Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have long been interested in what a professional-grade threat model from a large FAANG/SV organization is. Is this a representative model?

Microsoft came up with DREAD and STRIDE and they suggest there threat models are more elaborate.

Would love to see more representative examples!



This feels more like a marketing document to me than a workaday threat model. It's fairly handwavey, and the goal seems to be to convince rather than to do a hardnosed analysis.

Not that it's not useful—I found it convincing—but I doubt this is what a real threat model looks like. Not that I actually know. I'd be interested in seeing a real one too.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: