Skip to content

Add initial attempt at threat model.#82

Open
msporny wants to merge 5 commits into
mainfrom
threat-model
Open

Add initial attempt at threat model.#82
msporny wants to merge 5 commits into
mainfrom
threat-model

Conversation

@msporny

@msporny msporny commented May 31, 2026

Copy link
Copy Markdown
Member

This PR adds a minimal, experimental threat model to the recognized entities specification. It is meant as a baseline to build on top of and a conversation starter rather than a complete threat model. There are many more threats that the group suggested that will be incorporated after the general direction of this PR has consensus.

Comment thread threat-model/threats/t1-unauthorized-issuer-spoofing.js Outdated
Comment thread threat-model/threats/t2-recognized-entity-credential-tampering.js Outdated
Comment thread threat-model/threats/t3-list-fetch-denial-of-service.js Outdated
Comment thread threat-model/threats/t4-privacy-leakage-via-list-fetch.js Outdated
Comment thread threat-model/diagrams/dfd.mermaid Outdated
Comment thread threat-model/threats/t3-list-fetch-denial-of-service.js Outdated
Comment thread threat-model/threats/t4-privacy-leakage-via-list-fetch.js Outdated
Comment thread threat-model/index.html
<p>
This threat model follows the methodology described in the
<a href="https://www.w3.org/TR/threat-modeling-guide/">W3C Threat
Modeling Guide</a> and uses the STRIDE taxonomy for classifying threats.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
Modeling Guide</a> and uses the STRIDE taxonomy for classifying threats.
Modeling Guide</a> and classifies threats using the STRIDE taxonomy.

Co-authored-by: Ted Thibodeau Jr <tthibodeau@openlinksw.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants