Skip to content
AppSec PodcastThe Application Security Podcast — home
31 min

Adam Shostack — Remote Threat Modeling

With Adam Shostack

Threat Modeling

Adam joins us to discuss remote threat modeling, and we do a live threat modeling exercise to figure out how remote threat modeling actually works. On this episode of the Application Security Podcast, Robert and I are joined by Adam Shostack, and the topic we discuss is remote threat modeling.

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 11 chapters
  1. 00:00Meet Adam Shostack: Adam Shostack — Remote Threat ModelingAudioVideo ↗
  2. 01:52So we find ourselves right now recording this episode. The dateAudioVideo ↗
  3. 05:20Are some of the tools What are some of the toolsAudioVideo ↗
  4. 07:57So we'll— yeah, we can add in a couple of differentAudioVideo ↗
  5. 10:10So then we have a lock activator. So it's making meAudioVideo ↗

About this episode

Adam joins us to discuss remote threat modeling, and we do a live threat modeling exercise to figure out how remote threat modeling actually works. On this episode of the Application Security Podcast, Robert and I are joined by Adam Shostack, and the topic we discuss is remote threat modeling. We’re all living in this new world where we’re working from home or we’re sheltering at home, and the question we pose is, how are we still going to make progress on rolling out threat modeling when we can’t meet with people face-to-face and work directly on a whiteboard? So we hope you enjoy this special episode of the Application Security Podcast with— Adam Shostack.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
On this episode of the Application Security Podcast, Robert and I are joined by Adam Shostack, and the topic we discuss is remote threat modeling.
Learn more about Security Journey

Connect with Adam Shostack:
Shostack + Associates
Adam Shostack

Resources
Shostack + Associates
Adam Shostack
OWASP Threat Dragon Project
OWASP Slack

Actionable

From this conversation

  1. Start from a model template

    I think the takeaway there for our listeners that might be trying to do this is, it will be wise of you to have a template/sample threat model like Adam had here as a place to start.

    17:12
  2. Choose a collaboration tool

    I think the thing to think about as your listeners are asking, what tool do I want, is do I want a drawing tool like Miro that allows me to create these diagrams, get consensus around what we're working on, where the trust boundaries are, how it's put together, what the components are so that we can be

    20:23
  3. Standardize remote-modeling tools

    But secondly, working remotely, of course, you need to make sure you have good remote tools in place, whether that be tools that, like we've been looking at here, that naturally allow good collaboration inside the tool, or you use other video screen sharing tools that allows multiple folks to see a screen or see

    22:21
Transcript · 31 min conversation

0:00Chris RomeoOn this episode of the Application Security Podcast, Robert and I are joined by Adam Shostack, and the topic we discuss is remote threat modeling. We're all living in this new world where we're working from home or we're sheltering at home, and the question we pose is, how are we still going to make progress on rolling out threat modeling when we can't meet with people face-to-face and work directly on a whiteboard? So we hope you enjoy this special episode of the Application Security Podcast with— Adam Shostack. Adam Shostack. You cannot hack yourself secure. Everyone wants to focus on the offensive side of the equation. The challenge is that developers get bored with hacking broken pieces of code after a while. Sure, it's a shiny, cool new thing in the beginning, but how about one year later? At Security Journey, we focus on long-term sustainable security culture with the developers as defenders. Our approach integrates experimentation together with learning. We believe that developers need hands-on experience, but not at the expense expense of fundamental knowledge. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo or schedule a demo. Hey folks, welcome to this special episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey, and I'm also joined by my co-host, Robert. Hey, Robert.

1:31Robert HurlbutHey, Chris. Good to be here.

1:33Chris RomeoAnd Robert is a—

1:34Robert HurlbutThreat modeling architect.

1:36Chris RomeoWhich is going to fit in well with what we're going to talk about. We're also joined by Adam Shostack, who some people know from the world of threat modeling. Who am I kidding? Everybody knows that's involved in the world of threat modeling who Adam is. So, Adam, great to have you back with us again here.

1:50Adam ShostackHey, pleasure to be here as always.

