# Amazon's 'Alexa Built-in' Threat Model

DevFeed: [Amazon's 'Alexa Built-in' Threat Model](<https://devfeed.tech/articles/amazon-s-alexa-built-in-threat-model-36667.md>)

Original publisher: [Read original article](<https://shostack.org/blog/amazons-alexa-built-in-threat-model/>)

Author: Adam

Published: 2020-03-05T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [amazon](<https://devfeed.tech/topics/amazon.md>), [Security](<https://devfeed.tech/topics/security.md>), [Requirements](<https://devfeed.tech/topics/requirements.md>), [Secure Boot](<https://devfeed.tech/topics/secure-boot.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>)

Tags: [account](<https://devfeed.tech/tags/account.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [requirements](<https://devfeed.tech/tags/requirements.md>), [secure-boot](<https://devfeed.tech/tags/secure-boot.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

The article examines Amazon's Alexa Built-in device security requirements as an example of supply chain threat modeling. It discusses seven required capabilities, including Secure Boot, secure key storage, hardware-based cryptography, supported operating systems, host hardening, privilege separation, and threat surface reduction, and explains how security assessments fit into the model.

## Source excerpt

Exploring supply chain threat modeling with Alexa