--- title: "Elissa Shevinsky — Be Kind, Security People — 5 Minute AppSec" url: https://appsecpodcast.com/elissa-shevinsky-be-kind-security-people-5-minute-appsec/ date: 2019-08-14 duration_seconds: 138 guests: ["Elissa Shevinsky"] topics: ["Security Culture"] audio: https://www.buzzsprout.com/1730684/episodes/8122633-elissa-shevinsky-be-kind-security-people-5-minute-appsec.mp3 transcript: true --- # Elissa Shevinsky — Be Kind, Security People — 5 Minute AppSec *August 14, 2019 · 2 min* with [Elissa Shevinsky](https://appsecpodcast.com/guests/elissa-shevinsky/) on [Security Culture](https://appsecpodcast.com/topics/security-culture/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122633-elissa-shevinsky-be-kind-security-people-5-minute-appsec.mp3) ## Show notes Why should kindness matter in an industry responsible for protecting money, systems, and sometimes lives? Elissa Shevinsky argues that high stakes do not justify gatekeeping, arrogance, or treating newcomers badly. Drawing on the community conversation around her SecretCon event and Rob Graham’s “InfoSec is Good People” post, she acknowledges why security practitioners value competence while rejecting meanness as a professional virtue. The field has more work than people available to do it, making a welcoming culture a practical necessity as well as an ethical one. Her message in this short episode is direct: hackers and defenders share one community, and that community becomes stronger when its members choose to be kind. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Elissa Shevinsky: → [Elissa Shevinsky on LinkedIn](https://www.linkedin.com/in/elissashevinsky/) Mentioned in this episode: → [InfoSec is Good People](https://blog.erratasec.com/2015/10/infosec-is-good-people.html) Chapters: 00:00 Why kindness matters in information security 00:20 Rejecting gatekeeping as a security virtue 02:07 Continue with the full interview ## Transcript *369 words · assemblyai* **0:00 Chris Romeo:** Welcome to another edition of 5 Minute AppSec. This is Chris Romeo, CEO of Security Journey, and on this week's episode, Robert asks a question of Alyssa Shevinsky from fasterthanlight.dev. **0:13** Alyssa, why should people be nice, or why is niceness important in information security? **0:19 Elissa Shevinsky:** I'm so glad you asked that. In 2015, I ran this event called SeekerCon that focused on niceness in information security because I thought this was a really big need. And Rob Graham attended and he wrote a blog post called InfoSec is Good People for anyone who wants to go and look at the history. And I'll explain it like this. It seems like we consider meanness at times or— I don't want to say arrogance, but the There's certain gatekeeping that's treated as a virtue in information security. There's a reason for that, which is that a lot is at stake with information security. Money and lives are on the line and we need to protect and make sure that when people come to information security that they're sincere and that they do a good job. But there's a lot of just not niceness, let's put it that way, that we see at DEF CON, that we see on Twitter that we see pretty much wherever information security lives, and people wear that really proudly. I don't think we should ever be proud of not being nice, and we should welcome new people to the space. There are not enough of us right now in information security to support how much work there is to do. Really, there isn't any pride, there shouldn't be any pride in being terrible to people, and it shouldn't be a value, right? So a lot of us in the information security space may come from having been hackers or felons, and that's certainly a thread inside information security. You know, the white hat and the gray hat and the black hat, it's all of us together. But we need to remember it's all of us together, so be kind. **2:06 Chris Romeo:** We did a longer interview with Alyssa where we talk about static analysis and other things, application security. So tune in to hear that interview later this week. --- Source: https://appsecpodcast.com/elissa-shevinsky-be-kind-security-people-5-minute-appsec/