Skip to content

Security

  • Threat modeling asks four questions: what are we building, what can go wrong, what are we going to do about it, and did we do a good job.
  • STRIDE per element of a data-flow diagram (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege) makes “what can go wrong” systematic.
  • Trust boundaries are where checks belong: every boundary in the system’s interface matrix, including retrieved text reaching a tool call, gets a named control and a test.
  • Supply chain is part of the system: an SBOM per artifact and provenance for builds tell you what you shipped when the next CVE lands.

Read the OWASP cheat sheet, then Shostack part I. Draw your system’s data-flow diagram before reading further. In the course, craft.17 writes docs/THREAT_MODEL.md with every trust boundary of your system, craft.18 adds SBOMs and build provenance, and craft.19 reviews secrets handling and authorization paths.


Security is a property of the whole system, so it is reviewed against the whole system’s diagram. The threat model turns the architecture into a list of threats, each tied to a control and a test, and the supply-chain records make the shipped artifacts accountable.

Key ideas:

  • DFD: processes, data stores, external entities, data flows, trust boundaries; built from your C4 container view.
  • STRIDE per element with a control and an owner per threat, including the RAG-to-tools path (craft.17).

2. Supply chain, secrets, and authorization

Section titled “2. Supply chain, secrets, and authorization”

Key ideas:

  • SBOM and provenance for every image and binary (craft.18).
  • Secrets and authz review (craft.19): where keys live (TL_API_KEY, HMAC peppers), how scopes and tenants are checked in the gateway (gw.02).
ModuleTopicKindPass
craft.17Threat model (STRIDE on your DFD)practice11
craft.18SBOM and supply chainpractice11
craft.19Secrets and authz reviewpractice11
#ModuleChapterKindPass
1craft.17Threat model (STRIDE on your DFD)practice11
2craft.18SBOM and supply chainpractice11
3craft.19Secrets and authorization reviewpractice11
TrackConnection
Diagramming & the C4 Modelthe diagrams the threat model starts from
Authorization & Access ControlAPI keys, scopes, and tenants
Usage Policyabuse cases and their enforcement
Professional Responsibilitydisclosure when a threat becomes a vulnerability