Chapter 3: Threat Modeling on Paper
3.5 One worked threat and three fixes
The threat, in one sentence: an attacker changes the amount from 5000 to 1 before the payment API stores it.
That is the whole worked threat. It is tampering from STRIDE. It sits on the data flow between the phone and the API, or inside a body the API trusts too much. This page will not tell you how to catch, edit, or resend that request. Learning the name is the point.
This is for learning only, and only inside a system you are allowed to test.
Three fixes, named and plain. They match the outline of this volume. They are design rules, not a lab script.
- Enforce TLS in transit. The request should travel only over HTTPS, so the path is encrypted. A team enforces this on the server. They do not shrug if a plain request arrives. This page does not show how to listen on a network.
- Sign payloads with HMAC. A trusted sender attaches a signature. The payment API checks it. If the amount changed after the signature was made, the check fails and the API refuses the body. This page does not show how to compute, copy, or break that signature.
- Re-check the amount on the server. The server already knows the order is 5000. It compares the incoming number with that order. If the body says 1, the server keeps 5000 or it rejects the call. The phone is not the source of truth.
Why all three, in simple words:
- TLS protects the trip.
- HMAC makes a quiet edit visible to the API.
- The server-side re-check still works even if a client is buggy or dishonest, because the order total lives with the API.
If you only do the third fix, you have already stopped this particular tale: the API will not store 1 for a 5000 order. The first two fixes still matter for secrets on the wire and for other fields you might trust by mistake. Say that. Do not drop the re-check because a signature "sounds stronger."
Steps to talk about this threat without sliding into an attack:
- Show the four-part picture.
- Point at the arrow.
- Say the one-sentence threat: the amount 5000 becomes 1.
- Say the rupee gap in the teaching example: 4999, if the server believed the phone.
- Name the three fixes: TLS, HMAC, server re-check.
- Stop. Do not demonstrate the change on a live or borrowed system.
Ravindra Bagale's Tip
The exciting wrong answer in class is a story about intercepting traffic. That answer is not allowed here, and it is not the skill. The skill is: trusted amount lives on the server. Repeat that until it sounds boring. Boring is the fix working.