
Adam Shostack -- Think like an Attacker or Accountant?
Om avsnittet
What does “think like an attacker” actually ask a developer to do? Adam Shostack joins Chris and Robert to challenge a familiar instruction that can leave capable engineers feeling excluded from security work. He describes an experience that changed his approach and explains why developers’ knowledge of their own systems should be the starting point for threat modeling. The conversation examines the difference between persuading people that security matters and giving them a concrete way to practice it. Chris and Robert add examples from development teams, while Adam extends the discussion to infrastructure and operations. They close with practical ways to ask better questions, build a shared understanding of a system, and make security thinking accessible without demanding a new identity.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Adam Shostack:
→ Adam Shostack
Mentioned in this episode:
→ Start With Why
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Rethinking “think like an attacker” with Adam Shostack
01:25 Adam’s security origin story
03:34 Why the hacker mindset instruction can fail
07:15 When security conversations make developers feel excluded
08:02 Rethinking how security is taught
11:22 Giving teams a practical way to participate
14:16 Treating developers as experts in their own systems
17:08 Explaining why security matters
20:37 A developer’s perspective on security thinking
22:26 Applying the approach beyond software teams
25:49 Practical actions for more inclusive security work
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.