Skip to content
AppSec PodcastThe Application Security Podcast — home
29 min

Adam Shostack -- Think like an Attacker or Accountant?

With Adam Shostack

Threat Modeling

What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 11 chapters
  1. 00:00Rethinking “think like an attacker” with Adam ShostackAudio
  2. 01:25Adam’s security origin storyAudio
  3. 03:34Why the hacker mindset instruction can failAudio
  4. 07:15When security conversations make developers feel excludedAudio
  5. 08:02Rethinking how security is taughtAudio

About this episode

What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to practice it. Chris and Robert add examples from development teams, while Adam extends the discussion to infrastructure and operations. They close with practical ways to ask better questions, build a shared understanding of a system, and make security thinking accessible without demanding a new identity.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Adam Shostack:
Adam Shostack

Resources
Start With Why

Actionable

From this conversation

  1. Ask how an attacker would break the system

    When I say think like a hacker or think like an attacker, what I'm thinking about is how would I break this system, right?

    4:32
  2. Ask what could go wrong

    A bunch of different ways to ask the question, what could go wrong here?

    12:54
  3. Integrate fuzzing and static analysis

    You can integrate static analysis. build that in, you can do something else, and there's some engineering up front and there's some maintenance, but there's never enough time to do it all.

    20:16
Transcript · 29 min conversation

0:05Chris RomeoThe Application Security Podcast. Here we go. Greetings, friends. On this episode, Robert and I are joined by Adam Shostack. Adam is a well-known speaker and thought leader in the world of application security. We speak with Adam about how to connect with development teams. This whole thing started about a year ago when Adam tackled the issue of thinking like a hacker and why he wanted people to think differently. We dive deep into this issue But we also got into some other things that came out in conversation. We hope you enjoy. Okay, folks, welcome to episode 16 of the Application Security Podcast. We're joined today by a gentleman by the name of Adam Shostack, and Adam's had a pretty long career in the world of secure development, so we're excited to have him with us today. Adam, welcome to the show.

1:23Adam ShostackHappy to be here.

1:25Chris RomeoSo our first question that we always ask our guests is, what's your security origin story? Where did your security superpowers come from? So please enlighten us.

1:35Adam ShostackSo I started my career as a sysadmin at a medical research lab and over time found myself gravitating to security. And became a consultant, became an entrepreneur, worked at a big company for a while. And I don't really believe I have any superpowers. I just try and look at what's happening, assume some goodwill and some good intent on the part of the people I'm working with, and try and figure out why the things that we're asking them to do are challenging, and then solve those problems. And that's That's the approach I've sort of used through my whole career. I think it's being sympathetic to the folks around me. If I have a superpower, I don't want to say that's it, but that's where I get my inspiration.

2:39Chris RomeoYeah, that's interesting. It's certainly not a technical skill to really have a perspective on what you can do to help other people solve their challenges. But I think that's something that applies to all of life. That's not a security thing. That's just a trait that helps you be successful in anything that you do.

2:59Adam ShostackI hope so. I mean, it's— I've never been able to scale to the organizations that I work for. And so, I always find myself asking people, hey, could you do this? Could you do that? And they say, How, how do you do that? And I think a lot of the things that I've done along the years have been, how do we take this from being a super expert, you need to be a magician, to you need to be an engineer?

3:34Chris RomeoYeah, that's kind of what we want to talk to you specifically about today. And those folks that know you and are familiar with your work in the past, are expecting that we're going to have a threat modeling conversation right now because you are the person who officially wrote the book on threat modeling and have been responsible for influencing a lot of the threat modeling that's out there. But I actually want to ask you a different question because I know that you've written on this idea of why you dislike the term thinking like a hacker. And so I want to unpack that a little bit for our listeners because I really, I heard you say it in a conference talk and then I saw that you had blogged about it and I really grabbed onto that idea too. But I want our listeners to understand the perspective from the original person who came up with this idea. So what does it mean, first of all, when we say we want to teach somebody to think like a hacker?

