--- title: "Brett Crawley -- Threat Modeling Gameplay with EoP" url: https://appsecpodcast.com/brett-crawley-threat-modeling-gameplay-with-eop/ date: 2024-12-10 duration_seconds: 2728 season: 11 episode: 29 guests: ["Brett Crawley"] topics: ["Threat Modeling", "Privacy and Compliance"] audio: https://www.buzzsprout.com/1730684/episodes/16229133-brett-crawley-threat-modeling-gameplay-with-eop.mp3 video: https://www.youtube.com/watch?v=PUrpe3uDEVU transcript: true --- # Brett Crawley -- Threat Modeling Gameplay with EoP *December 10, 2024 · 45 min · Season 11, episode 29* with [Brett Crawley](https://appsecpodcast.com/guests/brett-crawley/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Privacy and Compliance](https://appsecpodcast.com/topics/privacy-and-compliance/) [Audio](https://www.buzzsprout.com/1730684/episodes/16229133-brett-crawley-threat-modeling-gameplay-with-eop.mp3) · [Video](https://www.youtube.com/watch?v=PUrpe3uDEVU) ## Show notes Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP. On today's episode, we're excited to host Brett Crawley, a principal application security engineer with over 25 years in software engineering and more than a decade in AppSec. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Brett Crawley: → [Brett on X](https://x.com/brettcrawley) → [Threat Modeling Gameplay with EoP](https://www.packtpub.com/en-us/product/threat-modeling-gameplay-with-eop-9781835089156) Mentioned in this episode: → [Brett on X](https://x.com/brettcrawley) → [Threat Modeling Gameplay with EoP](https://www.packtpub.com/en-us/product/threat-modeling-gameplay-with-eop-9781835089156) → [Conscious Business by Fred Kofman](https://www.fredkofman.org/lec-ing.php) → [Elevation of Privilege](https://owasp.org/www-project-elevation-of-privilege/) → [Adam Shostack](https://adam.shostack.org/) → [Threat Modeling Manifesto](https://www.threatmodelingmanifesto.org/) → [MITRE CAPEC](https://capec.mitre.org/) → [The Security Table (podcast)](https://podcasts.apple.com/us/podcast/the-security-table/id1659280767) Chapters: 00:00 Meet Brett Crawley: Threat Modeling Gameplay with EoP 01:57 Yeah, it's like almost the only thing we ever talk about 05:16 Okay. Very cool. So diving into our topic today, to get 06:45 About the Elevation of Privilege card game 08:44 There a, just to clarify here, make sure I understand, we 13:26 Anybody win 15:20 Um, just to go back and revisit, uh, who created the 17:45 Well, insecure data flows or open data flows, for example, things 20:11 Then people can say, well, we've got TLS everywhere now, which 22:38 For example, privacy and trim, T-R-I-M. Could you describe those or 25:49 Can I take these cards that are extensions and put them 27:45 Um, so is the goal then that I finish the card 29:51 You mentioned from, as a key to success for a threat 38:45 All right, let's jump in the lightning round. So we have 41:06 Yes, thank you. So next question is, if you could display ## Transcript *5,872 words · assemblyai* **0:00 Chris Romeo:** On today's episode, we're excited to host Brett Crawley, a principal application security engineer with over 25 years in software engineering and more than a decade in AppSec. Brett's not only CISSP, CSSLP, and CCSP certified, but he's also the project lead on the OWASP Application Security Awareness Campaign project and the author of the O-String Security Blog. In this episode, we'll explore the significance of using games in the workplace. Specifically for threat modeling, we'll delve into the elevation of privilege card game and its origins, and we'll discuss whether Stride is dead, alive, or evolving. Brett will also walk us through the book that he's written about this game, and he'll cover his Miro template, which helps to enhance threat modeling with the game. So stay tuned for. A conversation on integrating security by design into the SDLC and optimizing risk reduction through a data-driven approach to AppSec. The Application Security Podcast is brought to you by Security Journey. Security Journey is an enterprise-class solution with lessons that are built on learning science principles to deliver long-term, measurable results. Learn more at securityjourney.com. **1:16 Brett Crawley:** Hey folks, welcome to another episode of the Application Security Podcast. **1:26 Chris Romeo:** episode of the Application Security Podcast. This is Chris Romeo. I am the CEO of DaVinci, the threat modeling company. And as a matter of fact, we're going to talk about something related to threat modeling today. I'm also joined by my co-host, and as I like to say, threat modeling person to the stars, Robert Hurlbut. **1:45 Robert Hurlbut:** Hey, Chris. Yeah, Robert Hurlbut, Principal Application Security Architect and Threat Modeling Lead at Acquia. And yeah, this is a great topic to talk about, threat modeling. We enjoy that immensely. **1:57 Chris Romeo:** Yeah, it's like almost the only thing we ever talk about if we get the chance. But we talk about other things too. But excited to be joined by Brett Crawley, who has written a recent book on the topic of threat modeling, and that's Threat Modeling Gameplay with EOP. We're going to break that down. And don't worry if you don't know what that means yet, because you're about to find out. But Brett, before we jump into threat modeling and elevation of privilege, tell us your security origin story. If there was a comic book in the life of Brett Crawley, specifically to security, what would we find in release or episode number 1 of that book? **2:38 Brett Crawley:** Okay. In episode 1, you'd probably find It was back in about 2000. I was asked to extract information from PDF documents, and at the time there wasn't a decent— well, there wasn't a library for doing RC4 decryption in Java, but there was in Bruce Schneier's book in C. So I ported it to Java and that was how it all started. I got a little bit into cryptography, started doing digital signatures, and then I ended up working for a company doing search engines for electronics industry. So I was always doing more and more parsing, more and more text extraction and things of that nature. I ended up at the European Commission where I was developing a product a bit like Maltego for doing OSINT. It was the OSINT suite for the European Commission, multilingual, multi-script, and involved some machine learning for translating the characters. And it was, again, there was some cryptography involved. And gradually, I was getting more and more towards security throughout my career. And so I eventually went, well, what am I messing about at, right? Why don't I just start doing security? So I moved from, I'd been working as a software engineer for like the past 25 years. Well, at that point, probably about 15 years, but I'd been doing bits and pieces of security all the way through. And so then I started doing AppSec, and I've developed stuff to do with single sign-on with Kerberos, bit of everything. And, but now instead of just developing security solutions, I'll be more around actually working with teams and helping them develop their solutions. **5:15 Robert Hurlbut:** Okay. Very cool. So diving into our topic today, to get us started, Question about, Brett, what is the significance of using games in the workplace? **5:32 Brett Crawley:** Well, it's engaging. I mean, often engineers don't want to step back from the keyboard and they don't want to, they're very focused. It's, I guess it's a mindset. And I remember when I was just doing development work, sometimes you just want to be focused on the development, and you don't want distractions. And I often find that they see threat modeling, and they see discussions around security as not being relevant to them. And it's, trying to convince the teams to get involved and participate so that you get the information needed and you also build their awareness. So it's getting people involved. It's the engagement factor. And that's where the games come in because if you can make it fun, then it's more engaging. **6:44 Chris Romeo:** So how about the Elevation of Privilege card game? So I know that's the, just a spoiler alert, that's the EOP that we talked about in the book title. But let's unpack for our audience, what is Elevation of Privilege? Where did it come from? Who created it? And what was the purpose behind it? **7:08 Brett Crawley:** Okay. Elevation of privilege, well, is a threat category. And elevation of privilege is where you can either, an attacker can either gain higher privileges or they can move laterally and they can take on somebody else's privileges of the same level, but they can therefore see the data. So that's what elevation of privilege is, but the game Is, uh, it's a card game and it was, uh, um, it's a card game where, uh, the suits of the card game are, um, the different stride categories. Um, but at the same time, uh, it's, it's played like you, uh, as a, you play tricks. So you basically, uh, you're trying to win a hand by having the highest card. **8:06 Robert Hurlbut:** Yeah. **8:07 Brett Crawley:** And it's got a trump in a trump suit, which is the elevation of privilege suit. And on each card in each suit, you've got a description of a threat, but it's quite a high level. And that threat is so that you can look at your architecture and try and find somewhere in that architecture that type of threat. So, it's left reasonably high level