
Greg Vanore
Director of Software Engineering at Hunter Strategy, based in Greater Philadelphia.
3
APPEARANCES
1
PODCASTS
012
DEC 30
JAN 6
JAN 13
JAN 20
JAN 27
FEB 3
FEB 10
FEB 17
FEB 24
MAR 3
MAR 10
MAR 17
MAR 24
MAR 31
APR 7
APR 14
APR 21
APR 28
MAY 5
MAY 12
MAY 19
MAY 26
JUN 2
JUN 9
JUN 16
JUN 23
JUN 30
JUL 7
JUL 14
JUL 21
JUL 28
AUG 4
AUG 11
AUG 18
AUG 25
SEP 1
SEP 8
SEP 15
SEP 22
SEP 29
OCT 6
OCT 13
OCT 20
OCT 27
NOV 3
NOV 10
NOV 17
NOV 24
DEC 1
DEC 8
DEC 15
DEC 22
DEC 29
JAN 5
JAN 12
JAN 19
JAN 26
FEB 2
FEB 9
FEB 16
FEB 23
MAR 2
MAR 9
MAR 16
MAR 23
MAR 30
APR 6
APR 13
APR 20
APR 27
MAY 4
MAY 11
MAY 18
MAY 25
JUN 1
JUN 8
JUN 15
JUN 22
JUN 29
JUL 6
JUL 13
JUL 20
JUL 27
AUG 3
AUG 10
AUG 17
AUG 24
AUG 31
SEP 7
Sep 3, 2026
Threat Modeling Techniques in Defense Cybersecurity
34:42
34:55
35:10
35:32
35:46

Xander KeeleGUEST
the quarter, six weeks into the quarter when you're threat modeling a certain feature and realize, "Oh boy, we have a bigger problem here." That becomes an issue contractually, like you said.

Greg VanoreGUEST
Uh, s- so on a negative example side, I worked for, on a project for an agency that used a third-party tool t- for basically a, a content management system.

Greg VanoreGUEST
And the content management system did have all sorts of security protections when you went through their UI, and similarly to what you were saying, Xander, with the developers saying, "Well, users can't do that, so therefore I don't have to worry about it." Someone in the third-party product determined that to make it integrate with other tools, they would add a WebDAV layer.

Greg VanoreGUEST
Well, all of the security was built into the user interface layer, so the WebDAV layer essentially kind of, you know, went around the back end and served all the content inside the system without any kind of permissions checks.

Greg VanoreGUEST
And we had been in production for a number of years, and we just kind of randomly, accidentally discovered this ourselves while using the product.
Opensource Software Security in the DoD
4:22
4:35
4:48
M
4:07Matt TreinerHOST
And so why do you think, uh, so first off, let's just define what does that mean in, in your experience? And why do you think DoD was so careful to include that in its definition?

Greg VanoreGUEST
But the contributor license agreement is basically when you submit to an open source project that has one of these, you have to agree to assign them copyright of your code, which allows them to relicense it as they see fit.

Greg VanoreGUEST
So, you know, you've seen controversial projects like Terraform most recently turn and relicense itself as a business source license and other projects as well.

Greg VanoreGUEST
And there's a little bit of an interesting thing going on there because usually what we view in this country of public tax dollar spends uh belongs to the public even if that's dod and so if you sign a contributor license agreement you are essentially giving uh the the fruits of that labor to a privately owned company but that's being done outside the oversight of the contracting process so i think it's really uh It may be not well understood by DOD CIO, but if you are engaging in those sort of things, like if you have to sign a CLA to contribute upstream, you're kind of like making a decision about giving tax funded works to a private institution, which can then profit from it.
9 MINS LATER
Team Death Spiral
38:44
39:01
M
38:30Matt TreinerHOST
... resources, like, let's just say resources, then it's not profit or anything, it's just from a resources perspective, am I getting more out than I'm putting in?

Greg VanoreGUEST
If you, when you, you build a microservice architecture, and you do it right and you have good observability, including, you know, distributed logging and tracing, and when you have a problem in production, you can solve that in 10 minutes versus spending three days solving it.

Greg VanoreGUEST
You know, these things, these things really affect the cost of the team and your ability to respond to change, all those things.
