat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's been successful, and what's failed, when they've approached this practice. Akira Brand joins to talk about her direct experience with building threat models with developers. Speculative data flow attacks demonstrated against Apple chips with SLAP and FLOP, the design and implementation choices that led to OCSP's demise, an appsec angle on AI, updating the threat model and recommendations for implementing OAuth 2.0, and more! Visit https://www.securityweekly.com/asw for all the latest episodes! Show Notes: https://securityweekly.com/asw-316

NOW PLAYING

Threat Modeling That Helps the Business - Akira Brand, Sandy Carielli - ASW #316

0:00 1:11:39

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of Application Security Weekly (Audio)?

This episode is 1 hour and 11 minutes long.

When was this Application Security Weekly (Audio) episode published?

This episode was published on February 4, 2025.

What is this episode about?

Threat modeling has been in the appsec toolbox for decades. But it hasn't always been used and it hasn't always been useful. Sandy Carielli shares what she's learned from talking to orgs about what's been successful, and what's failed, when they've...

Can I download this Application Security Weekly (Audio) episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!