4:32Adam ShostackSo when I say think like a hacker or think like an attacker, what I'm thinking about is how would I break this system, right? Where would I, if I was gonna teach take it apart, where would I first insert my crowbar? What could I make it do that it's not supposed to do? And in security, we learn to do that. We learn to analyze a system. We learn to say, oh, here's an open port. I wonder what happens if I send it something unexpected. Here's a database query. I wonder what happens if I put some extra quote marks and semicolons in it. And we learn to do that and we do it over and over again in the course of prodding at the systems that we're responsible for. And in that sense, thinking like an attacker makes a lot of sense and you can ask a security person to do it and they know what to do. The flip side to this is when you ask a normal engineer to do it, and I'll tell your listeners the story, and I'll make this the PG-13 version of the story. It was a little bit after I had started at Microsoft. I was in a meeting with this guy who, and I said, think like an attacker. And he scowled a little bit and, you know, being at Microsoft, went back to his laptop and stopped participating in the meeting. And then afterwards, he politely came out and said, can I talk to you for a second? And said, you know, I didn't really appreciate when you said think like an attacker. Oh no, wait, wait, wait. This was Microsoft. This was 2006. He said, "That was the stupidest bleep bleep bleep I've ever heard." And he was really mad. He was really, really mad at me. And I talked to him for a minute, and I got him to calm down. And he said, "I don't know what the heck it is to think like an attacker." And when you said it, you made me feel dumb. And it really stuck with me. I mean, this was over a decade ago, and I can still I can still see his face.

6:59Robert HurlbutI can't remember his name.

7:02Adam ShostackNot sure I should share his name even if I remembered it, but it really stuck with me. The, you made me feel dumb. Nobody wants to collaborate with someone who calls them stupid.

7:15Chris RomeoWhat do you think? What do you think it was that made him feel— that made him feel like he was stupid? Was it he didn't have the security vocabulary or knowledge, or what do you think that stemmed from?

7:31Adam ShostackI don't think he had any idea how an attacker thought, how an attacker thinks. Right? It's like asking you to think like a CPA.

7:43Chris RomeoI'd be in trouble if that was the case.

7:46Adam ShostackLike an accountant?

7:46Chris RomeoNo. And I would probably be quickly in jail after a couple of tax seasons. But because I don't know what I'm doing, I mean, I'm competent as a CPA.

7:56Adam ShostackYeah, I don't even know what the first question I should ask is if you were to ask me something like that.

8:02Chris RomeoOkay. So then, so what— so did this cause kind of a change in your perspective? Was it the result of that story where you kind of went back to your cube and said, I got to do something different here?

8:24Adam ShostackIt wasn't immediate. It was, it was really looking, you know, I said, okay, is this a one-off or is this a problem that happens? And I saw that people see the stuff that we do as sort of magical, right? You wave your hands and all of the sudden Clippy is on screen singing. True, true demo that was, that was done for executives at Blue Hat. You can find the story of Clippy Sings out there somewhere. But people don't get it. They don't see, they don't see the steps. They don't see the days or weeks of sitting and looking at assembler or trying to write an exploit. They see the result, and the result is this magic thing. And so that's what really got me thinking about, okay, how do we teach this? How do we transfer these skills in bite-sized learnable pieces? And, and that's really the origin of a lot of the detail in the threat modeling book is about how do you, how do you break it down for someone in a way that makes it learnable, right? The 3 of us have been doing this for so long that we forget what it is to be a beginner. Yeah.

10:10Chris RomeoYeah, that's true. And I think about also the— when you tell somebody to think like an attacker, we have a Hollywood version of a hacker or attacker. And I think about some of the movies that people may have in their frame of reference. If they're not familiar with security, they may look to something like The Matrix or Hackers, the movie.

10:33Robert HurlbutYeah.

10:35Chris RomeoAnd even in our kind of a modern connotation right now with this Mr. Robot TV show, which is pretty technically reliable. But so they have this kind of perception though that it really doesn't have anything to do with what I do as a security person every day. I mean, I'm not—

10:53Robert HurlbutMm-hmm.

