Acknowledgments
First and foremost, I'd like to thank countless engineers at Microsoft and elsewhere who have given me feedback about their experiences threat modeling. I wouldn't have had the opportunity to have so many open and direct conversations without the support of Eric Bidstrup and Steve Lipner, who on my first day at Microsoft told me to go “wallow in the problem for a while.” I don't think either expected “a while” to be quite so long. Nearly eight years later with countless deliverables along the way, this book is my most complete answer to the question they asked me: “How can we get better threat models?”
Ellen Cram Kowalczyk helped me make the book a reality in the Microsoft context, gave great feedback on both details and aspects that were missing, and also provided a lot of the history of threat modeling from the first security pushes through the formation of the SDL, and she was a great manager and mentor. Ellen and Steve Lipner were also invaluable in helping me obtain permission to use Microsoft documents.
The Elevation of Privilege game that opens this book owes much to Jacqueline Beauchere, who saw promise in an ugly prototype called “Threat Spades,” and invested in making it beautiful and widely available.
The SDL Threat Modeling Tool might not exist if Chris Peterson hadn't given me a chance to build a threat modeling tool for the Windows team to use. Ivan Medvedev, Patrick McCuller, Meng Li, and Larry Osterman built the first version of that tool. I'd ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access