
Threat Modeling using the Force with Adam Shostack - OWASP Podcast e001
The OWASP Podcast Series
00:00
Is the White Board Real?
i used to be very loose when i diagrammed in a meeting. Riht white ward, everything was a square, everything was lines. And i'd take a picture with my phone at the end, and then i'd turn it into something real. I teach people a formalism for diagraming that i call d f d three,. We use rounded rectangles for code under your control. We use sharp rectangles forcode not under your control or for people. You pay a cost. People have to understand what the shapes mean. They have to agree on what the shapes means. This is where i'm going to push back on the whole perfection is when perfection is gatekeepi When
Transcript
Play full episode