1:52Chris RomeoAnd so we find ourselves right now recording this episode. The date is March 26th, 2020, and so we're right in the throes of the COVID-19 shelter-at-home orders across the country. And so we're all working from our houses right now and looking for new ways to keep up the momentum that we have in the various things we're doing in the world of security. And so what we thought we would talk about today, having Robert and Adam both here, both people who are focusing heavily on threat modeling, but now doing it remotely, which a lot of our listeners are going to be dealing with the same problem as well, we thought we would spend a few minutes Talking about some best practices, some lessons learned, some things about doing threat modeling remotely. So, Adam, I'm going to go to you first and say, what is some of the advice you have for folks out there that are trying to take on this threat modeling thing and keep that momentum going as everybody's working from home?

2:51Adam ShostackSo, the first thing, everyone is learning to work from home as we go. This is new to everybody. And so recognizing that we need to really apply the agile practices of experimentation and retrospective as we figure out what's going to work, so that things that we used to do at the whiteboard are now technologically mediated, and that the technology doesn't get in the way, but lets the—

3:26Chris RomeoYeah.

3:28Adam Shostacklets us do the job that we're trying to do, or even helps us do the job that we're trying to do.

3:34Chris RomeoAnd so what, Adam, are some of the things that from a tool perspective you would recommend folks try to use, given that we're not going to be able to be face-to-face for the immediate future?

3:48Adam ShostackSo let me split the answer into threat modeling tooling and drawing tooling. In the threat modeling tooling space, OWASP just released the Threat Dragon project. I think I saw on their channel that they're going to 1.2 very soon. So that's an interesting possibility for collaboration. It's free, it's open source. There are commercial tools that I think are worth looking at at this point to figure out Does this really help me? I'm not gonna sit here and talk through commercial tooling unless you really, really want to. Um, but I, I do think there's some interesting stuff in that market.

4:35Chris RomeoAnd then the second part was in the drawing tool perspective that you mentioned.

4:39Adam ShostackYeah, so I did, I did an experiment yesterday. Um, what I did was I set myself a Pomodoro timer where Where I said, I'm gonna spend 5 minutes creating the same data flow diagram in each of these tools. I'm gonna click the timer. Once I'm logged in, I'm at a drawing screen. You know, with some of them I had to sign up for accounts. Some others I sort of got bogged down in the software installation process, but I was pleasantly surprised by the state of some of these tools and how much I was able to get done in a short time.

5:19Chris RomeoAnd what are some of the tools What are some of the tools that you took a look at there that our folks in the world might wanna be taking a look at as well?

5:27Adam ShostackSo I took a look at 5 different tools. I looked at Miro, I looked at Awapp, A-W-W-A-P-P, I looked at Jamboard from Google, I looked at draw.io, and I looked at one called Tuple, which is a pair programming environment. And all of those except Tuple have a free tier that you can go play with.

5:50Chris RomeoAnd is there one, based on your kind of quick analysis of looking at those tools, is there one of those that you were like, hey, this is the one I'm gonna recommend folks use? Or do you think there's more than one that are adequate in doing this kind of drawing of data flow diagrams remotely?

6:06Adam ShostackThere is. I was really surprised. I thought there were gonna be more trade-offs, but I really am impressed by Miro.

6:15Chris RomeoOkay. Well, we're taking a look at Miro. We've got a video stream of Miro that's available for our listeners to check out. And so what are some of the things about Miro that drew you to thinking about this as a threat modeling platform? And before you continue and answer, I'm gonna say none of the 3 of us have anything to do with Miro. Like, we have no interest in it at all other than we're threat modeling people and we wanna figure out how to do this better remotely. So Miro's getting no money from us, or we're getting no money from them, and we're just practitioners here. So what do you love about this, Adam?

6:49Adam ShostackSo Miro had been mentioned whenever people are talking about threat modeling remotely on the OWASP Slack channel for threat modeling. Miro comes up and I poked at it a couple of years ago and I wasn't that thrilled. And I did an exercise yesterday. I spent 5 minutes taking a diagram that I use for my classes and trying to draw it in each of a couple of tools. And Miro, was fast, it was elegant, the diagram looks decent without me having to have spent a lot of time tweaking it. And as we're discovering today, it's got a collaboration mode where I can watch each of your cursors moving around. And this diagram, by the way, is intentionally incomplete. There's stuff that's not on it. It's for a— Rental bike service. So why don't we just add in some componentry that we might add to a rental bike service?

