
Adam Shostack -- Fast, cheap and good threat models
The Application Security Podcast
00:00
Fast, Cheap and Good Threat Modeling
When i say fast, i'm thinking about a methodology. Like just ask, what can possibly go wrong? Or just ask, how would you hack this? That might be a 60 second conversation. I hate the dropping down to no threat modelling. And that's why i think fast and cheap can also be good. Grid isar likes to ast as aur tarndok likes to ask, threatmodel every story. It an hour to threatmodel every stories. Might feel too heavy weight to some people. So instead of dropping down to one minute, they drop down to zero seconds.
Transcript
Play full episode