Shostack + Friends Blog
Recent Blog Posts, Page 26
A Threat Modeling Manifesto
A diverse set of experts and advocates for threat modeling are releasing a threat modeling manifesto, modeled after the agile manifesto and focused on values and principles.
On Legitimacy (After the Election)
Additional thoughts on the subject.
Friday Star Wars: Lego Holiday Celebration
A little something to make you smile today:
Maps and Visualization
A colorful map shares a powerful message.

On Legitimacy
The legitimacy of the outcomes of our election are already under aggressive and sustained attack.
Notice the Outrage Machines
With three days to the US election, the outrage machines are running on all cylinders. It'll be easier to stay happy if you remember to notice them.
On Monopolies
In a simpler age, Matt Stoller famously lost his job for critiquing Google.

Training: Threat Modeling for Security Champions
Expanding on our distributed class structure.
A PCI Threat Model
Compliance isn't Security, oh and something I wrote.
Mentions
A few recent mentions

Starting Threat Modeling: Focused Retrospectives are Key
Don't skip this important step.

Threat Modeling, Insiders and Incentives
Inspired by the recent story of Tesla's insider, I'd like to discuss insider threat as it fits into threat modeling.
Phil Venables Blogging
It's not LinkedIn posts or Tweets, but a real live blog.
The Uber CSO indictment
Thoughts on Mark Rasch's essay, Conceal and Fail to Report - The Uber CSO Indictment