intentionally so that you can find different threats within your architecture. **8:43 Chris Romeo:** So, is there a, just to clarify here, make sure I understand, we sit down at a table, Robert and I are developers, there's a few other developers with us, you're the game, you're kind of running the game for us. Do we have an architecture on paper that we kind of put in the middle of the table that we all look at and that's what we're— why is that the basis of the game or where does it, where does the source of that architecture come from? **9:10 Brett Crawley:** Okay. So you would put your architecture on paper, on paper or on a whiteboard, however you prefer. You could even do it digitally on something like Miro. And you, You, on that architecture diagram, you obviously, you will need to put things like trust boundaries. And a trust boundary, for those who don't know, is where data is flowing from one level of protection or— Boundaries. One level of security into another. So perhaps going from your internal network to your— through your firewall and onto the internet might be tunneled, but it's still going through the internet to some other place. So the minute it moves from one of these areas into another, that's where your boundary is. So that, so you've got, you would draw these onto your diagram so that you know where those boundaries are, so that you know when the level of protection that that piece of data that's flowing is changing. And you can then put mitigations in place to improve the security of that piece of data, perhaps when it's in transit. via TLS, so cryptography. And you'd design the— you'd put this onto your own diagram, which you'd put on a whiteboard or on the table, like you said, and you maybe put the threats onto that with Post-it notes, as an example. And you just stick them on where you can see the threat. And when I was talking about the threat descriptions being on the cards, they're really like prompts so that the team, when they're looking at this diagram, they can, I've got this threat, where might I find it on the diagram? And so, the diagram is there to help everybody in the room be on the same page and have the same context. Well, have a context because they all have different contexts. Uh, that's another thing about the game. Should really have, uh, different members, uh, or different team members in the sense you should have some, maybe somebody from product, uh, maybe even somebody from, uh, Arc, uh, who knows what the, um, um, what your I'm just trying to think what legal issues you may have if the data escapes. So that's from a privacy aspect. Then you've got maybe somebody from the front end, a front-end engineer, a back-end engineer. **12:26 Robert Hurlbut:** Mm-hmm. **12:28 Brett Crawley:** And you've got these different people and they, They will each have different context. The legal person will have the concerns about how this could affect the company in a litigation situation. The product person will have a knowledge of perhaps something that the way the customer uses the product that the engineers aren't aware of. And so you've got this mix of people. And so the diagram sort of brings everybody together and then they can, they're discussing all of their different ideas of what the threat could, how the threat could manifest itself. **13:14 Chris Romeo:** And so the game, the cards and the gameplay acts as a catalyst. **13:19 Robert Hurlbut:** Yes. **13:20 Chris Romeo:** To get them thinking about the particular architecture that they have in front of them. **13:26 Robert Hurlbut:** Yeah. **13:26 Chris Romeo:** Now, does anybody win? Because when I play games, I wanna win all of them. And so is there like, how am I declared the winner? Is that a possibility? **13:34 Brett Crawley:** Well, there's more than one winner there. I mean, there's the, there's the customer, but there's also the, for each, for each trick, whoever has the highest card wins the trick. But when you put a card down, if you find a threat in the on the diagram and you add that to the model, you score a point for finding that threat. If you, I mean, you can add variants to this. So if you can find more than one threat, you can get at least 2 points. If you can steal or do an assist for somebody else, then you can get an additional point as well. So you could arrive at 3, and if you won the hand, you've got 4 points for just one hand. And then at the end of the game, it's whoever's got the most points, basically. But I mean, the real winner is the company because, or the customer as well, because the more threats you find, the more secure, hopefully, your product's gonna be. **14:45 Robert Hurlbut:** Yeah. **14:45 