Matt Clapham — A perspective on appsec from the world of medical software
With Matt Clapham
Security teams learn something different when they leave their own conferences and listen to the industries using their products. Matt Clapham, a product security practitioner working with medical software, shares what he observed at the HIMSS healthcare technology conference.
Audio hosted by Buzzsprout. Nothing loads until you press play.
Episode chapters · 12 chapters
- 00:00AppSec through the lens of medical softwareAudio
- 03:03Matt’s path from testing to product securityAudio
- 05:34Balancing leadership and hands-on workAudio
- 06:43What HIMSS brings togetherAudio
- 08:45Healthcare technology and security maturityAudio
- 11:05Cloud adoption in healthcareAudio
- 12:16Compliance and protecting medical informationAudio
- 15:57What security vendors were offeringAudio
- 17:56Asking how products are built securelyAudio
- 20:30Responding to weak security explanationsAudio
- 21:21Lessons beyond individual security productsAudio
- 25:07Leaving the security echo chamberAudio
About this episode
Security teams learn something different when they leave their own conferences and listen to the industries using their products. Matt Clapham, a product security practitioner working with medical software, shares what he observed at the HIMSS healthcare technology conference. He describes the mix of established systems and newer cloud services, the sensitivity of medical information, and the questions vendors should be able to answer about secure development. Chris and Robert explore the gap between compliance claims and practical protection, including why adding security products cannot substitute for sound engineering. Matt also reflects on his path from testing into leadership. His closing challenge is to step outside the security echo chamber and understand how another industry sees risk.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Matt Clapham:
→ Matthew Clapham on LinkedIn
Resources
→ HIMSS
Actionable
From this conversation
- 7:41
Account for healthcare systems in your threat model
Think of the electronic medical records systems or the imaging archive systems, the IT, the operational IT that makes a healthcare delivery organization or a hospital more efficient in providing care.
- 14:53
Protect health information as high-impact data
Health information is such a different level that we need to secure because you can't get it back.
- 26:10
Make technical-debt reduction a routine practice
We need to make tech debt removal and renewal an even more common thing.
Transcript · 28 min conversation
0:01Chris RomeoMatt Clapham is a product security person as a developer, security engineer, advisor, and manager. He began his career as a software tester, which led him down the path of figuring out how to break things. Matt lives in the medical software world and visited the Healthcare Information and Management Systems Society, HIMSS, conference. Matt shares his perspectives on application cybersecurity through the eyes of the healthcare industry. There is much for us to understand by viewing how other segments approach security and privacy. Matt believes in stepping outside the echo chamber and experiencing how other industries see security. And he achieved that by visiting this non-security conference and sharing his experiences with us. And remember, if he visits your booth at an event, you better know how your companies make a secure product or solution. I want to take a moment to introduce you to Security Journey. At Security Journey, we believe security is every developer's job. We work with our customers to help them build long-term sustainable security culture amongst all their developers. Our approach is to provide security education that is conversational, quick, hands-on, and fun. We don't do lectures. Instead, we let the experts talk about what's important. The modules are quick, 10 to 20 minutes in length. We believe in hands-on experiments, builder and breaker style, that allow developers to put what they learned into action. And lastly, fun. Training doesn't have to be boring. We make it engaging and fun for the developers. Visit www.securityjourney.com to sign up for a free trial of the Security Dojo. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. This is Chris Romeo, CEO of Security Journey and one of the co-hosts here on the podcast. And I'm also joined by Robert. Hey Robert.
2:13Robert HurlbutHey Chris. Yeah, this is Robert Hurlbut, Threat Modeling Architect, Software Security Architect, and very enthusiastic about application security.
2:21Chris RomeoSo we're joined today by a guest who has been on the podcast 2 times before, so this is his 3rd visit, and that is Matt Clapham. And we were just talking about where we had actually done these podcast interviews before. And so, Matt and I had done our last interview at Converge Conference in Detroit, Michigan, which is actually coming up here in a couple of months. And so, if you're anywhere near the Detroit metro area in Michigan or anywhere in the state of Michigan, you should definitely come down and be a part of this event. It's very cool. Lots of good stuff happening.
2:55Robert HurlbutYeah.
2:56Chris RomeoMatt, great to have you back on the show again. Thank you for being willing to share your expertise with the industry.