10:54Chris RomeoSkateboarding around and hacking the cube or whatever they were doing on Hackers or traveling through the Matrix. But I think they get this Hollywood view as well, which could also cause somebody to be challenged when you say, well, think like a hacker or think like an attacker. And they're thinking, well, I've only seen movies about what these people are supposed to do, but it looked like I'm supposed to type the keys a couple of times and then something happens and I'm in, right? It's the CSI Cyber effect of hacking.

11:20Adam ShostackYeah.

11:22Chris RomeoSo, where do we go then? Or where did you go in your little bit of a journey here? You went from having this moment and then doing some more research and thinking about it, how did you approach this to try and fix this for an entire organization?

11:39Adam ShostackA lot of watching, a lot of listening, a lot of— and this is hard, right? When you're the expert in the room, people turn to you literally and figuratively. They turn to you and say, what do we do now? And no, So, for me, it was, how do I get them started with something easy to get that sense of flow and engagement going? And this is where I really started to get away from asset orientation and attacker orientation because I found this question that worked.

12:24Robert HurlbutOkay.

12:25Adam ShostackWhich is, what are we working on here? Let's go to the whiteboard and sketch what we're working on, because everyone in software engineering does that. Everyone in operations does that. They've got a project that's going on, and they can talk about that project. And you get them talking, and then you start saying, well, what could go wrong?

12:51Robert HurlbutMm-hmm.

12:54Adam ShostackAnd a bunch of different ways to ask the question, what could go wrong here? You can use STRIDE, you can use OWASP, you can use all these different things, or you can just say, what could go wrong? And let them think about it. And odds are they've got some answers that they know, right? They don't have the structured knowledge, they don't have the depth of knowledge, but they've got— Right. They've got some idea, and you can help them build on that. And that's that's what I really enjoy doing when I train people is to just get them talking about this stuff and demonstrate to them, reinforce for them, acknowledge, say, "Hey, you know what you're doing," and. From there, they need some nudges. They need to know what to do when they stall out. But I like to tell them, when I do my Star Wars threat modeling talk, I start out by saying, you know how to threat model. And it's true, they really do. You threat model a house, they know how to do that. They also, they need a little help, but not that much. And so that, for me, that's the fun balance is finding where that not that much fits in.

14:16Chris RomeoYeah. And I usually start my sessions by saying, when I'm working with a new development team that really doesn't have any security background, I say, you folks in this room are the experts in your product and your features and how it works. I know nothing. I'm just going to ask a whole bunch of questions, some of which are going to sound like I'm smart and know what I'm talking about, others of which are going to make me sound like a moron. But I'm just going to keep asking questions till we— till I can— to help me unpack kind of what's happening inside of your feature. But I think the key thing is that the developer is truly the expert. And so we're just trying to add a little bit of that nature of pulling apart what they've done to focus them in. And they don't even realize it, but they're doing security at that point.

15:03Adam ShostackI doubly love it. One, I, I, I— the, the thing that I really love about starting out that way, and I'm gonna borrow that, is you're acknowledging the expertise and skill of the person that you're dealing with. And who doesn't like that?

15:22Chris RomeoYeah, that's true.

15:23Adam ShostackIt, it's powerful right there to say, you guys are the experts on this. It creates a balance between you and them that can disappear if you don't nurture it.

15:41Chris RomeoYeah. And my experience is similar to yours in that most of the places that I've worked, it's been an uphill battle. So, it was not even a battle. Battle is not the right word, but people weren't on board with security in the beginning. So, if we came in and just said, here's all the things you have to do, we'd kind of overwhelm them and they'd just shut down and say, I don't even— that's too much. I can't even do anything with it. So, yeah, I think this is a good way to connect with people. And I think that's, once again, is good advice for bigger than the security world. But connecting with the people that you're trying to influence is always going to end up with a better result than trying to force them to say, Yeah. You have to do this or we're gonna hit you over the head.

