
Appsec Roundup - Nov 2024
A virtual feast of appsec!

A virtual feast of appsec!

Exciting news from the SEC, lots of AI, and lots of threat modeling.

The new IEEE S+P is all about usable security.

I'm doing a reddit AMA in /r/privacy

The Supreme Court has ruled in the van Buren case, and there's a good summary on the Eff's blog.

So there's some good news and some bad news in this story: 'Too Bad, Zuck: Just 4% of U.S. iPhone Users Let Apps Track Them After iOS Update'.

Exploring supply chain threat modeling with Alexa
I'm featured in (local NPR Affiliate) KUOW's Primed: Season 3, Episode 8.
A few tidbits in recent news.

Let's talk CAKED, a threat model for managed attribution.
My talks from AppSecCali 2019
[no description provided]

An extended version of Elevation of Privilege, now with Privacy.

[no description provided]

[no description provided]

[no description provided]
[no description provided]

[no description provided]
[no description provided]
[no description provided]
[no description provided]

[no description provided]