DevSec Station
DevSec Station is a security focused podcast for software developers who want to create amazing applications. Hosted by Tanya Janca, also known as SheHacksPurple, these short lessons will help you level up.
DevSec Station
Threat Modeling for Developers (How To)
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Threat modeling has a reputation for being complicated, full of diagrams, and requiring long meetings. In reality, most developers already do it, they just don't realize it. The difference is that doing it intentionally helps you catch security problems before they become security incidents.
This episode is sponsored by Maze.
In this episode of DevSec Station, Tanya Janca breaks threat modeling down into a simple five-step process that any developer can use while designing a feature. You'll learn how to identify what you're protecting, where trust boundaries exist, and how to ask a few simple questions that uncover security issues early; before they're expensive to fix.
You'll learn:
- why threat modeling is can be simpler than most people think
- how to threat model a feature in about fifteen minutes
- how to identify assets, entry points, and trust boundaries
- three practical misuse questions that reveal common insecure design mistakes
- how to turn identified threats into concrete security controls
Tanya walks through a practical, developer-friendly approach to threat modeling that doesn't require diagrams, special tools, or security approval. Instead, she demonstrates how asking a handful of structured questions during design helps developers build more secure software from the very beginning.
If you do just one thing after listening to this episode:
Threat model one feature you're currently building.
Follow these five simple steps:
- describe the feature in one sentence
- identify what you're protecting
- identify the entry points and trust boundaries
- ask what could go wrong if the feature is misused or fails unexpectedly
- identify at least one security control that should be added or verified
Write your notes somewhere your team can see them; a ticket, pull request, markdown file, or design document. You don't need a formal process. You just need to think about security before the code exists.
DevSec Station is a podcast by Tanya Janca (SheHacksPurple), focused on short, practical lessons that help software developers build more secure software.
Follow Tanya:
- https://shehackspurple.ca
- https://youtube.com/@shehackspurple
- https://newsletter.shehackspurple.ca
- https://linkedin.com/in/tanya-janca
- https://tanyajanca.com
This episode is sponsored by Maze.
One of the biggest problems in security right now is that every vulnerability scanner says everything is critical, and honestly, no one has time for that.
Maze uses AI agents to investigate vulnerabilities in context, so you can focus on the issues that are actually exploitable in your environment, not just theoretically scary.
Their AI agents also generate and prioritize fixes that knock out multiple vulnerabilities at once, which is honestly the kind of scaling that security teams need right now.
Learn more about Maze https://mazehq.com/devsec