7:56Chris RomeoOkay, so we'll— yeah, we can add in a couple of different, uh, I see one thing that's definitely, uh, missing here, and that is the bad people. You have no bad people here. Who's going to be trying to steal this bike? We don't have them modeled here at all, which is a problem. We need to add some bad people. It's always where I go is the bad people. And say, let's see, where do I want to put this? Oops, oops, oops, oops. It's got a nice undo function too, I figured out, because I'm cool to like push a lot of buttons quickly, just like Superman III, for those people that were around in the '80s, they'll get that joke.

8:36Adam ShostackSo you know what's sort of funny is I'm watching your mouse is I can tell you have a smaller screen than I do here.

8:41Chris RomeoI zoomed in because I got bad eyes.

8:44Adam ShostackAh, I couldn't see. I'm watching you move over like what looks like an inch from the diagram. And as you're talking, I know that you're in the little control panel over there, but my control panel's another couple inches over. So that's an interesting little difference.

9:03Robert HurlbutYeah, yeah, definitely.

9:05Chris RomeoAll right, so let's see. Let's add some bad people here. I keep saying I'm gonna add bad people and then I'm not adding bad people. So I'm gonna use this and I'm gonna put somebody up here. We're gonna call this bad people. Bike thieves, bike thieves, thieves. Good luck trying to spell thieves in a recorded format.

9:27Adam ShostackHey, you know what I discovered? Because I had a couple of minutes to poke around, if I click the little 3 dots on the bottom left, on the left, there's an icon finder.

9:38Chris RomeoOh, nice.

9:39Adam ShostackAnd so I'm just going to type devil in here and hit return. And holy cow, they've got a devil that looks like my threat modeling guys.

9:47Chris RomeoSo I'll put that up there by the bike thieves. So the bike thieves, though, are gonna be interacting with the lock. So we better move the bike thieves down here. Okay, so we've got the lock outside of the trust boundary, right? Because the lock is in the real world.

10:08Robert HurlbutMm-hmm.

10:10Chris RomeoAnd so then we have a lock activator. So it's making me ask some questions now about your Your trust boundary. So is this a self-contained electronic lock that's protecting the bike? Is that what we're modeling here?

10:25Adam ShostackSo in this diagram, there's an actuator and a sensor, right? And so the actuator would unlock the lock, you know, turn a magnet on or off to let the lock move. And then there's a sensor to tell you whether or not things are closed. But yeah, there's a physical lock that sits in the spokes and stops people from moving the bike. bike or stops people from riding the bike while it's not— while they're not paying us.

10:56Chris RomeoOkay, and so, hmm, where's the payment processing here?

11:01Adam ShostackSo payment processing, we don't have this yet, but let me draw a little app over here and make that a solid line. So the bike talks to the Bluetooth, or the bike, the app, your phone talks to the bike via Bluetooth. So we'd send a message here and label this unlock. And then the bike, and I'm not drawing in the trust boundaries just yet, but there's a cloud service up here and the app talks to the cloud service and gets, and so the unlock message would come down.

11:46Robert HurlbutOkay.

11:47Adam ShostackVia payment. All that happens off the bike via— it's a little hard to read the word unlock there, it's sort of small text. But that would— the app talks to the cloud service, the cloud service talks to a payment backend. And, you know, the thing I like about this as an example threat model is we've got some IoT, we've got some mobile, we've got some cloud, we've got some payment all in a All in a package that's a little bit fun to think about how it might work in the real world. Hey, I can change the nature of a shape, and that's pretty cool. Let's make this payments.bank.com.

12:27Chris RomeoI'm not loving any of the icons for the cybercriminal, but so I'm gonna go with just a jail cell.

12:35Adam ShostackAll right.

12:35Chris RomeoThat's where they're gonna end up eventually.

12:37Adam ShostackYou know, I think, I think there's a way to stick your own app or your own— you can do a web page capture here. So if you just put your picture in an app or maybe it's the upload. Yeah, I can upload a file. Let me try uploading something and seeing what happens.

13:03Chris RomeoI'm going to finish my dataflow diagrams here. At least my data connectors is what I'm working on now. So I've got meatspace bike thieves. They're going to attack—

13:16Adam ShostackThere you go. So yeah, you can upload a file and just include it.

13:20Chris RomeoOkay, so that's a good— that's a nice feature. So yeah, I mean, so I think what we're seeing here is the 3 of us are collaboratively working on a threat model, and we could, if we had somebody who was brand new to threat modeling, we could be letting them do the work while we're doing the talking.

13:38Robert HurlbutMm-hmm.