3:02Matt ClaphamHey, happy to be here.
3:03Chris RomeoSo we thought we would refresh your origin story. It seems like it's been about time, right? We have to refresh these things now and again. And so, especially because your origin story, Matt, is going to impact the rest of the things that we talk about here. What's kind of your origin story or how'd you get involved with security?
3:21Matt ClaphamYeah, sure. I started out as a software tester and I'd been interested in software and I, you know, I went to college to learn about technology and computer science. As I left college, I started as a tester and I found that I really enjoyed breaking things. Then as I got better and better at finding flaws and whatnot, I said, well, hey, why do we not look at things like preemptive risk management? Like question why everybody's running as an admin on Windows all the time.
3:51Robert HurlbutRight.
3:52Matt Claphamthat actually made me a better software tester because I could start to break things in new and interesting ways. I experimented more with that, and I also learned more from talking to coworkers and reading distribution lists and whatnot, and expanded my knowledge and became self-made in my security expertise there. Then finally, after a number of years as a software tester, I moved into being in a security position where I was like the security advisor, the security person, at change management for an operational enterprise IT security hosting solution. That got me deeper and deeper and I learned more and more about the operational side of security. Then I looked at policy and the impact that policy has on it. Finally, I took all those different skills and I put them all together as a security advisor for software development teams. I've done that now a couple of times for both the entertainment group at a company I worked at doing games and such, and now also for medical software and that type of thing. And, uh, and as I've, I've worked in that area and built it out more, I've, I've, uh, you know, sort of helped to, uh, define and refine the product security leadership discipline and kind of define, uh, almost like I think what they're calling today a blue teaming kind of a thing for within our, our company and really, um, uh, make that a more holistic thing for how we develop product and software. And then recently I moved into being a manager there, so I kind of took that knowledge of, of working and building and operating those into being responsible for directing the team and taking a small team of advisors and making them more efficient and better suited to what it is that we're doing there to help the teams.
5:34Chris RomeoYou've crossed over into a whole other realm of the universe there, right? And are you still getting a chance to put your hands on technology or are you focused in on directing other folks and managing and getting people, you know, getting everybody going in the right direction?
5:51Matt ClaphamA little bit of both. I still manage to get my hands dirty in the tech sometimes, but yeah, management certainly has its challenges of if I get too deep in the tech, then it might mean one of my employees doesn't. So there's a whole, there's probably a whole podcast right there just on application security advisorship management.
6:11Chris RomeoMaybe we could do that some other time. We'll definitely, I'm adding that to my list of things to do in the future.
6:16Robert HurlbutDefinitely a good thing to cover.
6:18Matt ClaphamYeah, having worked on both sides of that, there's a great idea because there's all sorts of lessons learned about what to do, what not to do. But anyway, one thing I do want to clarify while we're talking here, this is Matt Clapham, the independent person who has 20 years of software experience in a variety of different industries kind of operating independently and not that of my employer at all. I just want to make sure that's clear. This is just some old crotchety software guy who's saying, hey, here's what I noticed.
6:43Chris RomeoThe genesis of this conversation was Matt was telling us about an experience he'd had going to a particular conference that was focused on an industry. And what we realized coming out of that is there's some interesting things for us to consider as security people and as developers when we start to think about this particular space. So, Matt, the conference you went to is what? It was called— it's HIMSS?
7:06Matt ClaphamHIMSS, H-I-M-S-S. It stands for Health Information and Management Systems Society. I went to their 2019 conference. It was in Orlando, Florida, and it was in, I think, early to mid-February. I don't remember exactly. It was a few weeks ago, about a month or so ago.
7:23Chris RomeoOkay. And so when you say Health Information and Management Systems, so this isn't health devices or anything like that. This is the systems that people are using to protect health data when it's at a doctor's office or when it's at a provider or insurance company or something like that, right? Is that, that's what we're talking about?
7:41Matt ClaphamEven broader than that. Think of the electronic medical records systems or the imaging archive systems, the IT, the operational IT that makes a healthcare delivery organization or a hospital more efficient in providing care.
