
25 Years in AppSec: Looking Back
Time flies and things change... A look back on the growth of this industry.
Time flies and things change... A look back on the growth of this industry.
The pandemic gives us a chance to evaluate AI tools...you'll be shocked to discover how they did.
Many people want their threat modeling work to produce risk numbers, and in this post you'll learn why that's a mistake.
Earlier this week, NIST released a Recommended Minimum Standard for Vendor or Developer Verification of Code. I want to talk about the technical standard overall, the threat modeling component, and the what the standard means now and in the future.
It's the latest in the World's Shortest Threat Modeling videos!
The latest in the World's Shortest Threat Modeling Videos.
The US Government's lead cybersecurity agencies have released an interesting report, and I wanted to use this for a Threat Model Thursday, where we take a respectful look at threat modeling work products to see what we can learn.
At Blackhat USA, I'll be teaching Applied Threat Modeling.
The second video in my 60 second series!
Thoughts on the new federal holiday, Juneteenth
I'm exploring the concept of very fast threat modeling videos.
You know what's not in my threat model? A meteor hitting a volcano... And that's ok!
Arbitrarily powerful software -- applications, operating systems -- is a problem, as is preventing it from running on enterprise systems.
A new article by Steve Bellovin and myself at Lawfare.
The Supreme Court has ruled in the van Buren case, and there's a good summary on the Eff's blog.