SlideShare a Scribd company logo
The PDF is in ‘notes’ view because there are lots of URLS in the 2nd half.
1
2
Kim Yong Chol, former NK military intel chief, FBI has publicly attributed break in to
NK https://www.fbi.gov/news/pressrel/press-releases/update-on-sony-investigation
3
https://www.youtube.com/watch?v=EmBneh0oy7E
5
6
7
8
* Now if you include IoT which fails to compile with modern defenses.
9
New attackers are covered in Tampering, EoP and Conflict
10
Explicitly not “the way to threat model is”
11
12
13
14
15
https://twitter.com/evacide/status/878695077085708288
17
18
19
20
21
22
Discussion and dialog, Allspaw’s Kitchen Soap blog
23
24
25
26
28
29
30
https://techcrunch.com/2016/10/04/mastercard-launches-its-selfie-pay-biometric-
authentication-app-in-europe/
https://darkwebnews.com/dark-web/selfie-darknet-sale/
https://arxiv.org/pdf/1803.04683.pdf
31
https://www.theverge.com/tldr/2018/4/17/17247334/ai-fake-news-video-barack-
obama-jordan-peele-buzzfeed
32
33
https://www.theverge.com/tldr/2018/4/17/17247334/ai-fake-news-video-barack-
obama-jordan-peele-buzzfeed
34
https://www.theregister.co.uk/2018/06/15/taplock_broken_screwdriver/
35
http://www.iflscience.com/plants-and-animals/migrating-stork-racks-up-2700-on-
researchers-cell-phone-bill/
36
https://www.defense.gov/News/Article/Article/1594486/new-policy-prohibits-gps-
tracking-in-deployed-settings/
https://www.theguardian.com/world/2018/jan/28/fitness-tracking-app-gives-away-
location-of-secret-us-army-bases
https://www.bellingcat.com/resources/articles/2018/07/08/strava-polar-revealing-
homes-soldiers-spies/
37
38
https://www.eetimes.com/document.asp?doc_id=1333308
39
Stress how usability again becomes a security property, and how hard configuration
can be to understand.
https://www.nytimes.com/2018/06/23/technology/smart-home-devices-domestic-
abuse.html
https://threatpost.com/rowhammer-variant-rampage-targets-android-devices-all-
over-again/133198/
40
SSH auth forwarding still rocks by default J
41
42
Paul Pols
43
More complex code, more bugs goes back to the intro to the 1st ed of firewalls &
Internet security by Cheswick & Bellovin
44
Conflict
Countries & “Non-state actors” with geopolitical goals
Between groups
Between people
”non-state actors” like ISIS
45
Note the technical choices: create an interstitial; review (rather than delay) reviews;
explain what a good review is
https://www.yelp.com/biz/the-red-hen-lexington-3
https://www.nbcwashington.com/news/local/Wrong-Red-Hen-DC-Restaurant-
Getting-Death-Threats-After-Spot-With-Same-Name-Booted-Sarah-Huckabee-
Sanders-486500061.html
46
48
https://www.levendowski.net/conflict-modeling
http://achangeiscoming.net/2017/04/15/transforming-tech-diversity-friendly-
software/
50
Here’s a more structured example. What are some of the ways an harasser could
attack somebody?
Original:
https://docs.google.com/presentation/d/1JB3bTbJvjEypKlPu1JKV20Oz9YlF5zRCl3vLIP
dDTrA/edit#slide=id.g2073602466_0_0
52
https://splinternews.com/how-nextdoor-reduced-racist-posts-by-75-1793861389
https://blog.nextdoor.com/2016/08/24/reducing-racial-profiling-on-nextdoor/
53
54
56
57
58
59

More Related Content

Similar to Adam Shostack shared attacks, impacts, and other Updates on threat modeling in 2018

Internet of things
Internet of thingsInternet of things
Internet of things
JadaSolomon
 
ETSI Hell's Kitchen Debate, Nice 2009
ETSI Hell's Kitchen Debate, Nice 2009ETSI Hell's Kitchen Debate, Nice 2009
ETSI Hell's Kitchen Debate, Nice 2009
Paul Downey
 
Why do we need more nerds?
Why do we need more nerds?Why do we need more nerds?
Why do we need more nerds?
Dominik Helleberg
 