13:38Chris RomeoAnd just asking questions, which that's the way that I've always taught threat modeling, is to say, let's talk about threat modeling for about 5 minutes where I describe it. And then what I'm going to do is have you draw me a picture, and I'm going to start asking questions about it. Some questions I'll know the answer to, others I won't. And that's okay. I'm fine with that. I'm just going to ask lots of questions to see how you're able to adjust the diagram and connect with how the thing actually works. Hence the reason I asked about the payments, because You always want to follow the money, but that's just—

14:12Adam ShostackAnd you're saying I did the right thing there? I just started drawing the way you expected me to draw, huh?

14:16Robert HurlbutYeah.

14:17Chris RomeoNo, I mean, I think that's, you know, you start thinking about, well, the bikes app has to sit outside the trust boundary. There's no way you can say that's— unless you had some type of a trusted device, which we're not there yet in this world. The cloud service, there's probably what we're seeing here is there's actually multiple threat models now jumping out off the page, and we're starting to get to a macro threat model, which is, I think, always a danger early, early on because you can end up with a picture that has so many pieces that nobody can ever understand it. And from my perspective, I'm a simple guy. We gotta keep it simple if you want me to be able to understand it. And so that's one of the challenges that we could have in using this type of format is we could get too complicated too fast.

14:58Adam ShostackWell, you know, that's a danger that exists with the whiteboard as well. And so I think it's really important as we break this out and say what's new in the world of threat modeling, In this world where we're all working remotely, you're right, we can make the same mistakes that we can make at home when we're in the office using these tools. The, the thing that excited me when I started looking at this was how quickly I was able to start drawing, get something that looks better than anything else I draw, Without a lot of effort, we're collaborating in this tool. I think people should give it a shot.

15:43Chris RomeoYeah, totally, totally agree.

15:45Adam ShostackCan we get an affiliate link?

15:46Chris RomeoWe should, we should.

15:50Robert HurlbutYeah, so you're trying to minimize the friction of the tool itself to get you to, you know, similar to what you would have with a whiteboard, right?

16:01Adam ShostackYes, yes, I love what you said.

16:04Chris RomeoSo we've definitely had a really good experience, I have, in being able to work collaboratively with you guys. I think it would be great for us to quickly summarize the challenges we had kicking off this Miro session, just so folks are thinking about some of the challenges that they may encounter when they start trying to use this tool with some of their devs. And so we had to sign up for an account. That account had to be— we had to go through the process of proving that we owned the email address and so we owned the account. So there was some setup that had to be done here. So what else went into the setup process?

16:40Adam ShostackSo I found a dataflow diagram template when I just came on and started searching the tools. There's a little shape and I can go to all shapes. Where was it? I forget exactly where it was, but there was a, what sort of diagram do you wanna create? When I typed in DFD, I didn't find it, but when I Googled for data flow diagram in Miro, I found something very quickly. And so I used that to get going.

17:12Chris RomeoSo I think the takeaway there for our listeners that might be trying to do this is, it will be wise of you to have a template/sample threat model like Adam had here as a place to start. It would've been a lot more difficult, especially if you have somebody who's brand new to threat modeling, It'll be a lot more difficult for them to watch you build this threat model for 10 minutes, and it won't be a great use of their time, and they're going to wonder, what are these people doing? Why aren't they talking to me? And so I think that's one of the best practices we're seeing here is make sure you understand how to set up the tool, how to educate the person you're trying to teach in what they need to do in advance, but then also come to the conversation ready with a sample DFD like Adam had here. And you can see we started playing around with it, and now we've got all kinds of, extensions that we've made to it, but it was collaboratively where we did that work, and we all learned something in that process.

18:05Adam ShostackYeah, I think that's a great summary.

18:07Chris RomeoSo let's cycle back now to some of the other best practice things that we're thinking about here. And Adam, I want to touch on one thing that you mentioned earlier in our conversation, and then Robert, I'm going to come to you for your thoughts on best practices. But Adam, you mentioned a couple of commercial tools, and we don't normally talk a lot about commercial tools, but I think they're There are some tools that we all would agree we like, and once again, they didn't pay anything to have us talk about them on this show. But I still, as a practitioner, want to be able to share that information with the world. And so, Adam, what are your thoughts then on tools? We talked about ThreatDragon. Obviously, that's a great one for people, open source, it's free. But it is not— I wouldn't describe ThreatDragon as an enterprise-ready tool.