Chris Romeo:** I still like to win. the game myself personally. It's good that the company is winning as well, but there will be one winner at the table. **14:52 Robert Hurlbut:** Yeah, I've run several sessions of the game before, and, uh, I remember one in particular where there was a, a number of folks who were playing, and, and there was one person at the, at the game that was, they were definitely cleaning up. They were, they were assisting, they were gaining points, and they were doing really well. And so they loved it. Uh, but it, it's been, it's been great to see, uh, in my experience when running sessions with the game. **15:19 Brett Crawley:** Yeah. **15:19 Robert Hurlbut:** Um, just to go back and revisit, uh, who created the game and do you know why they created the game? **15:25 Brett Crawley:** Um, Adam Showstack created the game, uh, when he was, uh, working at Microsoft. I don't know the exact details of why he created the game, but, um, I, I know that when he was at, uh, Microsoft, he, he did create it. Um, and, uh, uh, um, it's also, it also features in his book. Um, the, um, and there's a section at the back where it actually explains what the cards mean. Um, but, uh, yeah, I mean, he, he created it when he was there. I don't know the, the full details of, uh, why, but I mean, presumably to try— **16:06 Chris Romeo:** Well, we'll ask him if we, uh, he's been a guest on the podcast a number of times. **16:10 Brett Crawley:** Yeah. **16:10 Chris Romeo:** Next time he swings by, we'll, uh, we'll make sure we, we get an answer to that, to why he did. So let's, um, let's be a little controversial. **16:18 Brett Crawley:** Okay. **16:19 Chris Romeo:** So what are your thoughts on stride? Is it dead? Is it alive? Is it, or is it in need of an evolution? **16:25 Brett Crawley:** Uh, I wouldn't say it's dead, uh, but I would say that it perhaps needs a bit of an evolution. Um, I mean, it's a funny one because with Stride, what you've got is you are finding a threat, but you would normally have a chain of threats. So one threat would lead to another. And in that respect, it's sort of missing something because you should be, you don't know which cat and which, sometimes when you look at it, you go, okay, this is the threat, but then it's also, it's 2 things at the same time. Which category should I put it in? I'm a bit, and the team members, when you're threat modeling, they're often asking you that because the— A tampering threat could be caused by Um, any number of, where I'm trying to think of an example off the, off the bat. Um, I've got loads of them in the book, but, um, I don't know. **17:45 Robert Hurlbut:** So, well, insecure data flows or open data flows, for example, things like that, that then can lead to tampering. And then once you've done that, what else could you do? And so forth. Yeah. **17:57 Brett Crawley:** Well, I mean, also information disclosure. I mean, it's by managing to steal somebody's credentials and then spoof them, you gain access to data which isn't yours. So is that spoofing? Is that elevation of privilege because you've actually moved laterally? **18:20 Robert Hurlbut:** Yeah. **18:24 Brett Crawley:** It's an information disclosure. I mean, there's like 3 different potential categories that you could apply to that. It becomes sometimes difficult to decide where to put things. And I also did some mind maps, which were mapping CAPEX to stride. And sometimes it was like, well, where does this go? **18:48 Chris Romeo:** Yes. **18:49 Brett Crawley:** And so I actually put it in both to try and so that people, when they were looking at it, they could go, oh, well, yeah, okay, it could go either way. **19:00 Robert Hurlbut:** Yeah. **19:04 Chris Romeo:** And I would say kind of where I land on this issue is I also think there's a need for an evolution. But what I've kind of, what I realized, and this kind of, I came to this realization in another conversation on a different podcast, The Security Table. that I do with Isak Terendash and Matt Coles. Somebody had posted on LinkedIn that stride was dead. And so we immediately said, oh, we gotta unpack this ourselves. And what I realized as we started to dive into it is stride really needs some modern examples of how those categories play out. **19:42 Brett Crawley:** Yeah. **19:42 Chris Romeo:** So like, we started to play around with it and we were like, oh, tampering. an attacker modifying an open source package, whether they're doing it in the repo or whether they're modifying it and, you know, tricking somebody into downloading something, like they're tampering with the software. Like, that's an example of a modern tampering. And I think