Skip to content

Commit

Permalink
remove br
Browse files Browse the repository at this point in the history
  • Loading branch information
sydseter committed Feb 3, 2025
1 parent 5c87a72 commit e344994
Show file tree
Hide file tree
Showing 3 changed files with 23 additions and 19 deletions.
18 changes: 11 additions & 7 deletions data/website/pages/about/en/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,16 +8,20 @@ If you have other questions, suggestions or ideas please feel free to discuss th

## Introduction

he idea behind Cornucopia is to help development teams, especially those using Agile methodologies, to identify application security requirements and develop security-based user stories.
The idea behind Cornucopia is to help development teams, especially those using Agile methodologies, to identify application security requirements and develop security-based user stories.
Although the idea had been waiting for enough time to progress it, the final motivation came when [SAFECode](http://www.safecode.org/) published its [Practical Security Stories and Security Tasks for Agile Development Environments](https://safecode.org/publication/SAFECode_Agile_Dev_Security0712.pdf '[inline] SAFE Code publication as pdf') in July 2012.

Cornucopia was created and first used for developer training in August 2012.

The Microsoft SDL team had already published its super [Elevation of Privilege: The Threat Modeling Game (EoP)](https://www.microsoft.com/en-gb/download/details.aspx?id=20303 'EoP publication at Microsoft. [external]') but that did not seem to address the most appropriate kind of issues that web application development teams mostly have to address.
<br/>EoP is a great concept and game strategy and was [published](https://www.microsoft.com/security/blog/2010/03/02/announcing-elevation-of-privilege-the-threat-modeling-game/ 'Microsoft announcing EoP on their blog. [external]') under a [Creative Commons Attribution License](http://creativecommons.org/licenses/by/3.0/ 'Link to the CC BY 3.0 Attribution Unported License [external]').
<br/>Cornucopia is based the concepts and game ideas in EoP, but those have been modified to be more relevant to the types of issues website app and mobile app developers encounter.
<br/>It attempts to introduce threat-modelling ideas into development teams that use Agile methodologies or are more focused on web application weaknesses than other types of software vulnerabilities or are not familiar with STRIDE and DREAD.

#### How to start
EoP is a great concept and game strategy and was [published](https://www.microsoft.com/security/blog/2010/03/02/announcing-elevation-of-privilege-the-threat-modeling-game/ 'Microsoft announcing EoP on their blog. [external]') under a [Creative Commons Attribution License](http://creativecommons.org/licenses/by/3.0/ 'Link to the CC BY 3.0 Attribution Unported License [external]').

Cornucopia is based the concepts and game ideas in EoP, but those have been modified to be more relevant to the types of issues website app and mobile app developers encounter.

It attempts to introduce threat-modelling ideas into development teams that use Agile methodologies or are more focused on web application weaknesses than other types of software vulnerabilities or are not familiar with STRIDE and DREAD.

### How to start

To start using Cornucopia:

Expand Down Expand Up @@ -49,7 +53,7 @@ Additionally, Adam Shostack maintains a list of tabletop security games and rela

## Acknowledgements

#### Volunteers
### Volunteers

Cornucopia is developed, maintained, updated and promoted by a worldwide team of volunteers. The contributors to date have been:

Expand Down Expand Up @@ -96,7 +100,7 @@ Cornucopia is developed, maintained, updated and promoted by a worldwide team of

Please let us know if we have missed anyone from this list.

#### Others
### Others

- Adam Shostack and the Microsoft SDL Team for the Elevation of Privilege (EoP) Threat Modelling Game, published under a Creative Commons Attribution license, as the inspiration for Cornucopia and from which many ideas, especially the game theory, were copied.
- Keith Turpin and contributors to the “OWASP Secure Coding Practices - Quick Reference Guide”, originally donated to OWASP by Boeing, which is used as the primary source of security requirements information to formulate the content of the cards.
Expand Down
14 changes: 7 additions & 7 deletions data/website/pages/printing/en/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ The fonts can also be downloaded from the web.
- Fivo Sans: [https://www.fontsc.com/font/fivo-sans](https://www.fontsc.com/font/fivo-sans)
- Atkinson Hyperlegible: [https://brailleinstitute.org/freefont](https://brailleinstitute.org/freefont)

#### The following fonts are used:
### The following fonts are used:

- Deck: Fivo Sans and Atkinson Hyperlegible
- Leaflet: Fivo Sans
Expand All @@ -59,23 +59,23 @@ The fonts can also be downloaded from the web.
- Noto Sans Extra Condensed Extra Bold


#### Dimensions
### Dimensions

###### Card decks:
#### Card decks:

The "bridge" files are (2.25 x 3.5" or 57mm x 88.8mm) standard playing cards.

The "tarot" files are (2.75 x 4.75" or 71mm x 121 mm) standard playing cards.

###### Cases:
#### Cases:

the boxes has standard dimensions used by Agile Stationary to print their OWASP Cornucopia decks.

The "bridge" is 60 x 89.25 mm x 27.15 mm

The "tarot" is 122.2 x 73.1 x 29.1 mm

###### Leaflets:
#### Leaflets:

The "bridge" and "tarot" version is a 16-20 page spread depending on which language you print it in.

Expand All @@ -91,11 +91,11 @@ You may need to adjust the font size to fit either a 16 or a 20 page leaflet spr

DO NOT PRINT an 18 Page leaflet! It won't look good.

###### Blead:
#### Blead:

A standard blead set to 3mm for all 4 sides.

###### Paper:
#### Paper:

Use 300gsm for both the bridge cards and the tarot cards.

Expand Down
10 changes: 5 additions & 5 deletions data/website/pages/roadmap/en/index.md
Original file line number Diff line number Diff line change
Expand Up @@ -19,11 +19,11 @@ Ordered alphabetically and not according to priority.

Involvement in the development and promotion of Cornucopia is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help are listed below.

#### Localization
### Localization

Are you fluent in another language? Can you help translate Cornucopia into that language? Note this is a very large task due to the number of documents involved, but the strings are now all available in textual data files.

#### Use and Promote the Cornucopia Card Decks
### Use and Promote the Cornucopia Card Decks

Please help raise awareness of Cornucopia by:

Expand All @@ -34,7 +34,7 @@ Please help raise awareness of Cornucopia by:
- Developing a mobile app to play the game


#### Feedback
### Feedback

Please use the friendly project [Google Group](https://groups.google.com/a/owasp.org/forum/#!forum/cornucopia-project 'OWASP Cornucopia google mailing list [external]') for feedback:

Expand All @@ -44,11 +44,11 @@ Please use the friendly project [Google Group](https://groups.google.com/a/owasp
- How could the guidance be improved?
- What other decks would you like to see?

#### Keep the Cards Updated
### Keep the Cards Updated

As the source referenced documents change, we have to update the decks. You may also find errors and omissions. In the first instance, please send a message to the project’s [Google Group](https://groups.google.com/a/owasp.org/forum/#!forum/cornucopia-project 'OWASP Cornucopia google mailing list [external]') if you have identified errors &amp; omissions, have some time to maintain the source documents, or can help in other ways.

#### Create a New Deck
### Create a New Deck

The first deck, Cornucopia Ecommerce Website Edition, has been renamed Cornucopia Website App Edition and is currently available in six languages. There is also a mobile app specific deck called Cornucopia Mobile App Edition available in English only. Do you have an idea for your own application security requirements card deck?

Expand Down

0 comments on commit e344994

Please sign in to comment.