18:55Robert HurlbutRight.

18:56Chris RomeoSo what are some of the other things that you're thinking about when you're talking about these commercial tools? Let's just call them out and say what they are.

19:04Adam ShostackSure. So the one that I like the most is Continuum's Arius Risk. And the thing I like about it is it's very oriented towards an enterprise and working across lots of threat models. And I should mention that I like it enough that I'm on their advisory board. But to me, the way they're thinking about the problem is very much aligned with the way I think about the problem.

19:34Chris RomeoYeah, and I'm a fan of Aries Risk from Continuum as well. Steven DeVries has been on the podcast here before, so he's a friend of the show. And yeah, I agree with what you're saying as well. This is a tool that's worth taking a look at from an enterprise perspective. Because it does give you that next level. How are we going to manage this across the board? Adam, from your days at Microsoft, my days at Cisco, we're used to scaling this at a big scale.

20:02Adam ShostackMm-hmm.

20:03Chris RomeoI love Threat Dragon. I'm a fan of it. But I wouldn't roll it out when I was at Cisco. It wasn't ready yet. It wasn't battle-tested from an enterprise perspective to be able to manage all those individual threat models and keep track of of them. And so, yeah, that's a good thing, good thing to think about. And definitely recommend folks take a look at that areas risk. It's a good tool.

20:23Adam ShostackYeah, and I think the, the thing to think about as your listeners are asking, what tool do I want, is do I want a drawing tool like Miro that allows me to create these diagrams, get consensus around what we're working on, where the trust boundaries are, how it's put together, what the components are so that we can be comprehensive, and then we'll manage our threat modeling work and we'll do the analysis of what can go wrong and we'll track that in a Word doc or something. Or do you want a tool that takes more of it on and shapes your behavior a little bit? And there's a real trade-off there, 'cause however much you like the tool, The tool makes assumptions about what you should do and encodes them in the rules that the software has. The thing that I really liked about Miro when I picked it up yesterday was just how fluid it felt. And I hear from some people that they feel that a tool like Continuum is very fluid for them. I hear from other people That they've got their processes that they've built out. And so do we, do we keep with the workflow that we have, with the organizational process that we have? The, the move to remote is just really important as an opportunity to say, maybe it's time to put in a little more structure, help people get the work done.

22:07Chris RomeoYeah. So let's come back around now to some of Robert's thoughts about remote threat modeling. As somebody who's a practitioner who's actually doing this on a day-by-day basis, Robert, what are some of the best practices that you would share with our audience?

22:21Robert HurlbutWell, I think we've covered a lot of them already. Making sure everybody has similar tools, making that decision. I do like what Adam mentioned. You do need to make a decision on how you approach threat modeling, either from the drawing tool perspective, and we keep track separately, which is very similar to what you would do with a whiteboard many times, or you go and take a look at a tool that will help you navigate through finding threats, identifying threats, and follow up and so forth. I think that's a really good point, is to make that decision. But secondly, working remotely, of course, you need to make sure you have good remote tools in place, whether that be tools that, like we've been looking at here, that naturally allow good collaboration inside the tool, or you use other video screen sharing tools that allows multiple folks to see a screen or see multiple screens at the same time, something along those lines. So that's also a factor as well that can help you with either being successful or causing more friction. So that's the other thing you have to kind of weigh in those decisions as well.

23:46Chris RomeoAnd Adam, it looks like you got some other questions here based on the chat.

23:50Adam ShostackNo, no, I was just modeling the behavior. I was taking some notes. in the app as Robert was talking.

23:57Chris RomeoOh, that's great. No, and I think you did touch on something there in the notes that I think even goes a step further, and that is, what are we doing from a video collaboration perspective? Like, we're actually recording a podcast now, so we're not actually looking at video of each other, but is that something that's going to be important in this remote world when we're doing threat modeling remotely? Is it good for us to be able to see the look on each other's faces?

