--- title: "Tanya Janca -- A Secure SDLC from a Developer's Perspective" url: https://appsecpodcast.com/tanya-janca-a-secure-sdlc-from-a-developer-s-perspective/ date: 2025-02-26 duration_seconds: 2934 season: 12 episode: 5 guests: ["Tanya Janca"] topics: ["Threat Modeling", "Secure Development", "Security Testing"] audio: https://www.buzzsprout.com/1730684/episodes/16692689-tanya-janca-a-secure-sdlc-from-a-developer-s-perspective.mp3 video: https://www.youtube.com/watch?v=hgX75dxdwSk transcript: true --- # Tanya Janca -- A Secure SDLC from a Developer's Perspective *February 26, 2025 · 49 min · Season 12, episode 5* with [Tanya Janca](https://appsecpodcast.com/guests/tanya-janca/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/), [Secure Development](https://appsecpodcast.com/topics/secure-development/), [Security Testing](https://appsecpodcast.com/topics/security-testing/) [Audio](https://www.buzzsprout.com/1730684/episodes/16692689-tanya-janca-a-secure-sdlc-from-a-developer-s-perspective.mp3) · [Video](https://www.youtube.com/watch?v=hgX75dxdwSk) ## Show notes Security expert Tanya Janca discusses her new book "Alice and Bob Learn Secure Coding" and shares insights on making security accessible to developers. In this engaging conversation, she explores how security professionals can better Tanya Jenka, aka She Hacks Purple, is the bestselling author of Alice and Bob Learn Secure Coding, Alice and Bob Learn Application Security, and Cards Against AppSec. Over her 28-year IT career, she's won countless awards, including the OWASP Lifetime Distinguished Member and Hacker of the Year. She has spoken all over the planet and is a prolific blogger. Tanya has trained thousands of software developers and IT security pros via her online academies, We Hack Purple and Semigroup Academy, and her live training programs. Today's episode is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Tanya Janca: → [Ranakhalil1](https://www.linkedin.com/in/ranakhalil1) → [Alice & Bob Learn Secure Coding](https://shehackspurple.ca/books/) Mentioned in this episode: → [Alice & Bob Learn Secure Coding](https://shehackspurple.ca/books/) → [Confidence Staveley](https://confidencestaveley.com/) → [Ranakhalil1](https://www.linkedin.com/in/ranakhalil1) → [Laurabellmain](https://www.laurabellmain.com/) → [Adam Shostack](https://adam.shostack.org/) → [Liran Tal](https://twitter.com/liran_tal) → [OWASP Application Security Verification Standard (ASVS)](https://owasp.org/www-project-application-security-verification-standard/) → [Tanya Janca (SheHacksPurple)](https://shehackspurple.ca/) Chapters: 00:00 Meet Tanya Janca: A Secure SDLC from a Developer's Perspective 02:28 Glad, glad to have you here. So we have an intro 06:50 This is definitely a needed piece of literature. I can, Robert 09:26 Really 11:23 Wow. Wow. So Robert, why don't you take us into that 23:26 I'm curious to see who comes to those talks. Is it 24:33 That's a— that's a view of the— the way what we're 28:10 See 30:46 It makes me, just made me think of something that I 35:05 About other areas 43:49 Put it on a t-shirt. That's good stuff. Well, that's, that's 46:03 Yeah, definitely. Definitely. Well, Tanya, how about a key takeaway for ## Transcript *9,156 words · assemblyai* **0:00 Chris Romeo:** Tanya Jenka, aka She Hacks Purple, is the bestselling author of Alice and Bob Learn Secure Coding, Alice and Bob Learn Application Security, and Cards Against AppSec. Over her 28-year IT career, she's won countless awards, including the OWASP Lifetime Distinguished Member and Hacker of the Year. She has spoken all over the planet and is a prolific blogger. Tanya has trained thousands of software developers and IT security pros via her online academies, We Hack Purple and Semigroup Academy, and her live training programs. Having performed counterterrorism-led security for the 52nd Canadian general election, developed or secured countless applications, Tanya is widely considered an international authority on the security of software. Tanya currently leads education and community for Semgrep. Tanya joins us to discuss the developer perspective on a secure SDLC. We explore and deep dive on various areas of the SDLC and agnostic fundamentals to secure Today's episode is brought to you by Security Journey. **1:01 Tanya Janca:** Our education platform teaches valuable secure coding skills based on real-world vulnerabilities and threats, including OWASP Top 10. Learn more at securityjourney.com. **1:11 Chris Romeo:** Hey folks, welcome to another episode of the Application Security Podcast. This is Chris Romeo. I am the CEO of DaVinci and proud to be the co-host of this podcast. It seems like it's been going on for hundreds of years, but I know it hasn't been that long. Joined as always by my co-host, Robert Hurlbut. **1:39 Robert Hurlbut:** Hey, Chris. Yeah, Robert, and I'm a principal application security architect and threat modeling lead at Acquia. And as always, really glad to be here to talk about AppSec. And of course, uh, Tanya, our guest today. **1:52 Chris Romeo:** Yeah, I feel like Tanya is, is one of the people in AppSec that needs no introduction, but Tanya has now vaulted to the, uh, at the very top of the AppSec Podcast leaderboard and is at least 2 episodes above anybody else as far as appearances on the show. So, Tanya, we're always glad to have you on the show and to, uh, just be able to pick your brain and, uh, tap into the insights and things that you have about AppSec. **2:19 Tanya Janca:** Thank you so much for having me back. This is one of my favorite podcasts in the whole world. **2:25 Chris Romeo:** All right. We'll take that. Most definitely. **2:27 Tanya Janca:** Yeah. **2:27 Chris Romeo:** Glad, glad to have you here. So we