Your ballot-tabulation threat model assumed operators are always supervised; that assumption drops. What changes?
answer
- the design did not change
- only assumption-dependent threats move
- the asset is the truth of the count
- which controls were resting on supervision
- tampering and attribution dominate
basics
~20 sThe design is unchanged, so only threats whose reachability rested on supervision change status. Tampering and repudiation now dominate because the asset is the truth of the count, and every control whose strength came from supervision is unsupported.
solid answer
~50 sI re-model the dial, not the system. The operator stays on the diagram but loses the trusted label, and local paths I never drew as flows — service ports, maintenance modes, removable media — become boundary crossings, because unsupervised time is what makes them usable. Against an asset of audit truth, `tampering` with the counting software or the stored tallies dominates, and `repudiation` becomes first-class: if credentials are shared per station, supervision *was* the attribution mechanism and now nothing attributes an action to a person. `Elevation of privilege` re-enters through maintenance and recovery paths. Internet-facing threats are unchanged, and I say so — a re-model that moves every rating is one nobody trusts. Then I re-test controls: seals checked by the same operator, two-person procedure and machine-local logs all rested on supervision. What survives is evidence held outside that operator's control and verification performed by someone who is not them.
go deeper
Be ready to say that removing a supervision assumption puts the operator outside the trusted set, and that tampering with what is counted becomes the leading concern even though no component changed.
Explain the mechanics of the re-model: which diagram elements the actor can now reach, which previously-dismissed threats come back, and why shared credentials turn an integrity failure into one nobody can attribute afterwards.
Demonstrate the operating judgment: name the controls that were silently resting on supervision, keep the pass bounded rather than rewriting the model, and steer the fix toward evidence a hostile operator cannot edit and checks performed outside their control.
Own the programme angle: models should record which assumptions each rating depends on so a dial change triggers a cheap bounded review, and assurance for an integrity asset should not depend on the honesty of the party being assured.
## The scenario A ballot-tabulation network is modeled with an assumption that was never argued because it looked like a fact: *only credentialed poll workers ever touch a machine, and always under supervision.* The assumption now drops — the same credentialed operator can have unsupervised time with the hardware. No component changed. The design is identical. The model is not. The asset here is **audit truth**: the property that the reported count corresponds to the votes cast and can be shown to correspond. That framing matters, because most instinctive controls protect confidentiality, and confidentiality is not what is at stake. ## First move: redraw the boundary, do not re-enumerate everything A common wrong answer is "we start the model again". The right answer is bounded: only the threats whose *reachability* rested on the dropped assumption change status. Concretely: - The operator was an external entity you drew on the **trusted** side. They stay where they are on the diagram, but the trust label comes off. - Local interfaces you never drew as flows — service ports, maintenance modes, removable media, the boot path — become flows crossing a boundary, because time and privacy are what turned them from theoretical into usable. - Anything reachable only from the public internet is **unaffected**. Saying so out loud is part of the answer: a re-model that changes every rating is a re-model nobody will trust. ## Which threats survive, in STRIDE terms - **Tampering** dominates. With unsupervised time, modification of the counting software, its configuration, or the stored tallies moves from "requires a chain of unlikely steps" to "requires patience". This is the threat the asset is defined against. - **Repudiation** becomes first-class. If credentials are shared per shift or per station, no action can be attributed to a person, so an integrity failure cannot even be investigated afterwards. Under the old assumption, supervision *was* the attribution mechanism. - **Elevation of privilege** re-enters through local paths: maintenance and recovery modes, physical reset, debug interfaces — capabilities deliberately given to a trusted operator role. - **Spoofing** shifts meaning. The actor does not need to spoof to get in; the concern is impersonating *another* operator to shift blame, which is really an attribution problem again. - **Information disclosure** is largely unchanged, and **denial of service** is now trivially available but was already accepted as a procedural risk. Naming these as unchanged is as valuable as naming what got worse. ## Which controls stop being defensible This is the part interviewers listen for. Several controls were resting on supervision without ever saying so: | Control | Why it stops holding | | --- | --- | | Tamper-evident seals checked by the same operator | The checker and the assumed actor are the same person | | Two-person procedural rules | Only as strong as the supervision that was just removed | | Local audit logs on the machine | Writable by an actor with unsupervised administrative access | | "Only staff can reach this network" | Restates the assumption you just dropped | What survives is anything whose strength comes from a party **outside** the assumed actor's control: an independently held record that can be checked against the electronic count, verification performed by someone who is not the operator, evidence written to a place the operator cannot rewrite, and totals published early enough that a later change is visible as a change. ## Rating moves too Threats that were rated low because they required a chain of coincidences are now rated on patience alone. A rating that quietly encoded "someone would be watching" has to be redone, not carried forward. If your model records a rationale per rating, this pass is mechanical; if it records only a number, you cannot tell which ratings were assumption-dependent — which is the practical argument for writing rationales down in the first place. ## The general lesson The exercise generalises to any actor change. Substitute a compromised package maintainer inside your build for the operator at the machine and the shape repeats: the actor arrives inside a process you drew as yours, build-time flows you never diagrammed become in-scope, and controls aimed at the network edge do nothing about them. The method is the same four steps — restate the dial that moved, mark the elements it now reaches, revive threats that were triaged out because of it, and re-test every control whose strength came from it. ## What a strong answer sounds like "The design did not change, the assumption did. Tampering and repudiation now dominate because the asset is the truth of the count; supervision was load-bearing for three of our controls and all three are now unsupported; internet-facing threats are unchanged; and the fix direction is evidence that a hostile operator cannot edit and verification by someone outside their control."
- Which STRIDE categories move most once the actor already holds legitimate credentials?Tampering and repudiation. The actor no longer needs to spoof their way in, so authenticity at the front door matters less, while integrity of what they can touch and attribution of what they did matter far more. Elevation of privilege re-enters through paths deliberately granted to the trusted role. Information disclosure often changes least, because authorised reads were already in their remit.
- How do you stop a re-model like this from turning into a full rewrite?Restate exactly which dial moved, mark only the elements the actor can now touch, and for each existing threat on those elements ask whether it was triaged out because of the old assumption. Those come back; everything else keeps its rating. Then re-test controls whose strength came from the assumption. Bounded passes are what make re-modeling repeatable rather than an annual rewrite.
- Substitute a compromised package maintainer inside your build for the operator at the machine. What is different?The shape repeats but the entry is stranger: the actor never crosses a boundary you drew, they arrive inside a process the diagram labels as yours. Build-time flows nobody diagrammed become in-scope, and edge-facing controls are irrelevant to them. The same four steps apply — name the dial, mark reachable elements, revive threats triaged out under the old assumption, re-test dependent controls.
- How should ratings from the old model be treated after this change?Any rating that quietly encoded 'someone would be watching' has to be redone rather than carried forward — threats that scored low because they needed a chain of coincidences now need only patience. This is the practical argument for recording a rationale beside each rating: with a rationale the pass is mechanical, with only a number you cannot tell which ratings were assumption-dependent.
Dropping the supervision assumption is like pulling out one beam and finding out how many controls were quietly resting on it.
saying these in an interview costs you the question
- Claims every threat must be re-derived from scratch
- Keeps controls whose only strength was supervision
- Reaches for encryption when the asset at risk is count integrity
- Trusts machine-local logs the same actor can rewrite
- Treats authorised insider misuse as a spoofing problem
- Never says which threats are unaffected by the change