24:20Robert HurlbutYeah, and I hear both. I hear sometimes, no, not so much. We're just focused on For example, a whiteboard, we're focused on that, so let's just do that. And then I hear the other side where, and I've seen the other side where, okay, no, we need to see each other. We need to make sure we're engaged. There's that aspect of when I'm working at a whiteboard, it's not that I'm just working at the whiteboard, but I'm actually talking to people and communicating. And I could see they may not say something, but the quizzing look on their face. I'm not sure where you're going with that. I could see that in a camera perhaps. So there is still that personal interaction as much as we're trying to capture that working remotely. If we can do that, then it helps just as we would be— it would help rather if we're at a whiteboard. So that's another thing to make a decision about too is how do we share? Do we just share the thing we're looking at, or do we share that as well as turning on the camera so that we can see reactions and make sure people are engaged? Especially if you have a larger number of folks who are trying to do threat modeling at the same time, a good-sized team, you might have 2 or 3 people who are actually doing the threat model, working on the threat model, or data flow diagram, or talking about it, and then you've got maybe 5 people who are sitting and multitasking, doing something else, and I may not be engaged because, hey, the remote and there's no camera on me, no one knows type of thing. And so you sometimes have to make that decision as well, that maybe turning on the camera kind of forces us to be engaged and be there and verify that we can see each other and react and so forth.

26:12Chris RomeoAnd that makes me think as a teacher of threat modeling, Something we need to do in this remote world is we need to be checking in with the people we're working with directly in the collaboration. And I think we did a good job of that in our little collaborative example here because we were kind of constantly checking in with each other and drawing each other into the conversation. But I think that's something we got to do as trainers, as teachers of threat modeling. We got to be deliberate about that. And if somebody kind of appeared to drift away, We gotta ask them a question like, you know, if let's say Robert had been silent here for 5 minutes or something, I need to do something as the trainer to say, hey, Robert, you know, what do you think about the GPS radio module here? What's the impact of that? And so I'm not calling you out by saying, hey, Robert, are you paying attention? I'm just drawing you back into this remote collaborative experience. And for us as trainers, we gotta be paying attention to that stuff as teachers because we don't want anybody to miss out. on the cool stuff that's happening right in front of them.

27:11Adam ShostackYeah, and I think as everyone is learning to go remote, there's a really interesting difference between the companies that have been remote for a while. And I'll talk to a lot of people where, oh God, no, I don't turn on my camera ever. I tell people it's broken. The folks who are going remote now, almost all of the advice that I'm hearing is that your camera is on most of the time. Managers' open door policy is they have a Google Hangout or a Zoom call that's open just showing them. And if you wanna walk into that room, the URL is available to you. And that willingness to share, willingness to expose the inside of our homes as messy as they are, Yeah. As our pets, as our kids come in frame and wave to our coworkers. I think there's a tolerance for that that really enables what Robert was talking about with being able to see whether or not people are engaged or if they're looking quizzical or if they're sitting there with their arms crossed and frowning. All of these things are things that we're all working through, that companies are working through. What should our culture be? What is the expectation here for the way we're gonna do this? And 90% of that just applies to the way you're gonna threat model. And then there's the 10% that's different because threat modeling involves these new skills, this critical thinking, And the specific tooling that we're gonna use to make it work. But so much of what we're doing today is just, let's figure out how to make this, let's figure out how to work in a world where we have to be physically distant from one another.

29:19Chris RomeoYeah, definitely. So as we close out this little segment we did on remote threat modeling and some best practices and things for folks to think about, Adam, I'll start with you. What's, what's kind of one thing that you would leave with our audience as a conclusion coming out of this session?

29:36Adam ShostackQuestion number 4 in threat modeling is, did we do a good job? Make the time to talk about that. Make the time to learn what's really working and what's not working, and everything will go better.

29:47Chris RomeoAwesome. Thank you. Robert, what's your kind of takeaway here for the audience?

29:52Robert HurlbutYeah, I think similar, just checking in. I think follow up what you mentioned there, just checking in with all the members in the team and making sure they feel like they're a part.

30:04Chris RomeoWell, gentlemen, thank you for taking the time to share with our audience today. Like we said, this is a special episode of the Application Security Podcast that we want to get out to our folks in our audience that are dealing with some of these issues right now. And I would say that we would be open If folks in the audience want to ping us on the OWASP Slack or, you know, on Twitter or any other places where we're hanging out, we would love to continue this conversation and hear their best practices and thoughts as well on remote threat modeling. Thanks for listening to the Application Security Podcast. You'll find the show on Twitter @AppSecPodcast or on the web at www.securityjourney.com/podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbut. Remember, security is a journey, not a destination.

5,185 words · transcript by assemblyai

More on Threat Modeling

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.