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
Mike Lee
 
Security news vol. 2 - 20141016 - Risk & Technology Wrocław Group
Security news vol. 2 - 20141016 - Risk & Technology Wrocław GroupSecurity news vol. 2 - 20141016 - Risk & Technology Wrocław Group
Security news vol. 2 - 20141016 - Risk & Technology Wrocław Group
Logicaltrust pl
 
IOT LA NUEVA ERA TECNOLÓGICA
IOT LA NUEVA ERA TECNOLÓGICA IOT LA NUEVA ERA TECNOLÓGICA
IOT LA NUEVA ERA TECNOLÓGICA
Maria Jose Uscategui Romero
 
Security news 20151119
Security news 20151119Security news 20151119
Security news 20151119
Logicaltrust pl
 
Secuirty News Bytes-Bangalore may 2014
Secuirty News Bytes-Bangalore may 2014 Secuirty News Bytes-Bangalore may 2014
Secuirty News Bytes-Bangalore may 2014
n|u - The Open Security Community
 
Latest News Articles from Techworld
Latest News Articles from TechworldLatest News Articles from Techworld
Latest News Articles from Techworld
coherentcontain85
 
Frederic Lavigne - IBM Bluemix: The Cloud APP revolution
Frederic Lavigne - IBM Bluemix: The Cloud APP revolutionFrederic Lavigne - IBM Bluemix: The Cloud APP revolution
Frederic Lavigne - IBM Bluemix: The Cloud APP revolution
Codemotion
 
11 social media marketing trends for 2011
11 social media marketing trends for 201111 social media marketing trends for 2011
11 social media marketing trends for 2011
Tiphereth Gloria
 
2012 02-15 - future of social media - university of calgary, cont ed
2012 02-15 - future of social media - university of calgary, cont ed2012 02-15 - future of social media - university of calgary, cont ed
2012 02-15 - future of social media - university of calgary, cont ed
Anduro Marketing
 
The startup of you : Build your digital identity
The startup of you : Build your digital identityThe startup of you : Build your digital identity
The startup of you : Build your digital identity
Francisco Jose Cordoba Otalora
 
09 09 2014
09 09 201409 09 2014
09 09 2014
Steph Cliche
 
Conceitos Interativos A06
Conceitos Interativos A06Conceitos Interativos A06
Conceitos Interativos A06
Plínio Okamoto
 

Similar to Adam Shostack shared attacks, impacts, and other Updates on threat modeling in 2018 (15)

Internet of things
Internet of thingsInternet of things
Internet of things
 
ETSI Hell's Kitchen Debate, Nice 2009
ETSI Hell's Kitchen Debate, Nice 2009ETSI Hell's Kitchen Debate, Nice 2009
ETSI Hell's Kitchen Debate, Nice 2009
 
Why do we need more nerds?
Why do we need more nerds?Why do we need more nerds?
Why do we need more nerds?
 
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
Presentation for AARP DSO Online Marketing Summit 2013 (Also for What's Next ...
 
Security news vol. 2 - 20141016 - Risk & Technology Wrocław Group
Security news vol. 2 - 20141016 - Risk & Technology Wrocław GroupSecurity news vol. 2 - 20141016 - Risk & Technology Wrocław Group
Security news vol. 2 - 20141016 - Risk & Technology Wrocław Group
 
IOT LA NUEVA ERA TECNOLÓGICA
IOT LA NUEVA ERA TECNOLÓGICA IOT LA NUEVA ERA TECNOLÓGICA
IOT LA NUEVA ERA TECNOLÓGICA
 
Security news 20151119
Security news 20151119Security news 20151119
Security news 20151119
 
Secuirty News Bytes-Bangalore may 2014
Secuirty News Bytes-Bangalore may 2014 Secuirty News Bytes-Bangalore may 2014
Secuirty News Bytes-Bangalore may 2014
 
Latest News Articles from Techworld
Latest News Articles from TechworldLatest News Articles from Techworld
Latest News Articles from Techworld
 
Frederic Lavigne - IBM Bluemix: The Cloud APP revolution
Frederic Lavigne - IBM Bluemix: The Cloud APP revolutionFrederic Lavigne - IBM Bluemix: The Cloud APP revolution
Frederic Lavigne - IBM Bluemix: The Cloud APP revolution
 
11 social media marketing trends for 2011
11 social media marketing trends for 201111 social media marketing trends for 2011
11 social media marketing trends for 2011
 
