Why Nostr? What is Njump?
2024-09-03 15:20:22
in reply to

Adam Shostack :donor: :rebelverified: on Nostr: Appsec Crowdstrike released what they call an RCA. Before they did, I said I’d ...

Appsec

Crowdstrike released what they call an RCA. Before they did, I said I’d judge it based on clarity, depth and scope, and it fails on all three. There’s no “five whys”, there’s no discussion of management choices or funding. Rushing root cause work gets you shallow analyses and you get shallow improvement.
Narrowing the Software Supply Chain Attack Vectors: The SSDF Is Wonderful but not Enough by Laurie Williams (from March, but I’d missed it).
Simon Tatham lists Code review antipatterns, none of which specifically mention security, but code reviews are often associated with security, and the “Late breaking design review” pattern certainly ties into threat modeling either done or communicated badly.
Author Public Key
npub1s7cghayd6cuu7tnvxw6xlxq5ddz0grs956tzwsqj59v5vvucgd7sdgrcqn