I support Adam Shostack and the statement he made about his stalker.SheHacksPurple2026-09-22 | I support Adam Shostack and the statement he made about his stalker.SheHacksPurple: Interview with Vandana Verma at Black HatSheHacksPurple2025-09-11 | I had just a couple of minutes with my amazing friend @Infosecvandana at Black Hat and I really made them count. Listen to all the amazing projects she's working on!I interviewed Farah Hawa at Diana Initiative in Las Vegas! 🎉 #bughunting #appsec @FarahHawaSheHacksPurple2025-09-11 | ...Bilingual hilarity... ChatGPT in French translates to Cat, I farted. 😂 #ai #chatgptSheHacksPurple2025-09-10 | ...The very last words of my book. Alice and Bob Learn Secure Coding. ☺️💖SheHacksPurple2025-09-07 | ...Petition to ask Canada to adopt a secure coding policy ipetitions.com/petition/secure-canadas-futureSheHacksPurple2025-07-02 | ...What do I think of Shift Left? Hear my answer to my friend Laura Bells question.SheHacksPurple2025-06-28 | ...NDC Oslo 2025 - Kjersti SandbergSheHacksPurple2025-06-19 | I had the pleasure of interviewing Kjersti Sandberg, founder of the legendary NDC Conferences, about something very exciting — a brand-new AI + security + application development conference coming to Manchester in December 2025! ✨ NDC Manchester, AI & Security✨ ndcmanchester.com
This event is set to bring together top minds in AppSec, DevSecOps, and secure software development — and I'll be there, so I hope you will be too! 🙌
Watch now to hear how it all came together, what to expect, and why this is one event you won’t want to miss. 🔐💻
#AppSec #CyberSecurity #NDC2025 #TanyaJanca #ManchesterConference #DevSecOps #AIGet to know me a bit betterSheHacksPurple2025-06-01 | Get to know me a bit more.... #shehackspurple #appsec #career #code #programmingSheHacksPurple: Tanya interviews Dustin Lehr at RSA 2025 | Security Champions & KatilystSheHacksPurple2025-05-31 | In this #RSAC conference interview, I sit down with Dustin Lehr to dive into the power of Security Champions Programs—why they matter, how to build them, and what makes them succeed. We also discuss Dustin’s new venture, Katilyst (katilyst.com), a new startup focused on empowering engineering teams to take ownership of security in a practical, scalable way.
Whether you're a security leader, developer, or just curious about building a stronger security culture, this conversation has something for you.
👉 Don’t forget to like, comment, and subscribe for more insights from RSAC!
#RSAC2025 #SecurityChampions #Katilyst #AppSec #DevSecOps#infosecgardening transplanting asparagusSheHacksPurple2025-05-15 | ...SheHacksPurple: Interview with Marisa Fagan | Security Champion & Product Management at KatilystSheHacksPurple2025-05-09 | In this RSAC 2025 interview, Tanya sits down with Marisa Fagan, a seasoned security leader and product manager at Katilyst. Marisa shares insights on building effective security champion programs, scaling security through empowerment, and how her work at Katilyst is helping organizations bridge the gap between security and development teams. Whether you're a security professional, a PM, or just curious about modern AppSec strategies, this conversation is packed with practical takeaways.
🔒 Don’t forget to like, comment, and subscribe for more cybersecurity insights from Tanya!Thank you for everything #rsac, and all the wonderful people I got to see and talk to this week!SheHacksPurple2025-05-02 | ...SheHacksPurple: Interview with Chris Hughes at RSA 2025SheHacksPurple2025-05-02 | In this RSAC interview, I catch up with Chris Hughes to talk about software supply chain security (and how it's not just dependencies!), application security, and the conference. Chris also shares updates on Resilient Cyber, the platform he's helping build to elevate conversations around cybersecurity.It was GREAT!
Key Topics: The current state of supply chain security AppSec challenges in modern development The mission behind Resilient Cyber
🔔 Like, share, and subscribe for more expert conversations from RSAC!
