Security Threat Modelling
Familiar
I review changes against how they could be attacked, for example account-enumeration oracles in sign-in copy, token and cookie scope creep, or trust in client-reported data. I adjust how closely I review based on what a change can actually affect.