2012 02-15 - future of social media - university of calgary, cont ed
2012 02-15 - future of social media - university of calgary, cont ed2012 02-15 - future of social media - university of calgary, cont ed
2012 02-15 - future of social media - university of calgary, cont ed
 
The startup of you : Build your digital identity
The startup of you : Build your digital identityThe startup of you : Build your digital identity
The startup of you : Build your digital identity
 
09 09 2014
09 09 201409 09 2014
09 09 2014
 
Conceitos Interativos A06
Conceitos Interativos A06Conceitos Interativos A06
Conceitos Interativos A06
 

Recently uploaded

Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
Zilliz
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
Pablo Gómez Abajo
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
Safe Software
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
DanBrown980551
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
akankshawande
 
Must Know Postgres Extension for DBA and Developer during Migration
Must Know Postgres Extension for DBA and Developer during MigrationMust Know Postgres Extension for DBA and Developer during Migration
Must Know Postgres Extension for DBA and Developer during Migration
Mydbops
 
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
"Scaling RAG Applications to serve millions of users",  Kevin Goedecke"Scaling RAG Applications to serve millions of users",  Kevin Goedecke
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
Fwdays
 
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
saastr
 
Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)
Jakub Marek
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
Miro Wengner
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
Javier Junquera
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Neo4j
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
christinelarrosa
 
High performance Serverless Java on AWS- GoTo Amsterdam 2024
High performance Serverless Java on AWS- GoTo Amsterdam 2024High performance Serverless Java on AWS- GoTo Amsterdam 2024
High performance Serverless Java on AWS- GoTo Amsterdam 2024
Vadym Kazulkin
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
Hiroshi SHIBATA
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
Jason Packer
 
Session 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdfSession 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdf
UiPathCommunity
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
ScyllaDB
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 

Recently uploaded (20)

Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024Northern Engraving | Nameplate Manufacturing Process - 2024
Northern Engraving | Nameplate Manufacturing Process - 2024
 
Fueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte WebinarFueling AI with Great Data with Airbyte Webinar
Fueling AI with Great Data with Airbyte Webinar
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
 
Essentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation ParametersEssentials of Automations: Exploring Attributes & Automation Parameters
Essentials of Automations: Exploring Attributes & Automation Parameters
 
5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides5th LF Energy Power Grid Model Meet-up Slides
5th LF Energy Power Grid Model Meet-up Slides
 
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development ProvidersYour One-Stop Shop for Python Success: Top 10 US Python Development Providers
Your One-Stop Shop for Python Success: Top 10 US Python Development Providers
 
Must Know Postgres Extension for DBA and Developer during Migration
Must Know Postgres Extension for DBA and Developer during MigrationMust Know Postgres Extension for DBA and Developer during Migration
Must Know Postgres Extension for DBA and Developer during Migration
 
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
"Scaling RAG Applications to serve millions of users",  Kevin Goedecke"Scaling RAG Applications to serve millions of users",  Kevin Goedecke
"Scaling RAG Applications to serve millions of users", Kevin Goedecke
 
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
9 CEO's who hit $100m ARR Share Their Top Growth Tactics Nathan Latka, Founde...
 
Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)
 
JavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green MasterplanJavaLand 2024: Application Development Green Masterplan
JavaLand 2024: Application Development Green Masterplan
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
 
Christine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptxChristine's Supplier Sourcing Presentaion.pptx
Christine's Supplier Sourcing Presentaion.pptx
 
High performance Serverless Java on AWS- GoTo Amsterdam 2024
High performance Serverless Java on AWS- GoTo Amsterdam 2024High performance Serverless Java on AWS- GoTo Amsterdam 2024
High performance Serverless Java on AWS- GoTo Amsterdam 2024
 
Introduction of Cybersecurity with OSS at Code Europe 2024
Introduction of Cybersecurity with OSS  at Code Europe 2024Introduction of Cybersecurity with OSS  at Code Europe 2024
Introduction of Cybersecurity with OSS at Code Europe 2024
 
Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024Columbus Data & Analytics Wednesdays - June 2024
Columbus Data & Analytics Wednesdays - June 2024
 
Session 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdfSession 1 - Intro to Robotic Process Automation.pdf
Session 1 - Intro to Robotic Process Automation.pdf
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 

Adam Shostack shared attacks, impacts, and other Updates on threat modeling in 2018