Chris' Links resilientcyber.io linkedin.com/in/resilientcyberCanada, its Election Day! Please go pick our new government. #yourvotematters #electionday #voteSheHacksPurple2025-04-28 | ...Im headed to San Francisco for #Bsides and #RSAC!SheHacksPurple2025-04-26 | ...Housing question for political parties in Canada. Why arent you making it easier to be a landlord?SheHacksPurple2025-04-25 | ...Hi Canada! Election Day is THIS MONDAY! Please go out and vote! #yourvotematters #ourvotesmatterSheHacksPurple2025-04-24 | ...Today is the last day of advance polling. Please vote today, or make plans to vote election day.SheHacksPurple2025-04-21 | ...I voted in the Canadian federal election! Please go vote Canada! #ItsOurVote #votingmattersSheHacksPurple2025-04-18 | ...Canada, please go vote! Advance voting starts tomorrow. Please vote. 🙏SheHacksPurple2025-04-17 | ...I just received OWASP Distinguished Life Time Member Award in the mail. Thank you. ☺️ #appsecuritySheHacksPurple2025-03-26 | ...Im on my way to Denver for OWASPs #SnowFroc conference!SheHacksPurple2025-03-12 | ...SheHacksPurple: Unboxing my brand new MacBook!SheHacksPurple2025-03-05 | I'm incredibly excited about my new MacBook. It's black, beautiful, and so powerful!!!!! I can't wait to cover it in stickers.DeveloperWeek with Guled AbdilahiSheHacksPurple2025-02-24 | ...DeveloperWeek with Jessica Deen of GitHubSheHacksPurple2025-02-21 | ...DeveloperWeek with Andra Lezza and Wendy Segura!SheHacksPurple2025-02-21 | ...DeveloperWeek with Starr Brown of OWASP FoundationSheHacksPurple2025-02-20 | ...DeveloperWeek with Sweta SinhaSheHacksPurple2025-02-20 | ...DeveloperWeek with Jason Haddix of Arcanum SecuritySheHacksPurple2025-02-20 | ...I finally have my book!!!! https://shehackspurple.ca/books/#appsec #securecodingSheHacksPurple2025-01-31 | ...A very happy storySheHacksPurple2025-01-28 | ...SheHacksPurple: Lets talk Chapter 7: Popular Frameworks! Alice and Bob Learn Secure CodingSheHacksPurple2025-01-21 | Chapter 7: Popular Frameworks Web: · Security Controls and Gotchas · Express · React.js · Angular · jQuery · Vue.js Other Frameworks and Libraries · Security Controls and Gotchas
· .Net CORE · Spring Boot · Flask · Chapter ExercisesSheHacksPurple: Explore Chapter 6 of my new book, Popular Programming LanguagesSheHacksPurple2025-01-21 | Chapter 6: Popular Programming Languages · Security Controls and Gotchas · JavaScript · HTML/CSS · Python · SQL · Node.js · Java · TypeScript · C# · PHP · C/C++SheHacksPurple: Chapter 4 of Alice and Bob Learn Secure Coding: AchievingSheHacksPurple2025-01-21 | Chapter 4: Achieving · Secure Design · Dependency Management and Supply Chain Security · Secure Defaults · Readable and Auditable Code · Important Functions Happen on Trusted Systems · Approved Lists versus Block Lists · Secure Configurations · Hostname Validation · Reusable Code · Safe System Calls · Commenting and Other Documentation · Verification of User Consent · Integrity Checks, Code Signing and Immutable Builds · Avoiding Brute Force · Security Controls · Handling Elevated Privileges · Secure Maintenance · Reusable Wrappers/Libraries · Repaying Technical Debt · Chapter Exercises · Part 1 Check List of General Secure Coding AdviceSheHacksPurple: Chapter 3 of Alice and Bob Learn Secure CodingSheHacksPurple2025-01-21 | Hear me discuss the contents of Chapter 3: Improving · Database Security · File Management · Memory Management (Buffer, Stack, String, and Integer Overflows) · (De)Serialization · Privacy (User/Citizen/Customer/Employee) · File Uploads · Logging, Monitoring, and Alerting · Fail Closed · Locking Resources · Enabling Password Managers · Cryptographic Practices · Strongly Typed Languages · Domain-Driven Development · Memory-Safe Languages · Chapter ExercisesSheHacksPurple: Learn about Chapter 2 of Alice and Bob Learn Secure Coding BeginningSheHacksPurple2025-01-21 | Chapter 2: Beginning · Follow a Secure System Development Life Cycle (Part 3) · Use a Modern Framework, and All Available Security Features Within · Input Validation · Output Encoding · Parameterized Queries and ORMs · Authentication and Identity · Authorization and Access Control · Session Management · Secret Management · Password Management · Communication Security (Cryptography and HTTPS Only) · Protecting Sensitive Data · Security Headers · Same-Origin Policy · Secure Cookies · Error Handling · Chapter ExercisesSheHacksPurple: How to get talks accepted by conferencesSheHacksPurple2025-01-21 | I am often asked: how do you get into conferences? What should I submit? How much detail? Can I do the same talk twice? How can I get feedback on a talk that I am working on? So I made a video to answer the most recent person who asked. I hope you find it helpful. Below is what I wrote to him.
I feel like a professional mentor would be very helpful for you. I am already mentoring quite a few people, and can't add another person right now, but I can help you find someone with my mentoring program #CyberMentoringMonday. Every Monday on X, LinkedIn, BlueSky and Mastadon I make a post, using that hashtag, and then people respond with what they are looking for or offering. LinkedIn is by far the least active, because you can't "reshare" someone's response to your own thread. That said, if you respond to my posts on any platform I will like them and (if possible) I will reshare them to all of my followers until you find someone.
