Exercise sec-stride — turning a DFD into STRIDE threats, boundary by boundary

Threat modeling with STRIDE drew the picture by hand: a process gets all six categories, a store gets four, and a flow gets three plus Spoofing only when it crosses a trust boundary that is actually declared. This exercise is threats(dfd) — the function that reads a DFD as JSON and applies that same table mechanically, over 7 checks, including the exact 3-node diagram the lesson draws.

~90 minruns in the browser 7 checkssec-stride

What you're building

The checks are ordinary Python and ship with the page like everything else on a static site — open devtools and you can read every one. Check 4 is the trap that catches "any zone difference is a crossing": it hands you two zones that differ with an empty boundaries list and expects no Spoofing, because nothing on that DFD ever drew a boundary between them.

If you get stuck