Skip to content
AppSec PodcastThe Application Security Podcast — home
2 min

Elissa Shevinsky — Be Kind, Security People — 5 Minute AppSec

With Elissa Shevinsky

Security Culture

Why should kindness matter in an industry responsible for protecting money, systems, and sometimes lives? Elissa Shevinsky argues that high stakes do not justify gatekeeping, arrogance, or treating newcomers badly.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 3 chapters
  1. 00:00Why kindness matters in information securityAudio
  2. 00:20Rejecting gatekeeping as a security virtueAudio
  3. 02:07Continue with the full interviewAudio

About this episode

Why should kindness matter in an industry responsible for protecting money, systems, and sometimes lives? Elissa Shevinsky argues that high stakes do not justify gatekeeping, arrogance, or treating newcomers badly. Drawing on the community conversation around her SecretCon event and Rob Graham’s “InfoSec is Good People” post, she acknowledges why security practitioners value competence while rejecting meanness as a professional virtue. The field has more work than people available to do it, making a welcoming culture a practical necessity as well as an ethical one. Her message in this short episode is direct: hackers and defenders share one community, and that community becomes stronger when its members choose to be kind.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Elissa Shevinsky:
Elissa Shevinsky on LinkedIn

Resources
InfoSec is Good People

Actionable

From this conversation

  1. Reject gatekeeping in security

    I don't think we should ever be proud of not being nice, and we should welcome new people to the space.

    0:19
  2. Welcome newcomers to the security community

    I don't think we should ever be proud of not being nice, and we should welcome new people to the space.

    0:19
  3. Treat security as a shared effort

    But we need to remember it's all of us together, so be kind.

    0:19
Transcript · 2 min conversation

0:00Chris RomeoWelcome to another edition of 5 Minute AppSec. This is Chris Romeo, CEO of Security Journey, and on this week's episode, Robert asks a question of Alyssa Shevinsky from fasterthanlight.dev.

0:13Alyssa, why should people be nice, or why is niceness important in information security?

0:19Elissa ShevinskyI'm so glad you asked that. In 2015, I ran this event called SeekerCon that focused on niceness in information security because I thought this was a really big need. And Rob Graham attended and he wrote a blog post called InfoSec is Good People for anyone who wants to go and look at the history. And I'll explain it like this. It seems like we consider meanness at times or— I don't want to say arrogance, but the There's certain gatekeeping that's treated as a virtue in information security. There's a reason for that, which is that a lot is at stake with information security. Money and lives are on the line and we need to protect and make sure that when people come to information security that they're sincere and that they do a good job. But there's a lot of just not niceness, let's put it that way, that we see at DEF CON, that we see on Twitter that we see pretty much wherever information security lives, and people wear that really proudly. I don't think we should ever be proud of not being nice, and we should welcome new people to the space. There are not enough of us right now in information security to support how much work there is to do. Really, there isn't any pride, there shouldn't be any pride in being terrible to people, and it shouldn't be a value, right? So a lot of us in the information security space may come from having been hackers or felons, and that's certainly a thread inside information security. You know, the white hat and the gray hat and the black hat, it's all of us together. But we need to remember it's all of us together, so be kind.

2:06Chris RomeoWe did a longer interview with Alyssa where we talk about static analysis and other things, application security. So tune in to hear that interview later this week.

369 words · transcript by assemblyai

More on Security Culture

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.