Although I can't give you a lot of time at the moment, if you send me your email I will send you a couple of my submissions that I have had accepted to conferences in the past to give you an idea of what they are looking for. When you send an outline, or there's a box where they ask for "any details", tell them EVERYTHING. All the secrets of your talk, all the details, all the research that you will present. Hold nothing back, this is what makes their decision.
You do not need to create a unique talk for each conference, I redo the same talks over and over again. However, for big conferences they want a unique one (Black Hat, Def Con, etc.) So keep a new talk for a big conference, and submit talks you've already given to smaller conferences like B-Sides and other community events.
To get feedback if you live in a small town with no local community that you can join: you can 1) find a professional mentor, 2) ask online if someone will help (perhaps one of your connections will respond) or 3) join an online community and then ask people there.
I wish you all the luck in the world! You can do this!
TanyaSheHacksPurple: About Chapter 1 of Alice and Bob Learn Secure CodingSheHacksPurple2025-01-21 | Learn about chapter 1 of Alice and Bob Learn Secure Coding!
Chapter 1: Introductory Security Fundamentals · Assume All Other Systems and Data Are Insecure · CIA · Least Privilege · Secure Defaults/Paved Roads · Assume Breach / Plan For Failure · Zero Trust · Defense in Depth · Supply Chain Security · Security by Obscurity · Attack Surface · Usable Security · Fail Closed/Safe, Then Rollback · Compliance, Laws and Regulations · Security Frameworks · Learning From Mistakes and Sharing Those Lessons · Backwards Compatibility (and Potential Risks It Introduces) · Threat Modeling · The Difficulty of Patching · Retesting Fixes For New Security Bugs · Chapter ExercisesPlease consider buying my new book before February 5th. 🙏https://shehackspurple.ca/books/SheHacksPurple2025-01-19 | ...I cant wait to see so many of my European friends!!! #owasp #ndcsecurity #europe #London #osloSheHacksPurple2025-01-13 | ...Chapter 5 of Alice and Bob Learn Secure Coding, a brief descriptionSheHacksPurple2025-01-08 | ...Chapter 14 of Alice and Bob Learn Secure Coding, a brief descriptionSheHacksPurple2025-01-06 | A brief overview of chapter 14 of Alice and Bob Learn Secure Coding.
Aliceandboblearn.comSheHacksPurple: What if you dont know the answer? Dealing with imposter syndromeSheHacksPurple2025-01-05 | When I first switched to application security, I feared not knowing all the answers. Watch the video to hear about how I dealt with this, built up my confidence, and how you can too.The new office background/set! Embrace the purple! Advice on setup?SheHacksPurple2024-12-25 | ...Please, everyone, thank you mentors. Dont wait. #cybermentoringmondaySheHacksPurple2024-12-16 | ...SheHacksPurple: PenTest - No, no, no! (a parody video)SheHacksPurple2024-12-13 | This is a parody of Amy Winehouse's Rehab.
They tried to make me book a Pentest But I said no, no, no Yeah my app’s bad, but gotta WAF I said no, no, no I ain't got the time, and AppScan Says I'm fine They tried to make me book a Pentest But I won't no, no, no
I'd rather be coding alllllll day I ain't got seventeen days 'Cause there's nothing There's nothing you can teach me That I can't learn from Stack Overflow I didn't get a lot in class But I know users never act like that!
They tried to make me book a Pentest But I said no, no, no Yeah my app’s bad, but gotta WAF I said no, no, no I ain't got the time, and AppScan says I'm fine They tried to make me book a Pentest But I won't no, no, no
The CISO said, "Why you think you here?" The Dev said, "I got no idea" "I'm gonna, I'm gonna miss my deadline" "And no one would ever use my app like that…." He said, "I just think that you're stressed” “Bug fixes, new features, and the PenTest"
They tried to make me book a Pentest But I said no, no, no Yeah my app’s bad, but gotta WAF I said no, no, no
I don't ever want to lint again I just, ooh, I just need a SAST I'm not gonna spend ten weeks Doing my code review manually
And it's not just my pride It's just 'til these bugs subside
They tried to make me book a Pentest But I said no, no, no Yeah my app’s bad, but gotta WAF I said no, no, no I ain't got the time, and AppScan says I'm fine They tried to make me book a Pentest But I won't no, no, noAskMeAnythingAppSec: How do you tune a SAST to avoid false negatives?#ama #appsecSheHacksPurple2024-11-08 | AskMeAnythingAppSec: How do you tune a SAST to avoid false negatives? #ama #appsecHow do you incorporate code review onto a developers business as usual ? #appsec #amaSheHacksPurple2024-11-08 | How do you incorporate code review onto a developer's 'business as usual '? #appsec #amaMy new book, Alice and Bob Learn Secure Coding, is now available for presale!SheHacksPurple2024-10-28 | My new book, Alice and Bob Learn Secure Coding, is now available for presale! Please get yours here: amazon.com/Alice-Bob-Learn-Secure-Coding/dp/1394171706How does AI affect cyber security?SheHacksPurple2024-10-28 | ...