Skip to content
AppSec PodcastThe Application Security Podcast — home

From the archive

Advice you can use this week

Specific recommendations, grounded in the original conversation. Start with what’s newest or choose one lens.

Choose one filter

Showing the four newest recommendations

practitionerThreat Modeling

Fix one real weakness instead of waiting for a perfect threat model

Said by Brook S.E. Schoenfield ·

“If your inexperienced threat modelers find one thing and they do something about it, you're in better shape than you were yesterday.”

Transcript evidence from Your Opinion on AI Doesn't Matter. Learned Fragility Does.

Episode notes
practitionerThreat Modeling

Bring in an expert when AI threat modeling needs more assurance

Said by Brook S.E. Schoenfield ·

“But wherever you have greater needs, it is not wrong to get an expert in there to finish the job.”

Transcript evidence from Your Opinion on AI Doesn't Matter. Learned Fragility Does.

Episode notes
practitionerThreat Modeling

Check agent output against its intended goals

Said by Brook S.E. Schoenfield ·

“For one thing, even the slightest little twiddle away from goals, set goals, and these things, they drift. There's provable drift.”

Transcript evidence from Your Opinion on AI Doesn't Matter. Learned Fragility Does.

Episode notes
practitionerThreat Modeling

Use AI to trace whether a weakness is reachable in the code

Said by Brook S.E. Schoenfield ·

“I'm going to ask it to go read the repos. and make a good graph and give me a reachability so that whenever I don't have to do the work, whenever I find a weakness, I can ask it from the code, how reachable is this guy?”

Transcript evidence from Your Opinion on AI Doesn't Matter. Learned Fragility Does.

Episode notes