7:56Chris RomeoWhen we think about the way that healthcare organizations work now, I mean, they're using technology everywhere they can. They're digitizing anything that they can. They're really growing. You know, we, this greatly overused term in the world of, is digital transformation. But when I look at healthcare companies and what they're doing now, it truly feels like they're going through a digital transformation because they had stuff that they were doing by hand and on paper that, that it's, they're trying to move everything into technology-based systems.
8:25Matt ClaphamAbsolutely. The digitization is getting deeper and broader and they're looking at even how it might integrate with some of the devices. While it wasn't the focus of the conference, there was something I saw there in that they had example devices that could link to the EMR and take some of that data and automatically send it out to be gathered and collected for later analysis and whatnot.
8:45Chris RomeoSo, you had some thoughts about how this space of health information and management systems fits in, in kind of a general context with the world of IT? Is health information and management systems, are they cutting edge? Are they up to speed with where the rest of the industry is from a security perspective, or where do they fall?
9:07Matt ClaphamI think you see parallels to general IT tech across the board there. There are some, some of the newer companies that are, you know, all brand new modern stuff, and then there's plenty of companies that have been there that have been iterating on their product for decades. And have some of the past problems and future challenges there. So I really think you see that entire spread.
9:31Chris RomeoI mean, in general, are they behind the times from where we would think that these companies are going to be, or does it depend on whether they're newer or have been more established for years?
9:41Matt ClaphamIt's difficult to say for certain, but what I did see is that there is a lot of stuff that's been there for a long time. And maybe it was something that's been incrementally iterated on and was originally an enterprise tech. And now they're trying to expand that and use it across a broader set of solutions.
10:02Chris RomeoSo I see a lot of parallels, or I hear— I'm hearing a lot of parallels between when you think about the world of Internet of Things, IoT tech, at least when IoT first came out a few years ago, or more than a few years ago now, but 10 years ago, There was a lot of companies that were taking some traditional product that they used to make that never was intended to be attached to the internet, and they were adding an IP network stack to it that they bought from somebody else that they had no idea where it came from. And they were putting that device out on the public internet with no security, no ability to be updated, none of the other things that you actually need. So it almost sounds like there's, there's some parallels between where health information and management systems are now and where IoT has been and where it continues to be. Yeah.
10:46Matt ClaphamUm, I would say those are well-founded. Uh, like all software, it's going through its own cycle, and compared to what we see in the enterprise where it's gotten, um, more efficient and whatnot, uh, I would say in general the health information isn't— systems aren't quite there yet. They're, I would say, a couple years behind at least.
11:05Chris RomeoSo from a kind of a cloud perspective, is that— is— are these folks all looking to move stuff to the to the cloud? Is that, is that a trend that you're seeing in the world of health information and management systems?
11:18Matt ClaphamUm, absolutely. There was a lot of, uh, cloud push, uh, software as a service startups and whatnot. Um, in fact, the, your typical big 3 cloud vendors were there. So, um, if I may name a couple of names that I saw there in the vendor section, uh, Microsoft, Amazon, and Google all had booths, and their booths were really, um, not even focused on them per se. They certainly mentioned, you know, why their, their cloud was the best cloud to run some sort of health information system, but they were really also pushing, uh, the success of some of the startups and some of their partners who do all these sorts of neat health information management stuff on top of their clouds.
11:56Chris RomeoSo it's from a kind of from a shared responsibility then perspective of these partners are providing their services through these other cloud platforms. And so, and so they're likely relying on a lot of the underlying security technology and architecture that these cloud providers provide to act as a foundation then, right?
12:16Matt ClaphamDefinitely. Specifically, the Google booth had an entire wedge, an entire section just about their cybersecurity stuff and trying to say how from what they build up until where they hand off into their partner, they do their darndest. And I'm sure all the other cloud providers do this as well to make a nice secure solution. and then they make it easy for additional vendors and partners to build on top of that. And then that leaves them with as tight of a, and as secure of a solution as they can get to up into where they hand off to the actual healthcare delivery organization. And at that point, right, you get into your traditional HIPAA type stuff, right? Where there's a certain amount of expectations that are just expected to be on healthcare delivery org, the hospital, if you will, and they need to then make sure that their vendors provide all that. But they really wanted to make sure it was clear that they were already doing their due diligence ahead of the curve to provide that entire full stack from, you know, running silicon in the data center all the way up into the edge of the software as a service solution their partner put on top.
