Shostack + Friends Blog

 
 
A screen capture of the words ‘Teaching Software Engineers to Threat Model: We Did It, and So Can You‘

RSA 2024

A great threat modeling talk at RSA 2024

 
 
An AI image of A person typing at a computer in a text on screen, but the words are changed on the monitor of a different person's screen

Sutter on Safety

What do we need to assess if memory safe langages are 'sufficient'?

 
 
 
 
 
 
 
 
A Victorian factory with managers spending time on a complex risk management practice.

The NVD Crisis

The NVD is in crisis, and so is patch management. It’s time to modernize.