STRIDE, as it sits now, it leads us back to, well, tampering is messing with data on the wire between 2 points. **20:10 Robert Hurlbut:** Well— **20:10 Chris Romeo:** And then people can say, well, we've got TLS everywhere now, which we don't, unfortunately. We have TLS most places. I'll never say everywhere. There's always places people have forgotten it, right? **20:20 Brett Crawley:** Yeah. **20:20 Chris Romeo:** But that's, I think, the piece that's missing here with Stride right now is I still believe in it. I think it's an important teaching tool for people, but I think it's missing some middleware that translates it more because Stride's over 20 years old. **20:35 Brett Crawley:** Yeah. **20:36 Chris Romeo:** Right? And everybody thinks that Adam created Stride. Adam didn't create Stride. Loren Kohnfelder and another individual at Microsoft are the creators of Stride. And so what I think it really needs though is it needs some of that connective tissue that brings us into some modern 2024/2025 examples of how those categories play out now at almost 25 years after Stride was originally created. **21:01 Brett Crawley:** I mean, to a certain extent, the CAPEX Stride mapping does that because it takes up— but I mean, even CAPEX isn't complete because, uh, and neither is, uh, CWA. because one covers some areas and the other covers others. And you sort of social engineering, I think, is it missing? I can't remember whether it's missing from C— I think it's missing from CWE and not from CAPEC. **21:27 Chris Romeo:** Yeah, I think that's true. Yeah. **21:29 Brett Crawley:** And so you've got in CAPEC, there are some other areas that are missing and you've got some more modern technologies in like containers and cloud, and they're covered, but very, it's very bland in that respect. And so they need enriching with a bit more, a few more of the newer things that we're seeing out there in the wild, both technologies and the threats. **22:05 Robert Hurlbut:** Yeah. **22:06 Brett Crawley:** But yeah, I mean, I, I agree. But Adam has actually added some cards in, I think it was 2022, to the tampering deck to cover things like when you've got tampering with a, within a repo, if I remember correctly. **22:30 Chris Romeo:** Okay. **22:31 Robert Hurlbut:** Well, that, with that in mind, I know in your book that you covered some other extensions to the game. **22:37 Brett Crawley:** Yes. **22:37 Robert Hurlbut:** For example, privacy and trim, T-R-I-M. Could you describe those or explain those to us and understand what those mean? Privacy and trim. **22:48 Brett Crawley:** Okay, so the privacy one, that was by Mark, I can't remember his last name. but he was at LogMeIn. He added an extension, which was a privacy suite. It covers pretty much GDPR. It goes through the different types of threat around minimization, around not using people's data for things that they haven't agreed to. So when they've signed up, You shouldn't be using it for anything that wasn't in that original agreement. And you've also got things around, and they're not sharing their data, around protecting their data within, when it's within your system. And so that's just the privacy suite. But then you've got TRIM, which is also known as Elevation of Privacy, and it's an extension to Elevation of Privilege that covers the different private, or 4 different privacy categories. Those are transfer, so when the data is transferred across region, or into, you know, different countries. So not just from continent to continent, but also within a continent. Then you've got retention and removal. So that's looking more at the things like how long you can keep the data. And if you are going to keep the data, You can keep it, but you have to anonymize it. And there are also legal holds where you might be forced to keep it because it's in the greater, it's in the interest of the greater good. So law enforcement need, would need to see that. So they've subpoenaed it or whatever. Then you've got inference. So when you are constructing data from people's data and the ethical aspects of that as well. And then the last one is minimization. So basically don't store or don't gather more than you need to, 'cause, well, Uh, you, if you've, if they've only agreed to allow you to do a certain task and you're not using this data for that task, why would you, uh, be gathering it? Uh, so legally, you're not, you're not entitled to it. **25:49 Chris Romeo:** So can I take these cards that are extensions and put them together with the original EOP? **25:58 Brett Crawley:** Yes. **25:58 Chris Romeo:** Like, do they all fit together in the same game? **26:00 Brett Crawley:** Yeah. Yeah. You can, uh, you can just add, uh, I mean, You can take suits out of the deck and add others in, or you can just increase the deck. Obviously, that's gonna increase the amount of time that you're playing the game, which some people might find positive, others might find it's disruptive. So you have to sort of balance things out. And, but yeah, you can, you can add these into the deck. And you can perhaps choose the ones that are most relevant to this particular project or this particular feature, because you might just be threat modeling a feature of an existing project. How long does one of these games take to run on average? I mean, on average, it's about 3 hours. **26:52 Chris Romeo:** Okay. **26:54 Brett Crawley:** But that's when you did, that's if you're doing a feature As opposed to if you're doing a greenfield project, or if you're doing a project that is perhaps not legacy, but it's been in development quite a while, and you are looking to threat model the historical development as well as what's coming, then it's gonna take longer. I mean, it could take, Uh, 6 hours, 9 hours. Uh, I mean, how long's a piece of string? Um, depends on what detail you want to go in. Uh, it depends on whether your, uh, architecture diagram is high level or so like Duplo, or whether it's low level like Micro Lego. **27:45 Chris Romeo:** Um, so is the goal then that I finish the card game And the threat model is done? **27:55 Brett Crawley:** No, it's a living document. Should you— should be continuing to threat model throughout the life of the application. **28:03 Chris Romeo:** Do we keep coming back to the game? Or do— is the game— does the game just get us rolling into the threat modeling process? Or do we have a follow-on game 3 months in the future, whatever, some at some time interval? **28:16 Brett Crawley:** You can have a follow-on game anytime in the future. To update the diagram or the model with the new threats for the new developments that you're planning, because it should be done before you implement, ideally, so that you can correct the design before you start implementing. Because I use the example of a house in the book, Where if you build a house and you don't put a front wall on it, then it doesn't matter how strong the doors and locks are. You you're never going to be able to secure it. And if you do go back, if you do want to fix that problem, you're going to have to go right back to the foundations because you've still got to stitch the walls together when you. Depends on what materials you're using, obviously. But if you're using bricks. then you're gonna have to stitch the walls together at the corners. You're gonna have to put the foundations in. And it may never be as strong as it would've been had it been correct from the onset with the design. **29:31 Robert Hurlbut:** Yeah. **29:32 Brett Crawley:** Whereas a door has a standard lock fitting that if that particular lock isn't strong enough, you can just take it out and you can put a new one in. So that's an implementation problem as opposed to a design problem. **29:48 Robert Hurlbut:** Yeah. **29:50 Chris Romeo:** So you mentioned from, as a key to success for a threat modeling game, one of the things you already mentioned was diversification of role, which is a Threat Modeling Manifesto principle. So that's something that we've, that we put in the manifesto specifically because we all really believe in that as well. What are some of the other keys to success in having an actionable threat modeling game? **30:15 Brett Crawley:** I mean, you need to, I mean, the people involved need to have a good understanding of the system that they're developing. If they don't, if you have people who are looking at a, a late, a legacy system, and they don't have sufficient knowledge of the system, the architecture diagram is a bit ragged, and they've never threat modeled before, then it's gonna be an uphill struggle. If you've got people who are familiar with their, the product they're developing, They have a good architecture diagram or data flow diagram, and they don't necessarily have to have threat modeled before, but they need at least somebody who can guide them and help them in doing that threat modeling. And I think having, For people who are new to threat modeling, having somebody facilitate the meeting and help give them guidance is of fundamental importance, or at least having some way of them being able to visualize what the problems might be, which is why I came up with the book. I mean, basically, For people who don't have a mentor or a facilitator for the meetings, when I've been facilitating threat modeling sessions, I've had people say, well, what does this card mean? You know, can