The @w3cWorld Wide Web Consortium Security proposes to make systematic use of threat modeling in W3C to identify potential , vulnerabilities, and safeguards in web specifications.
This guide is designed to help standards make informed decisions about and risks from the beginning of standard development

▶️ w3.org/TR/threat-modeling-guid

Feedback wlc: github.com/w3c/threat-modeling

Data Flow Diagram for Minimalist Web Threat Model with 3 entities (user, network operator, website admin), linked by 7 flows to 3 processes (DNS, browser, server), as described in section A1.3 of the guide.
0

If you have a fediverse account, you can quote this note from your own instance. Search https://w3c.social/users/w3cdevs/statuses/115962281271714019 on your instance and quote it. (Note that quoting is not supported in Mastodon.)