have an intro question for you that's never been used before because when you come on the show is when we, when we create new intro questions, because you're at the top of the leaderboard here. So I thought we'd go into the world of movies. And so I'm curious what in your, from your perspective, is the best movie that you've seen in the past year? But then also, why was it worth watching and why would our listeners enjoy watching it? **2:56 Tanya Janca:** Okay, so I'm going to come out a bit in left field on this one. So I have stepkids now and I took them a few years ago to see Inside Out. And recently Inside Out 2 came on and one of our kids has anxiety. And so for those that don't know the premise, the idea is, um, of Inside Out is inside the person's brain, we have different emotions and how they influence us and how we act. And this is something that's always fascinated me. Um, and recently, and by recently, I mean about 3 weeks ago, I was diagnosed with ADHD. And it explains a lot, um, that I blamed on dyslexia previously. And one of the things is we have a lot of trouble understanding where other people are coming from. And I've had people think I was on the spectrum before because I just didn't get the social cues everyone else received. Um, and so it's so fascinating to me to be like, oh, so I'm feeling anxiety and so I behave this way, or I'm feeling, um, one of them's named ennui, and if you don't speak French, that means boredom. And so how you might act when one's embarrassed, et cetera. And the idea of as someone grows up, these different Emotions make you behave in different ways, and it shows the child and then the parents as well. And, um, yeah, I think that a lot of people could use a look at that about emotional intelligence. It really helped our kids talk about their emotions and name them better. And it sounds weird, but when you can name what you're feeling, it's so much easier to express it and explain to people and then get them to respond the way you want. And so I realized that's probably pretty off topic for AppSec, but in AppSec we need to understand other people, right? Because we're the bridge between the security team and the software developers and sometimes the project managers and the QA team and all sorts of other people. And so having some empathy and understanding where people are coming from makes us better at our jobs. **4:54 Robert Hurlbut:** Yeah. **4:55 Chris Romeo:** And I'm, I'm so glad that you're willing to share the fact that, you know, you were diagnosed with ADHD because A lot of folks out there might also be experiencing that as well, and they can look at you and see, Tanya's got ADHD, perhaps like I don't, but like if somebody's out there and they're like, hey, I do too, look at what you've done. Like you've had such a successful career, you've started a company, you know, you've done keynote events everywhere. And so it's like, it'll help people. It'll help them say, hey, I can do this too. I can do more. I can do more. Look what Tanya's doing. So thanks for sharing that. I mean, it's being vulnerable like that is not easy. And so you're just being really vulnerable with our entire community. And that's just a really powerful thing from my mind. **5:45 Tanya Janca:** I'm hoping that by being open, more people will talk to me about it because it, I thought I didn't have it because I unfortunately had the stereotype that ADHD is a really hyperactive 8-year-old boy, which I do have at home. But it turns out a lot of women bring their child to get diagnosed, which I'm doing. And then it's like, oh, me too, me too, me too, me too, me too, me too. Until eventually all the people I know were like, you know you have it, right? And I was like, no, no, not me. My son has it. And they're like, no, no, but you do. I'm like, no, we're not related. It's hereditary. And they're like, but you still have it. I'm like, crap. **6:23 Robert Hurlbut:** Interesting. **6:23 Tanya Janca:** But, um, it's, It's awesome. And so if you're listening and you do too, like, feel free to reach out. We can chat. Awesome. **6:32 Robert Hurlbut:** Cool. All right. **6:34 Chris Romeo:** Well, I'll kind of kick us off and then Robert will, uh, we'll jump in here as well, but you got a new book coming out. So let's, what's the title? Share the title with the audience. **6:44 Tanya Janca:** Alice and Bob Learn Secure Coding. Okay. **6:49 Chris Romeo:** This is definitely a needed piece of literature. I can, Robert and I can both attest to that throughout our careers working with developers and, and understanding the, the disconnect between coding and secure coding. You wrote the first book and then you decided to write another one. So, like, how much time did it take you to write this? I'm just curious, like, in, what would you say in hours, total number of hours that go into writing a book like this? **7:17 Tanya Janca:** So it took almost 3 years of time, but the first 2, or like a year and 3 quarters, I would write for a bit, then I would stop for a few months, and then I'd write for a month and stop for a month. And then basically in April of 2024, my publisher was like, so you've written about a third of a book. Are we gonna do this or are we not gonna do this? 