Ancestors

Toot

Written by Levi Broderick on 2024-10-15 at 00:57

Over the past few months, I've been trying to lead an effort within the .NET team to make threat models and other security design documents publicly available to our consumers. This is a non-trivial amount of work since it involves getting the data into a format appropriate for external consumption, re-reviewing the docs in the context of other .NET ecosystem efforts, and getting publication signoff from multiple teams. 1/

=> More informations about this toot | More toots from GrabYourPitchforks@infosec.exchange

Descendants

Written by Levi Broderick on 2024-10-15 at 00:59

But I am happy to say we're making some significant progress here! Just a few minutes ago I submitted a PR with threat models / security designs for some commonly-used building blocks within the .NET ecosystem:

2/

=> More informations about this toot | More toots from GrabYourPitchforks@infosec.exchange

Written by Levi Broderick on 2024-10-15 at 01:01

Publishing these documents helps our consumers better use our components in a reliable and secure manner. It gives people confidence in the safety of our code base and our review process. And it gives a minor glimpse into .NET security team operations, including the pitfalls we try to be mindful of during API design processes.

Enjoy!

3/FIN

=> More informations about this toot | More toots from GrabYourPitchforks@infosec.exchange

Written by πŸ’‘πš‚π—†π–Ίπ—‹π—π—†π–Ίπ—‡ π™°π—‰π—‰π—ŒπŸ“± on 2024-10-15 at 00:59

@GrabYourPitchforks

@bot boost this

=> More informations about this toot | More toots from SmartmanApps@dotnet.social

Proxy Information
Original URL
gemini://mastogem.picasoft.net/thread/113308720612067855
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
260.146296 milliseconds
Gemini-to-HTML Time
1.391281 milliseconds

This content has been proxied by September (3851b).