16:25Adam ShostackDo you find that's the same now? Because it sort of ironically, a lot of the places I've worked, people have been okay with the security thing. It hasn't been something I've had to advocate for, right? I've done work at a hospital, I've done work at banks, I've done work at Microsoft where the transformation to we care about security had already occurred and it had boiled down to how. And I'm wondering if now when you go out and you're talking to new organizations, do you need to sell people on the why or do you need to sell them on the how?

17:08Chris RomeoOkay, it depends. I've seen both at this point. So I've had a chance to interact with startups and some big companies that are kind of behind, I guess, behind where the rest of the industry is. And I'm seeing both. I mean, I've got a startup that I've been working with that's super excited about security, and they're just looking for how do we plug application security into what we're doing. They're about, say, 100, 200 people, somewhere around there, and they feel like, hey, it's time that we actually dedicate somebody as a part of our team to do this. But then on the flip side, enterprise customers that are not yet have everybody bought in, I think they're still out there. I think it's less than it would've been. I mean, I've been floating around this world of security for 20 years now, and it was certainly much different back in the old days when a lot of times people didn't even know what we were talking about. To then we got to the phase where people just said, oh, we know what you're talking about, but the answer is no, we're not doing it. to, in general now, I think the industry has moved forward and I think most people are not going to fight over the idea of doing security. But I think there's still— one of my key principles is I always start with why. You know, Simon Sinek wrote that book on Start with Why, and I apply that to what I do now because— And I try to do that with everything because I find that if you explain to somebody the why, even if they think they understand the why, If you understand it, if you explain it from your perspective, it just really changes the conversation because then they know what's really at stake and they can be like, oh, well, maybe I should do some things differently here.

18:46Adam ShostackThat's interesting. I haven't read that book, but I'll put it on my list. When you say, you know, we don't want to do that, one of the things that I saw, and I saw this even at Microsoft, where is Security is one of something like 20 -ilities that matter, right? There's security, there's privacy, there's usability, there's accessibility, there's maintainability, et cetera, et cetera. And the developer takes a job at Microsoft 'cause they wanna build stuff that they can show to their mom and say, I put this in Windows, right? Yep. And there's always a trade-off. And I think if you start with the why, why do we do this, you enable a different conversation about what trade-offs get made than if you start with the, we need you to do this and this and this. And at some point, the list just gets too long, right? There's— and this is the case not just for security, it's the case for features, right? You think back to like the iPhone 1, The iPhone 1 didn't have an app store. It was still an amazing product, but it didn't do everything that they wanted it to do. Over time, they added more and more, and the same thing happens in security, right?

20:15Chris RomeoYeah.

20:16Adam ShostackYou, you build in fuzzing, and then you don't need to spend the effort to integrate fuzzing anymore. You can integrate static analysis. build that in, you can do something else, and there's some engineering up front and there's some maintenance, but there's never enough time to do it all.

20:37Chris RomeoYeah, definitely. So before we kind of— before we move into the phase of how can somebody do this, Robert, I want to get your take on this as somebody who has done extensive development and extensive security work. What are you seeing? Have you had any experiences? And how do you approach this in the training that you do? Do you teach— do you try to do the think like a hacker? Do you think like a security person? Or how do you approach it?

21:06Robert HurlbutWell, I was going to say, because I have that software background, I'm also dealing with developers. I'm dealing with people who are trying to put together applications. So that's the majority of the people that I work with. I've also taken that approach of, you may not know what an attacker thinks or how they would think. That's also been my approach as well, to take that more software-centric view that we don't know and we may not be able to know, but if we can think a different way, ask the right questions, ask some good questions, I think it's a good approach. I was going to say on the other question that was asked about, is it why and how? I'm also seeing the same, that I'm not seeing why as much. It was definitely out there a lot years ago, but typically the customers I'm working with, the people that have contacted me, already figured out the why. All they have to do is turn on the news or look at the latest news and see why. It's the how. But I also had a question actually also for Adam, and this is in regards to software versus other ways of approaching these security problems. I think you mentioned that your background, Adam, was sysadmin, if I remember correctly?

22:25Chris RomeoYeah.

