
How useful is threat modeling in real-world security engineering?
threat modelingsecurity engineeringcybersecurityvulnerability analysissecurity architecturedesign reviewbest practices
A discussion about the practical application of threat modeling in security engineering. The poster is learning about threat modeling and questions how often security engineers actually build formal threat models in practice, particularly when analyzing web applications or investigating vulnerabilities versus during architecture/design reviews. They understand threat modeling as a way to make explicit the scope, attacker capabilities, assumptions, and security guarantees of a system rather than simply labeling it secure or insecure. The poster seeks input from practitioners about when threat modeling is genuinely useful versus when it becomes unnecessary overhead.