skip to content

Which Threat Modeling Manifesto anti-patterns explain a session spending ninety minutes on one exotic threat, and how do you steer it back?

level: seniorimportance: should knowfreq 42%

answer

  1. Two of the Manifesto's four anti-patterns
  2. Analysis that never becomes a solution
  3. Proportion, and interdependent parts unlooked-at
  4. Every threat leaves with a disposition
  5. Cover the whole model before deepening

basics

~20 s

Admiration for the Problem, analysis that never reaches a practical solution, plus Tendency to Overfocus, where one threat eats the attention the rest of the model needed. Force every threat to a decision, and sweep the whole system before deepening any part.

solid answer

~50 s

Two of the Manifesto's four anti-patterns are running at once. **Admiration for the Problem** is the failure to go beyond analysing a threat and reach for a practical, relevant solution — the room is enjoying the threat. **Tendency to Overfocus** is losing the big picture by over-weighting one adversary, asset or technique while interdependent parts of the model go unexamined. Concretely: a post-production transcoding farm session elaborates an exotic timing side-channel for ninety minutes while the unauthenticated render-queue admin path is never opened, and the realistic actor is a contracted colourist studio whose workstation is compromised, going after unreleased-film IP. The correction has two halves matching the two anti-patterns: make the current threat produce a decision — mitigate, eliminate, transfer or accept, with a name against it — before opening the next one, and pass over every element and flow at low resolution before anyone goes deep.

go deeper

for a junior

Know that a threat which never turns into a decision has not been finished, and that a session which never leaves one component has not covered the system.

for a middle

Be ready to name both anti-patterns and give the Manifesto's own remedy for each: reach for practical solutions, and do not lose the big picture across interdependent parts.

for a senior

An interviewer wants the intervention, not the label. Show how you force a disposition on the threat in play and how you get a coarse pass over every flow before anyone goes deep.

for a principal

Own the proportionality argument. You will be asked to justify letting a genuinely interesting threat go with an explicit acceptance, and to defend that call to an engineer who found it.

### The two anti-patterns, precisely The Threat Modeling Manifesto lists four anti-patterns. Two of them describe how a session's attention goes wrong, and they are routinely confused: - **Admiration for the Problem** — the room analyses the threat beautifully and stops there. The Manifesto's own remedy is to go beyond analysing the problem and reach for practical and relevant solutions. - **Tendency to Overfocus** — the room loses sight of the big picture. The Manifesto specifically warns against exaggerating attention on adversaries, assets or techniques, and notes that parts of a model may be interdependent, so a narrow view misses what the neglected parts do to each other. The distinction is worth holding: **admiration is about depth that never converts**; **overfocus is about proportion**. A session can be free of one and drowning in the other, and the corrections differ. ### The worked case A post-production house runs a transcoding farm: mezzanine masters land, a render queue schedules jobs, workers transcode, and deliverables go to distributors. The asset at stake is unreleased-film intellectual property, and the realistic attacker position is a contracted colourist studio whose workstation has been compromised — a trusted vendor with legitimate access to submit and retrieve work. The session spends ninety minutes on a timing side-channel in a comparison inside the licence check. It is a genuine threat, it is technically fascinating, and by the end there is a whiteboard full of analysis and not one decision. Meanwhile the render-queue admin path — reachable without authentication from the studio VLAN, capable of re-targeting output destinations — is never opened. Both anti-patterns are visible. The side-channel discussion is admiration: no mitigation was proposed, no owner named, nothing was accepted or rejected. And the whole session is overfocused: attention concentrated on one exotic technique against one component while a whole class of flows, and the interaction between the queue and the delivery path, went unexamined. ### Steering back The two failures take different corrections, which is why naming them separately is useful rather than pedantic. **Against admiration — force the conversion.** No threat leaves the discussion without a disposition: a mitigation, an elimination (delete the feature or the flow), a transfer, or an explicit acceptance, each with a name attached. Writing `accepted, with a reason` is a legitimate output; writing nothing is not. The useful prompt in the room is *what would we actually change on Monday*. If the answer for the side-channel is `nothing, the effort-to-payoff is absurd for this actor`, that is a finished threat, and it took ninety seconds. **Against overfocus — cover before you deepen.** Sweep every element, every flow and every boundary crossing at low resolution first, generating one or two obvious threats each, and only then choose where to go deep. Depth chosen after coverage is a decision; depth chosen before coverage is an accident of who spoke first. Ask which threats the assumed attacker would actually reach for: a vendor workstation with legitimate queue access does not need a timing oracle when an unauthenticated admin path re-points the deliverable. ### The distinction on a second case A claims-adjudication platform session sinks into the cipher and key-management choices for a single stored field and never reaches the batch payout path. That is **overfocus** with little admiration — the crypto discussion did produce decisions, they were just decisions about the wrong two percent of the system. The dominant threat, an adjuster approving and paying their own claims, sits on a path nobody looked at. The correction here is coverage, not conversion. Recognising which of the two you have tells you whether to change how threats are *closed* or how attention is *allocated*. ### The nuance that separates a senior answer Depth is not the defect. If the rest of the model is covered and the asset justifies it, ninety minutes on one threat is a proportionate investment — and for some assets it is obviously right. The anti-patterns are about **proportion** and about **stopping at analysis**, not about rigour. A candidate who reflexively labels every long discussion as overfocus has swapped one bad heuristic for another; the question to ask first is always *what have we not looked at yet*.

  • How do you tell Admiration for the Problem apart from Tendency to Overfocus?
    Admiration is about conversion: the analysis is fine but nothing becomes a practical solution, so the session ends with an elegant threat list and no decisions. Overfocus is about proportion: attention is over-weighted on one adversary, asset or technique while interdependent parts of the model go unexamined. A session can suffer both at once, but the corrections differ — force dispositions versus force coverage.
  • A claims platform session sinks into cipher choices for one stored field and never reaches the batch payout path — which anti-pattern is that?
    Overfocus, with little admiration — the crypto discussion did reach decisions, they were just about a tiny slice of the system. The dominant threat is an adjuster approving and paying their own claims, and it lives on a path nobody opened. The correction is coverage first, not better closure of the threats already discussed.
  • Is it ever right to spend ninety minutes on one exotic threat?
    Yes, when the rest of the model is already covered and the asset justifies the depth. The anti-patterns are about proportion and about stopping at analysis, not about rigour. Choose depth after a coverage sweep and it is a decision; choose it before, and it is an accident of who spoke first.

saying these in an interview costs you the question

  • Labels any long discussion as overfocus regardless of coverage
  • Ends a session with an elegant threat list and no decisions
  • Ranks threats by cleverness rather than by what the assumed attacker would do
  • Treats an unexamined admin path as out of scope because nobody raised it
  • Uses the two anti-patterns interchangeably

context