In a per-interaction STRIDE sweep, why can the same data flow rate differently at each crossing?
answer
- identical payload, different context
- look at both endpoints
- audience changes, sensitivity does not
- who can read it on the far side
- one flow, three crossings, three answers
basics
~20 sBecause the applicable STRIDE categories follow the two endpoints of a crossing, not the payload. Identical bytes moving from an untrusted device, then between internal services, then into a widely-read analytics estate raise different threats at each hop.
solid answer
~50 sThe letters that bite are decided by who the source is, what the destination acts with, and who can read the message on the far side — none of which is a property of the data itself. Take a ride-hailing location update that appears three times: driver device to edge ingest, edge to dispatch, dispatch to analytics. The first crossing is dominated by spoofing and tampering, because the source is a device physically held by someone with an incentive to fake their position. The middle hop crosses no boundary and honestly answers "not meaningful" for most letters. Only the analytics crossing carries a serious information-disclosure threat, because that is where a live operational position becomes retained movement history readable by a much wider internal audience. Rate the flow once and you get one verdict where the design has three.
go deeper
Remember that the same data flow can appear several times on a diagram, and that each appearance is analysed separately. Do not assume one verdict about the data covers every hop it takes.
Explain mechanically why the endpoints decide the letters: source identity drives spoofing and repudiation, destination privileges drive elevation, far-side audience drives disclosure. Walk one flow through more than one crossing without repeating yourself.
In a live whiteboard exercise, refuse to rate a flow once. Name which endpoint changed at each hop and which category changed with it, and be ready to say where a proposed control such as transport encryption does and does not reach.
Own the discipline that keeps this affordable: a signature for collapsing equivalent crossings, and a clear rule about which hops are swept at all. Be able to explain why a cheaper single-verdict habit systematically hides the crossing where the real exposure lives.
The instinct people bring from per-element analysis is that a data flow is a thing with properties — it carries these fields, it is encrypted or not — and therefore its threats can be worked out once. Per-interaction analysis breaks that instinct on purpose. The six STRIDE letters are asked of a *crossing*, and a crossing is defined by two endpoints, not by a payload. ## The same message, three crossings Consider a ride-hailing platform where a driver's device emits a location update every few seconds. On the diagram that update appears three times: ``` 1. driver device -> edge ingest (crosses: untrusted device -> our platform) 2. edge ingest -> dispatch service (crosses: nothing, both inside the platform) 3. dispatch service -> analytics store (crosses: operational -> analytics estate) ``` The bytes are the same at all three hops. The threats are not. **Hop 1** is where the source is an untrusted device physically held by a driver who has every incentive to lie about where they are. Spoofing bites: can the device assert a *different* driver's identity? Tampering bites: can the reported coordinates be fabricated to game dispatch or surge? Denial of service bites: can one device, or many, exhaust ingest? Information disclosure barely registers — the driver already knows their own location, so a threat about them reading it is empty. **Hop 2** crosses no boundary. Both ends run with the same privileges inside the same estate, the identity was established at hop 1, and the audience on the far side is the same audience. Most letters answer "not meaningful here", and writing that down deliberately is part of the sweep, not a gap in it. **Hop 3** is where information disclosure finally bites hard, and it has nothing to do with the payload changing. The analytics estate is read by a far wider population — analysts, dashboards, data-science jobs — and it retains history. A live position that is operationally necessary becomes, once retained and joined, a movement history of an identifiable person. That is a privacy consequence at the crossing, not a property of the message. Repudiation and elevation, meanwhile, are largely uninteresting here: the source is a trusted internal service, not a principal whose actions need to be attributable to a person. ## The rule underneath For each triple, the letters that bite follow from three things about the crossing rather than the content: | Question about the crossing | Categories it decides | |---|---| | Who is the source, and how strongly does the destination know it? | Spoofing, repudiation | | What rights does the destination act with on the source's behalf? | Elevation of privilege | | Who, on the destination side, can now read or keep this? | Information disclosure | | Can the source change what the destination believes or acts on? | Tampering | | Can the source or the path exhaust the destination? | Denial of service | Notice that "who can read this on the far side" is the disclosure question, not "is this data sensitive". Sensitivity is constant across the three hops; audience is not. This is exactly the difference a single per-element row on the location-update flow cannot express: it would produce one verdict where the design has three. ## How this shows up in a live session If an interviewer draws this and asks you to threat-model it, the strong move is to refuse to rate the flow once. Walk the crossings, say out loud which endpoint changed, and name the letter that changed with it. The weak move is to say "the flow carries location data, so it is an information-disclosure risk, encrypt it" — which is a single row, an unexamined control, and no analysis of the hop where the disclosure actually materialises. Transport encryption protects hop 1 and hop 3 from an eavesdropper on the wire; it does nothing about who can query the analytics store afterwards, which is where the disclosure threat on hop 3 lives. ## The bookkeeping cost, and the honest way to pay it Three near-identical rows for one logical flow is exactly the row explosion that makes teams distrust per-interaction sweeps. The usable discipline is to key rows by the *signature* of the crossing — source trust level, destination trust level, data class — and collapse triples that share a signature into one row with a note listing the edges it covers. Hop 2 collapses away almost immediately. Hops 1 and 3 have different signatures and must stay apart; collapsing them is the mistake the whole variant exists to prevent.
- How do you stop three near-identical rows from bloating the table?Key each row by the crossing's signature — source trust level, destination trust level, data class — and collapse triples that share a signature into one row that lists the edges it covers. Hops that cross no boundary usually collapse away immediately. Crossings with different signatures must stay separate, because collapsing them is precisely the loss the variant exists to prevent.
- If the analytics store sits inside the same trust boundary, does the disclosure threat disappear?No, it moves. The threat was never "this data crossed a line on a diagram", it was "a far wider audience can now read and retain it". If your boundary places the analytics estate on the trusted side, the sweep will inherit that and go quiet — which is a signal to re-argue the boundary, not evidence that the threat is gone.
- What makes a crossing carry repudiation rather than only tampering?Repudiation needs a source that is a distinguishable principal whose action has consequence, and a destination that keeps no attributable record of it. Service-to-service hops inside one estate rarely qualify. A crossing where a named person triggers a consequential state change and nothing durable ties them to it is the classic repudiation row.
saying these in an interview costs you the question
- Says the payload's sensitivity decides which STRIDE letters apply
- Rates a flow once and copies the row to every hop
- Claims transport encryption removes disclosure at every crossing
- Skips internal hops without checking who reads the far side
- Confuses retained history with a live value of the same field