22:26Robert HurlbutAt the beginning. But your approach has been mostly software. So what would you tell someone who is a network person, an admin person, an infrastructure person? How would you help them to think certain ways about their system, not necessarily from a software, because that's in particular my background, as Chris mentioned, But other parts of the system, how would they think about this in terms of the attacker versus not and so on, or is it very similar?

22:53Adam ShostackI think it's very similar. And I always start from the question of, what are you working on? What are you building? What are you deploying? Let's look at that. And to me, when I started talking initially about software versus asset versus attacker, approaches to threat modeling. I used the term software in the hopes of using it as an umbrella term. And frankly, it was a mistake on my part. It's a mistake that I haven't corrected yet because I don't know what term to use that gets the right balance of concrete versus general, right? Because when I say software, I think, okay, I'm gonna stand up a new server. There's software on that server, right? I'm gonna stand up a new network segment. I'm gonna connect a bunch of routers. I'm gonna lay pipe between them. To me, that's part of what are you building? What are you working on? What are you doing?

24:07Chris RomeoRight.

24:08Adam ShostackAnd I call that software-centric in contrast to attacker-centric or in contrast to asset-centric. So the term software turns off a lot of people who are in the IT operations in the networking space. But I don't know what word to use that works. Do you have a suggestion?

24:39Robert HurlbutNot yet. And that's why I'm asking. That's why I'm asking. I get the same thing. I get the same thing. So, well, that's interesting, but I'm in the IT or I'm in the infrastructure, I'm in the whatever. I'm not in software, not building software, I'm building systems. So how do I do this? Yeah.

24:56Adam ShostackYep. Yeah. And I mean, when I talk about it now, I try and say, I'm including you, but it's never as inclusive. And I hate the outpouring of words that is necessary to be inclusive because I wanna talk about the point of do this. And to do that, I have to say, if you're building something, if you're deploying something, if you're architecting something, You can draw it on a whiteboard, and that's the real key.

25:35Robert HurlbutSo we can visualize it and we can think about what it is. That's the first part anyway, right? Yeah.

25:47Adam ShostackYeah.

25:49Chris RomeoSo I think this would be a good time to transition into some actionable things. So Adam, from, from your perspective, what are some actionable things that our listeners could do if they're faced with this similar type of situation at their place of employment where some people are saying, well, we need to think like a hacker, and so there's confusion. What would you recommend? Like, what would be 3 things you'd recommend that they do to try and right the ship and get people focused the right way?

26:20Adam ShostackWell, the first is to ask if it's working. Maybe it works for your organization to say, think like an attacker. Maybe it's working for the people around you, but really, really take a close look. Are they engaged? Are they— are their brows furrowed? Are they reading email? Are their arms crossed? So first ask, is it working? If so, stop. If it's not working, then acknowledge the mistake and move to something different. And the different that I recommend is to say, what are we working on? Take those people whose arms are crossed, who are reading their email, and say, can you walk me through what you're working on? And then say, what can go wrong here? And work with them to set— to help them see You know, common problems like someone might pretend to be someone else when they're logging in, or, well, this connection isn't encrypted, so someone could monitor it or make changes to it, right? The easy spoofing, the easy tampering sorts of things. And so your actionable steps are, Ask if it's working. If not, ask, what are you working on? And the you is important again. And then say, what can go wrong here? And that'll get you into a— that'll get you into a better space.

28:09Chris RomeoDefinitely. That makes perfect sense here. So, Adam, thank you for taking the time today to address our listeners on this topic, and we look forward to following you into the future, into all the other exciting things that you're working on. So thank you very much for taking the time.

28:25Robert HurlbutYou're welcome.

28:27Adam ShostackIt was a pleasure.

28:27Chris RomeoThanks for listening to the Application Security Podcast.

28:33Adam ShostackOur intro music is 8-Bit Kung Fu by Boring and TJ, and the outro is Southern Delight by Stefan Cartenberg.

28:39Chris RomeoYou can find us on Twitter @appsecpodcast or on the web at www.appsecpodcast.com.

4,295 words · transcript by assemblyai

More on Threat Modeling

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.