Chapter 3: Threat Modeling on Paper
3.1 Why we draw the danger before we code
A threat model is a conversation on a picture. You draw how data moves. You say what you are afraid of. You name a fix. You do this before you argue about tools.
Why bother?
- A picture shows the amount leaving the phone and arriving at the server. A code file hides that trip.
- A sentence you can say aloud is a threat. A vague worry is not.
- A fix you can point at is a decision. "We should be more secure" is not a decision.
- Paper is slow in the right way. It stops you from collecting commands you do not understand.
Raju wanted a trick. Guru-ji wanted a sentence. The sentence is harder, and it is the job.
Suppose we are Netflix shipping a release. Before a new "continue watching" control goes out, someone should be able to say what must not leak: a private watch history on a shared television. The model can be four boxes on a whiteboard. It does not start as a scanner log.
Suppose we are at Infosys on a client project. The client will ask, in simple words, "what can go wrong with this payment, and what did you do about it?" A one-page picture answers better than a folder of tool names.
Ravindra Bagale's Tip
Students skip the picture and collect attack recipes. That habit is unsafe and it does not teach judgment. In this course the answer is one plain threat and one plain fix. If you cannot say both without a command, you are not done.