Alice and Bob Learn Application Security versus Threat Modeling.
Both show up on every "best" list. They're not competitors. They're a sequence. Here's which one to read first, and when.
Reviewed by Ashish Sheth · Updated August 2026
Author
Tanya Janca
Adam Shostack
Pages
288
624
Published
2020
2014
Publisher
Wiley
Wiley
Level
beginner
intermediate
Amazon Rating
4.7/5 (225)
4.5/5 (339)
Goodreads Rating
4.27/5 (133)
4.07/5 (288)
Alice and Bob Learn Application Security
Strengths
+ Friendly, encouraging tone that lowers the barrier to a hard topic
+ Covers the whole lifecycle, not just a list of vulnerabilities
+ Practical checklists and exercises at the end of each chapter
+ Strong on the people and process side of security, not only the code
Caveats
− Breadth over depth; each topic is an introduction rather than a deep dive
− Language-agnostic, so few copy-paste code examples for your stack
− Experienced security engineers may find the early chapters too basic
Threat Modeling
Strengths
+ The definitive treatment of threat modeling from a field founder
+ Gives you repeatable frameworks instead of vague advice
+ Deep and thorough, with plenty of worked examples
+ Applies well beyond software to any system you design
Caveats
− Long and dense at 624 pages; it reads like a reference, not a tutorial
− Published in 2014, so cloud and modern pipeline examples are thin
− Heavier going for developers new to security fundamentals
The verdict
Read Alice and Bob Learn Application Security first to build foundations, then move to Threat Modeling for advanced concepts.
Alice and Bob Learn Application Security
Check Price on Amazon →
Threat Modeling
Check Price on Amazon →
Frequently asked
Which is better, Alice and Bob Learn Application Security or Threat Modeling?
Read Alice and Bob Learn Application Security first to build foundations, then move to Threat Modeling for advanced concepts.
Is Alice and Bob Learn Application Security good for beginners?
Yes, that is exactly who it is written for. Tanya Janca assumes little security background and builds up fundamentals, secure design, and coding practices in a warm, encouraging voice. About 130 Goodreads readers rate it around 4.3. Experienced security engineers may find the early chapters slow, but newcomers get a clear map.
Is Threat Modeling by Adam Shostack still worth reading in 2026?
Yes. The frameworks it teaches, the four-question method, STRIDE, and data flow diagrams, are still the standard vocabulary for threat modeling and have not been replaced. The 2014 examples predate today's cloud and CI/CD tooling, so read it for the durable method and apply that method to your own modern architecture.