Microsoft’s security team tried to teach developers what to do to find security vulnerabilities in Windows Server 2003 code. But they made some mistakes, including telling developers to think like a hackers approach to threat modeling. The result was a few interesting bugs that nowhere near justified the effort expended. Not every engineer is going to be able to think like hackers, says security expert David LeBlanc, one of his colleagues from his days at Microsoft, who says developers want to do the right things, but you have to be very specific.”]