13:16Chris RomeoAnd so when I think about this as, and I'm thinking about a lot of our audience members are application security-focused people, or they are developers that are learning more about application security, I just wanna stop for a second and kind of summarize for them what I'm thinking of and why this conversation is so important. What this is telling us is when we look at a particular part of the industry, so a particular kind of area of the world of technology, there are different levels of knowledge and different levels of experience and different approaches that are being done. You may, you may, I don't want people to just assume that, hey, because it's healthcare, there's this HIPAA thing that, I have to sign every time I go to the doctor's office and that, so everything's okay. Just like any other industry, health has challenges. It has companies that are operating at different levels. And so, it's important to understand the industry as an AppSec person when you're thinking about how am I gonna help make solutions better, you know, within a given company.
14:20Matt ClaphamThat's a good way to think of it. Yeah. And the security stuff that we've learned in any AppSec scenario absolutely would apply even in the health information space, right? I mean, 'cause you're talking about really sensitive detail, stuff that's probably similar to like managing and storing credentials kind of thing, because you're talking about people's personal health information. That's very specific to the individual and often is something that they want to keep very private. And it's up to that entire stack and that entire ecosystem to do their darndest to make sure that that health information doesn't leak.
14:53Chris RomeoAnd when I think about the term PHI, personal health information, is thrown around, we haven't used it yet, but I managed to work it in here. Quickly. But when I think about it, the thing that always strikes me about PHI and why these conversations we're having right now are so important is I can get a new credit card. I can't get new medical records, right? That's a historical thing that you can't just disable my old medical records. And once that information's out there, it's out there. There's no way to bring it back in. A credit card, I can just have the credit card number canceled and I can get a new card. And then, Sure, it might've caused me a challenge for a little bit of time, but health information is such a different level that we need to secure because you can't get it back.
15:36Matt ClaphamAbsolutely. It's so personal that people expect, and as well they should, and me having, you know, personal health information myself, I expect it as well, that we've gotta keep that protected across the board. You know, if you think of it from an AppSec design perspective, it's really about saying all those really cool things that we need to do, yeah, that.
15:57Chris RomeoSo kind of coming back to your experiences at this particular event, at the HIMSS event, you said you saw some kind of mom-and-pop style smaller companies. There was a section focused on them and their approaches to cybersecurity. What did you see kind of from that perspective with the smaller companies?
16:15Matt ClaphamThere was a whole section on cybersecurity, and what they had were— there were some others that were sprinkled throughout the vendor hall, but they had a whole corner section about cybersecurity, and it was focused on largely on what I might call itch scratching, right? There was a lot of companies there, some of which you might be familiar with from the antivirus space, and they were all there trying to solve some niche problems. So for example, maybe they were trying to figure out a way to provide additional security layers on top of existing email systems so that the email system that they had could be certified or protected for transmitting that PHI that we were talking about.
16:55Chris RomeoYeah, and you said you had a particular example of one in the email space that we're going to be very careful. We're not here to shame anybody. We're not here to point fingers at anybody. But there was something in kind of the secure email space where you asked them an interesting question.
17:12Matt ClaphamAnytime I have a chance to chat up a security vendor, I love asking them how they themselves make a secure product or solution. And so I did that with one of the vendors I talked to, and I got a— not a totally scary response, but just a one that kind of actually would be a good discussion, further discussion point, in that the developer, he couldn't tell me. He was a developer at the company. They were a smaller company providing these additional services, and they had some software components that they had to plug in. But he couldn't tell me how they engineered and developed a secure solution for their customers. So, here is a security tech that can't tell you how they security.
17:56Chris RomeoYeah. And that story is not just limited to small companies too. I mean, security companies in general, and I used to work for a really big company that had lots of products, and the security products were some of the most difficult in the early days. Because people would say, oh no, we have— we're a security product. Don't you know that? They'd be talking to me and I'd be like, so that means you're doing all the things, all the correct things from a secure development lifecycle perspective? Crickets, right? No answer because they didn't even know. But they said, oh, we're a security product. Well, that's not an answer. Like, we're a security product is not an answer to how you do product security correctly. So—
18:37Robert HurlbutYeah, it's not a default.
18:39Chris RomeoYeah.
18:40Matt ClaphamNo.
18:40Robert HurlbutFlip the switch and say now it's secure because it is a security product. No.
