4 ms·
That’s unfortunate. When I was on windows phone in the late 2000s, every new feature got a round of threat modeling. Each team (pm/test/dev) were responsible fo
by physicles 3y ago
That’s unfortunate. When I was on windows phone in the late 2000s, every new feature got a round of threat modeling. Each team (pm/test/dev) were responsible for building the threat model themselves, but the threat model was reviewed by another security team.
What the hell happened? Is annual security training still a thing?
- 1attice 3y agoThere's still annual security training, but it's tapas-model. So basically you have to take N courses by <date>. If you're interested in lockpicking, but your job is in the cloud, you could still meet the requirement by watching a video about lockpicking. (If such a video was offered.) No one follows up, except to ensure that you took enough courses by the given date. Note: My time at this company overlapped heavily with Covid WFH, so things may have been looser/weirder than normal. And regarding threat modelling: I literally have no idea; I was just an IC. All I know is, there were several occasions where delivery cadence was selected for, and in my opinion, on at least some of those occasions, security should have been selected for instead. One charitable explanation is that they'd just threat-modelled my part of the product and decided there weren't any threats there, so there was no need to ease up on the gas pedal. But some threats are subtle, and where you least expect them.
- Arnavion 3y ago>Each team (pm/test/dev) were responsible for building the threat model themselves, but the threat model was reviewed by another security team. That still happens. >Is annual security training still a thing? Yes it is.