Elektrine lite

← Feed

@adamshostack@infosec.exchange

2026-09-24 21:50 UTC

This dichotomy of “is it worth it” is a theme of the book, because it’s a theme of threat modeling. How do we improve return on investment? The first step is to know where you’re investing. If your diagram tool requires a lot of clicking, then you have to deal with the lots of clicks. And if you need a Visio license before you can start, then there’s both the cash cost and the administrative overhead of getting Visio. Neither adds materially to the quality of a threat model, and so, with investment being higher, the return must be increased as well. (5/9)

Replies (1)

  • A question I hear all the time is “do we need a diagram if we’re asking an LLM to threat model for us?” The obvious answer is “no.” The LLM will “threat model” (whatever that means) without a diagram, or create one if its token stream stumbles on the idea it needs one. A better question is “how do we get the LLM to do a good job threat modeling?” The answer depends on how you engage with its output. Is a diagram a useful checkpoint? Does it help keep the LLM on task? Does it help the humans review the plan or output? (I know, those things aren’t as fashionable as turning dollars into tokens and burning them.) (6/9)

    Open ##4840616