18:45Chris RomeoIt almost seems like there's a t-shirt in there somewhere.
18:48Matt ClaphamFun little bit of Matt story time there. Years ago, there was this antivirus client that I noticed used, I think it was FTP, to download the latest signatures. And me, you know, being a budding security guy, I was like, hey, wait, FTP? Maybe there's something in the file that defines the signature that means that, yeah, go ahead and download it via FTP, doesn't matter because there's a signature. No, it was just a text file with the signature details. No hash, no signed values, none of that. Basically, it was an unencrypted data file going over an unencrypted channel. I'm thinking, oh my gosh, this is a security tech, this is an antivirus client. I actually went to the effort of hunting down somebody who was the representative of that company and I said, Don't you think this is a problem? And I got exactly the kind of response that Robert talked about. Well, but it's a security technology. Like, you just, you just don't get it, do you?
19:46Chris RomeoI wish we could say that that problem was solved and we never gonna— we're never— we don't hear that anymore and we're never gonna hear it again. But unfortunately, I don't think I can say that in good faith because I don't really think it's true. I think there's still people that have that, that kind of thought process going through their brain that that, yeah, this is the challenge. And, you know, I mean, one of the things that I'm really passionate about that our audience knows is about educating people. And part of that is educating across the board. And that's one of the advantages of taking an approach where you say, hey, we're going to educate our entire company across the board from people that work the booth from a sales perspective all the way to our most experienced engineers. Everybody has to have that basic understanding of security.
20:30Matt ClaphamYeah.
20:30Chris RomeoAnd when they do, somebody at that booth, like if that, if the person at the booth had said, you know, we take security, product security seriously. We have a secure development lifecycle, which just has some steps about how you could, how, what were the things we do to secure our product. And we're using static analysis. It's new for us, but we're using it. We're doing stuff with it. Like, I feel like that would've caused you to walk away going, hmm, at least they're thinking about it. Like you would, like, how do you think you would've responded to that?
20:56Robert HurlbutYeah.
20:57Chris Romeoto an explanation like that, Matt?
20:58Matt ClaphamI would have thanked him and been thoroughly impressed because my experience is more of what I saw, which is the folks who are there, even if they're in development, they just, they don't have the talking points, they don't have the experience. They might not even know what the options or what the answer there is.
21:16Chris RomeoYeah. So we got work to do as an industry, definitely.
21:19Matt ClaphamYeah, as always.
21:21Chris RomeoSo you also mentioned something about third-party technologies kind of defending themselves. What were you thinking about there?
21:29Matt ClaphamIn that cybersecurity section, there was a lot of defensive tech, and some of it was like that email example, right, where it's, it's, it's adding, uh, it's trying to take an enterprise tech which the, the hospital might already have and apply some sort of additional layers of protection to make it into something that's internet ready, right, to convert it from one deployment and use scenario into another, or to provide one set of use constraints, which was originally some thick client thing that was only on the hospital internal network, and make it available in some sort of shape or fashion for medical clinicians with their personal mobile device being able to somehow access the information and make use of it. And that provides better outcomes, but they're trying to convert existing enterprise into internet or existing enterprise into some sort of cloud scenario.
22:21Chris RomeoSo they're dealing with the challenges of trying to do that and maintain security as well.
22:26Matt ClaphamThey're trying to add security on top where something didn't exist before, right? If anything, they're kind of contributing to that tech debt problem that we talked about in one of our previous podcasts, right, where I was just railing against tech debt because it's something I'm really passionate about. And that's perpetuating the problem in some respects because if If all these other solutions had newer versions that include all of that stuff, which to their credit, sometimes they do. But if we didn't have to try to add stuff on top of the old and focused on just building the new with all this extra stuff, we wouldn't need all these different integrators. We wouldn't need as many of the additional layers of tech on top. We could actually have something that was natively capable of being run and connected to the internet and provide everything that it needs with respect to 2-factor authorization. for patient records access or something like that.
23:18Chris RomeoBuilt-in versus bolt-on, right, is our age-old debate of security. And nobody uses that term. Everybody uses— it's gotten this new fancy shift left kind of idea. And I think I've mentioned this before. I heard a great quote from somebody that I've borrowed and started using myself, and that's, don't shift left, start left. So it's going on a t-shirt somewhere. I just— I didn't say—
23:45Matt ClaphamI love it. I'll buy one when you have them.
