OWASP / OWASP/cornucopia

Create scenarios for the EoP game

Open
#3,405 3 comments 0 reactions 0 assignees View on GitHub
documentation help wanted
Dominant language
Python
Stars
146
Forks
97
Avg merge
1d 7h
Merged PRs (30d)
104

Description

Elevation of Privilege (EoP) is a serious tabletop card game designed by cybersecurity expert Adam Shostack in 2010 to make threat modeling accessible, engaging, and collaborative for software developers and architects. Instead of forcing engineering teams to sift through dry, academic security checklists, the game uses gamified mechanics to help players look at a system diagram and figure out "what can go wrong" before the code is actually built.

We are looking for contributors to help us with the help pages for each of the EoP Cards https://cornucopia.owasp.org/edition/eop

We need you to help us write a funny, but technical correct scenario with an example.
You also need to provide a STRIDE analysis of the example.
We also need you to help players answer:

- What can go wrong?
- What are we going to do about it?

Remember to provide authoritative references (links) under "What can go wrong" and "What are we going to do about it?" that support your claims. The point is not to create an exhaustive list of everything that can go wrong, or that should be done, but to help the player start thinking about their own situation, and if you have a hilarious and absurd example, don't be afraid to use it (E.g: 2014 Steam "Blank Password" exploit)!
It‘s better if it is a hilarious example from the real world.

As an example, see: https://cornucopia.owasp.org/cards/AA2

To contribute, simply comment here and tell me which card you will do and wait for me to confirm.

To add your text, simply click on the "View source on GitHub" button on the bottom of the page of the card you want to do. See image.

Image

Contributor guide

Open the contributing guide

Research direction

Choose a card and first review the existing AA2 example at https://cornucopia.owasp.org/cards/AA2, then use that card page’s “View source on GitHub” entry point. Done means a technically accurate, humorous scenario with an example, STRIDE analysis, answers to both player questions, and authoritative references; comment with the chosen card and wait for confirmation before editing.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
52/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.