<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Threat Modeling Again, Analyzing the threats to PlaySound</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/13/threat-modeling-again-analyzing-the-threats-to-playsound.aspx</link><description>In my last post , I enumerated a bewildering array of threats that the PlaySound API is subject to, today I want to work through the analysis process for each of those threats. To refresh, here's the DFD and the list of threats: Application: External</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Threat Modeling Again, Analyzing the threats to PlaySound</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/13/threat-modeling-again-analyzing-the-threats-to-playsound.aspx#4900519</link><pubDate>Fri, 14 Sep 2007 00:25:39 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4900519</guid><dc:creator>Dennis E. Hamilton</dc:creator><description>&lt;p&gt;I think here, around &amp;quot;spoofing issue against the audio APIs,&amp;quot; you've pretty much explained why you don't see a threat surface there, since it comes down to someone running as administrator and the PC becoming owned any number of ways.&lt;/p&gt;
&lt;p&gt;The prospect of trojan Audio Playback attacking the system also seems remote in that case, since it will run at the privilege level of the requester (so the install process is more favorable as an attack injection anyhow).&lt;/p&gt;
&lt;p&gt;Did I miss anything? &amp;nbsp;&lt;/p&gt;
&lt;p&gt;I'm still uneasy and I think it's this: Even if you had some only-global-mitigation (or more-appropriately worded) annotation/marker on that dataflow, it would provide a placeholder for your rational for why there is no meaningful mitigation to be taken at Playsound itself because of what has to have happened. &amp;nbsp;It would be good to have the narration of your thinking be preserved and visible for those who come after you and consider making changes. &amp;nbsp;[I am speculating beyond my knowledge of the practice and of Playsound itself.]&lt;/p&gt;
</description></item><item><title>re: Threat Modeling Again, Analyzing the threats to PlaySound</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/13/threat-modeling-again-analyzing-the-threats-to-playsound.aspx#4900667</link><pubDate>Fri, 14 Sep 2007 00:38:24 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4900667</guid><dc:creator>LarryOsterman</dc:creator><description>&lt;p&gt;That sounds about right.&lt;/p&gt;
&lt;p&gt;Actually I think the comments in your 4th paragraph are quite reasonable, I'll do my best to ensure that the final threat model contains this reasoning.&lt;/p&gt;
</description></item><item><title>re: Threat Modeling Again, Analyzing the threats to PlaySound</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/13/threat-modeling-again-analyzing-the-threats-to-playsound.aspx#4918964</link><pubDate>Sat, 15 Sep 2007 02:15:20 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:4918964</guid><dc:creator>Triangle</dc:creator><description>&lt;p&gt;&amp;quot;for PlaySound, there is no risk of the interactor repudiating their action (nobody's going to come along and claim that they didn't really make that noise).&amp;quot;&lt;/p&gt;
&lt;p&gt;None immediately come to mind, but I'm willing to bet there are situations where that isn't always true.&lt;/p&gt;</description></item><item><title>Some final thoughts on Threat Modeling...</title><link>http://blogs.msdn.com/larryosterman/archive/2007/09/13/threat-modeling-again-analyzing-the-threats-to-playsound.aspx#5225279</link><pubDate>Mon, 01 Oct 2007 19:54:13 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:5225279</guid><dc:creator>Larry Osterman's WebLog</dc:creator><description>&lt;p&gt;I want to wrap up the threat modeling posts with a summary and some comments on the entire process. Yeah,&lt;/p&gt;</description></item></channel></rss>