you give us an example? And so originally, the book was just going— meant to be a collection of examples. So that when they were looking at the card and they were looking at their architecture, they could go, okay, so it could be something like this. Where are we doing something like that in this diagram? And it's just to help them understand how it could manifest itself. It might not be identical, but it's to give them an idea. Um, and that was why I came up with it. It was just, uh, if I kept being asked to give examples, then I was fairly confident that, well, probably other people were as well. Uh, and maybe it would, uh, help them have, uh, um, an example to hand when they need one, because, uh, when you have to come up with one on the spur of the moment, you you don't perhaps want to tell them exactly where the threat is in the diagram or on their architecture, because that's not going to help them learn for when they threat model again. **33:26 Robert Hurlbut:** Yeah. **33:28 Brett Crawley:** So, by giving them a sort of generic example, they can then go, oh, okay, I get it now. And they go and find it in their architecture. Okay. **33:43 Robert Hurlbut:** So one of the things that you made available was a Miro template. And yeah, tell us how that works with the threat model, in threat modeling with the elevation of privileged card game. **33:54 Brett Crawley:** Okay, a bit like we were saying about having the diagram on the table or on a whiteboard. Obviously, a Miro board is, a digital whiteboard, if you like. And for threat modeling with EOP, what I did was I created different areas for each suit because you're supposed to start with the tampering suit, and then you, whoever wins that round, chooses the next suit to go to. So I created different sections for each suit on the whiteboard, the digital whiteboard, and put a list of the cards down the side. Originally, I'd put graphics for each card, but when you are submitting to Miro to get them approved for Mirrorverse, uh, they, they prefer it if, uh, they've got like a style guide and they prefer that you use their elements. And, uh, to, uh, redesign all of the cards individually, uh, would've taken, um, an enormous, uh, amount of effort. And it was, uh, it was lo— losing, um, Yeah. It was losing some of the, uh, the structure to, um, because, well, it was difficult to, uh, to design the cards like that. So what I did was I took the, um, it within the, within the deck, you've got a card which has the list of all of the, um, the threats on all of the cards in that suit. And so I took those and I put those into the board, and then I added Post-its for pink ones for the threats, orange ones for proposed mitigations, and green ones for mitigations that are already existing in the design or in the implementation. Now, when we talk about threat modeling, it's often said we shouldn't think in mitigations, and I agree with that statement. We should be thinking in terms of threats because you're trying to document all of the potential problems and You do that because you can then add the detail to say, okay, we've actually fixed this already, or we've thought of this, so that in a, in the case of a litigation, you can show that you've done your due diligence. So that's why I've also included all of the potential mitigations and the existing mitigations. So You do the threat model, and then you can add the mitigations to the board afterwards, or during even, as potential solutions. And at the end of it, you can, there's a Jira plugin, I think, for Jira app, I think it's called, for Miro. And from there, you can right-click on your orange tickets, and you can create your Jira tickets straight from that, which is quite cool. **37:41 Chris Romeo:** Very cool. **37:43 Brett Crawley:** Yeah. **37:44 Chris Romeo:** So, give me the 60-second plug for the book here, because I feel like we kind of unpacked a lot of this stuff, but we didn't necessarily tie it directly back to the book as far as what people are going to get. So, give us the 60-second book pitch here. **38:00 Brett Crawley:** It's great for new starters who are threat modeling. 'Cause it gives them the instructions on how to play the game, gives them examples for every threat in the card, in the deck. And it also gives them potential mitigations that they can put in place along with references where they can go and read up further about the threat. So it can be used for when you are doing the threat modeling for gathering the requirements, for the different mitigations as well. **38:34 Robert Hurlbut:** Cool. **38:37 Chris Romeo:** Well, thank you for sharing that. Okay, Robert, I think it is time for you to shine. **38:44 Robert Hurlbut:** All right. **38:44 Chris Romeo:** The lightning round. **38:45 Robert Hurlbut:** All right, let's jump in the lightning round. So we have 3 questions. Okay. The first one is, what's your most controversial opinion on application security? And why do you hold this view? **39:01 Brett Crawley:** Okay. The ratio of AppSec to engineers is ludicrously unbalanced. And at the same time, the support for tooling Is to try and balance that out so that the— because if you've got like 1 to 200 ratio, to be able to support those 200 people, you need to have sufficient tooling to be able to put automation in place. Otherwise, you can't cope with the workload. And this is something that you see right across industry. And because of this, it's, I think it's weakening the overall security posture of industry in general. **40:16 Robert Hurlbut:** Yeah. **40:17 Brett Crawley:** And I think there are things that we can do to optimize. And I know that people talk about reachability and they talk about VEX and they talk about SBOM, but it all needs to be linked together. And I think the way to do that is by creating a graph. and enriching the graph with all of the information to be able to, but this is more related to pinpointing the risk so that you can define the priorities. **41:04 Robert Hurlbut:** Okay, thank you. **41:05 Brett Crawley:** Does that answer that one? **41:06 Robert Hurlbut:** Yes, thank you. So next question is, if you could display a single message on a billboard at the RSA or Black Hat conference, what would it say? **41:16 Brett Crawley:** We need to think out of the box to find the best way to optimize. Okay. **41:28 Robert Hurlbut:** All right. And last question, what's your top book recommendation and why do you find it valuable? Any book, it doesn't have to be technical, but any book that you would recommend. **41:38 Brett Crawley:** Okay. I think Fred Kaufman, Conscious Business, was an excellent book for me because I was— I've always been told I'm too direct. And it explains some aspects of communication that and how else, and behavior that I was missing. And it, uh, helped me a lot, um, mature in my, uh, approach. Uh, examples might be, um, that, uh, you sometimes it's It's easier to just, uh, uh, you need to let things go as opposed to, um, because the value in them isn't perhaps as high as you think it is. You need to understand the, uh, the, the bigger picture and see that, okay, for you it's important, but what's the, uh, greater value? Um, so sometimes it's better to just Let it pass. **43:02 Robert Hurlbut:** All right. **43:09 Chris Romeo:** Well, as we come towards the end of our interview here, Brett, I want to give you a chance to share a key takeaway or a call to action for our audience. **43:19 Brett Crawley:** Okay. I think, I know, Yeah, your application threat models existing code, but my call to action would be to threat model early. So, uh, because like I said before, um, I, uh, your, your application also allows you to do the drawing, uh, and, uh, but the AI part will do the analysis of the code as well and generate your threat model. Uh, but the sooner you threat model, uh, the better to try and, um, protect against the design flaws. Um, and, uh, uh, I, I need to look at the latest versions of what you've been doing because, uh, um, I've been, uh, tied up with lots of other stuff recently. Uh, so I'm curious to see how it's evolved 'cause I, I only saw it in its initial stages. **44:23 Chris Romeo:** Yeah. **44:26 Brett Crawley:** So, yeah. **44:26 Chris Romeo:** Very cool. **44:27 Robert Hurlbut:** Yeah. **44:28 Chris Romeo:** Well, Brett, thank you for sharing this knowledge about elevation of privilege and how to programmatize this and make it work with a group of technical folks who are building things. I know I did not have as much knowledge about EOP coming into this as Robert does. So I learned some things about how the game works and how it comes together. So thanks for writing the book. The book is entitled Threat Modeling Gameplay with EOP, and I'm sure you can find it wherever you buy books from. I don't know where people buy books from these days, but I'm sure it's on Amazon. I found it on Amazon, and I'm sure it's in other places as well. **45:09 Brett Crawley:** So, Adam wrote the foreword for it as well. So, so Adam, who invented the game, so Adam Szostak, he also wrote the foreword. Oh, nice. **45:19 Chris Romeo:** Very cool. Very cool. Well, thanks, Brett. I look forward to having another chat with you at some point in the future. **45:25 Brett Crawley:** Cool. Thanks a lot. --- Source: https://appsecpodcast.com/brett-crawley-threat-modeling-gameplay-with-eop/