23:46Robert HurlbutStart left.
23:47Matt ClaphamYes.
23:47Chris RomeoI'm not the originator. I'm not the one, but I've used it enough times now that I can pretend it was me. But there's somebody else that, uh, that I borrowed it from, and, and he gave permission for me to continue using it. So, um, I want to come back around here and kind of summarize and do some conclusions. I'm going to let— Matt, I'm going to have— I'm going to come to you last for this. Robert, I'm curious as to kind of what, what are some of the conclusions that you're drawn kind of listening to Matt talk about this Health Information and Management Systems Society and all the different things that he experienced in interacting with these companies and providers.
24:18Robert HurlbutWell, you know, it sounds interesting because I have some experience with it directly myself. I've done a lot of work in the healthcare industry. I've been a consultant for a number of years previously where I was helping different healthcare companies and try to manage this, try to figure out some good solutions. What do you think? You know, a lot of times it just came down to some of the things we're talking about, just applying some good security principles to these problems, try to figure out how to manage the data properly, obviously concerns about HIPAA and so forth. But, you know, I think we're on a good track. I think at least we understand some of the problems here, but we have ways to go, as we talked about, and it's good to see that we are talking about it, people are talking about it, but I'd like to see more.
25:07Chris RomeoAnd I guess, Matt, before I let you kind of have the final word here, one of the big takeaways I took from this is we need to step outside the echo chamber. We spend this— and when I say we, I'm referring to all of us as security professionals who spend all of our time at security conferences talking to security people where we're all talking about the same problems and we're commiserating perhaps, but we're not really impacting a lot of change because we're talking to the same people that we've always talked about for these problems. And so, that's the thing that I've taken away from, Matt, from your experience here is that by stepping outside the echo chamber and going to a conference that was not security-focused, even though it had security companies that were providing solutions there, that wasn't the primary focus of it, that I think that's really a powerful thing. And you got to interact with a whole other group of people who aren't going to come to DEF CON, Black Hat, AppSec USA, all those type of things. So that's my takeaway. Matt, what do you want to leave our listeners with as far as a summary and conclusions?
26:10Matt ClaphamI love your echo chamber concept because, yeah, getting out of your comfort zone and seeing how a different industry experiences the exact same problems that you might be experiencing in the enterprise space or any other software world was eye-opening for me. Not that I hadn't seen that stuff before, but it was like, You know, to have that comparison there. And, you know, I mentioned earlier, I'm big on tech debt. So I think we need to make tech debt removal and renewal an even more common thing. And we're getting all of these foundational pieces that should make that a non-issue, but we still find ourselves as a technology industry just kind of letting us coast by with the same stuff for a long period of time. That has to end. We have to get into the new world where we can more iteratively keep going through those pieces of software that we built to keep them fresh, to keep the vulnerabilities down, to improve and enhance whatever we need to do. We can't just take something, toss it over the wall, and drop it on somebody else's machine and leave it there for 20 years. It just, it doesn't work in the modern world.
27:18Chris RomeoAll right, Matt, thank you for being here for a 3rd visit on the Application Security Podcast. And we look forward to your 4th visit. I don't think we're probably going to talk about becoming a manager in the world of AppSec is the working title I'm going from, but thanks for being here today and look forward to that next conversation as well.
27:35Matt ClaphamAwesome. Thanks for having me.
27:38Chris RomeoThanks for listening to the Application Security Podcast. Our intro music is 8-Bit Kung Fu by Born and TJ, and our outro music is Southern Delight by Stefan Kartenberg. You'll find the show on Twitter @AppSecPodcast. AppSec Podcast, or on the web at www.securityjourney.com/application-security-podcast. You can also find Chris on Twitter @edgeroute and Robert @roberthurlbuck. Remember, security is a journey, not a destination.
5,176 words · transcript by assemblyai
More on Threat Modeling
View all episodes →- March 23, 2020 · 28 minKim Wuyts — Privacy Threat Modeling
- December 10, 2024 · 45 minBrett Crawley -- Threat Modeling Gameplay with EoP
- June 29, 2023 · 42 minKim Wuyts -- The Future of Privacy Threat Modeling