'Cause you know, we've given you like 400 extensions. And like, you're a great author. Like, we think you should do it, but you need to do it. And so, um, I booked 2 weeks off of work in the summer to just only work on it. And I basically what I was doing is I was supposed to every Saturday and Sunday morning work on it, but I'd always work on some grad work cuz I was just never done. And I felt like I just, which apparently is an ADHD thing. **8:11 Chris Romeo:** Yeah. **8:11 Tanya Janca:** You just feel like you can't complete all your work in 40 or 50 hours. And so you end up working the weekend. And so I like put my foot down and was like, I'm not doing that anymore. And I'm just gonna fall behind on things and I'm sorry. I'm just only gonna work 40 or 45 hours and that's it. Um, and so then every Saturday and every Sunday, maybe like 3 hours or 4 hours, I wrote the other two-thirds of the book and the book's 415 pages. And so I guess I wrote around 300 pages from April to, uh, the end of November is when I finished completely writing and editing the entire thing. Uh, and then we just did like copy edits and layout and stuff like that in December. Um, and I finished it all right before Christmas, which was perfect. So I didn't have to spend that time doing it. Um, so a lot of hours, a lot, and I. I did a lot of research too for this, cuz a lot of things were just not right. Like if you go and you search, so I uncovered a lot of languages. I uncovered a lot of plagiarism in blogs, unfortunately, which I commented on social media. My friend Tal Liren is the most, um, pirated blog author I know. **9:25 Robert Hurlbut:** Really? **9:26 Tanya Janca:** People cop— they cop— like over and over again, I, I would see blogs and I was like, oh, this is cool. And then I would find the same blog cuz I would go through like 20 pages of search results to make sure. And like I would evaluate cuz sometimes people would be like, you should do this. But I would want many authors to agree. **9:44 Chris Romeo:** Yeah. **9:45 Tanya Janca:** And many different research papers to agree before I'm willing to put something in the book. Uh, cuz sometimes people are like, you should do this. And then I'm like, really? And then it would be wrong. And then when I would go through, I'd get to the third page and It turned out Tal published that like 3 years ago or 2 years ago or 4 years ago. **10:00 Chris Romeo:** Mm-hmm. **10:00 Tanya Janca:** People would just copy him. And so I sent them to him and I also complimented him a lot. I'm like, you do great research, dude. Um, he's written books too. Yeah. If you wanna learn Node.js. **10:12 Chris Romeo:** He's a previous guest of the podcast as well. So that's a, that's a good reminder. We gotta go, uh, track him down again and see what he's been up to the last couple of years. But yeah, he, he, he's written some stuff on JavaScript if I remember Node. He's written a lot on that. Yeah. So that's, but yeah, I guess it is a labor of love to write a book though. That's what people always tell me. Like it's not easy and there's a reason that not everybody ever writes a book. **10:38 Tanya Janca:** Yes. And there's a reason that, so a lot of people were like, oh, you should just get the AI to write your book. And I remember I bought a book from PACT. And it was written by AI. Like it, it was all over the place like this. It didn't make sense. And like the information was pretty useless. And I remember thinking like, I'd be so embarrassed if this was published under my name. Um, I like, I couldn't imagine it not being like that. I know the, the content, I understand it and that I could communicate it clearly. **11:13 Chris Romeo:** Right. **11:13 Tanya Janca:** And it's like if you wrote the Um, anyway, I can't imagine like just being like, oh, I'll just pay someone else to write my book. **11:20 Robert Hurlbut:** Yeah. **11:20 Tanya Janca:** And I'll just put my name on it. **11:21 Chris Romeo:** Yeah. **11:22 Tanya Janca:** That's a good idea. **11:23 Chris Romeo:** Wow. Wow. So Robert, why don't you take us into that first question about the SDLC? **11:31 Robert Hurlbut:** Sure. So, um, we, we've been developers for years and, uh, from a developer's perspective, what does a secure SDLC Feel like. **11:42 Tanya Janca:** Okay, so this is, this is awesome. So when I was writing the book, I on purpose got a software developer to be one of my, one of my editors to make sure it was telling the truth, um, and having an accurate perspective because I've been doing security for a decade now and I was a software developer for 17 years before that. It's like, am I so super biased? Like, is this still true? Am I still like, am, am I still telling the truth? Or not that I would lie, but am I still correct? And so, um, I would say that, so obviously the word it depends starts at the beginning, but when you are a software developer going through the secure system development lifecycle, you are hopefully having one or more members of the security team support you. And there are certain activities that happen and they happen hopefully every single time. And you are taught, told in advance what they're going to be and then taught your parts of them. And you're given tools to do that. This is what the ideal situation is. And so you start off a project, there's a person from the security team, they're at the kickoff and they're like, hey, During this project, we're going to do a bunch of security requirements, and I'm going to make sure they're part of the schedule. And we're going to do an architecture whiteboarding activity, and we're going to do a threat model during the, whenever it is you're doing the design. If you end up doing a redesign at some point, we're going to add those in there. We're going to make sure that there's code review, and it's going to look like this. And you tell them all the things that are coming, and then anything they don't know, you teach them. That's The idea. So you should have a guide, essentially. This is my opinion. This is not always what happens, right? And so I talk about, there's a big section which the developer technical editor Fab asked for. He's like, what happens when I get the security report? So it's like they've scanned my code or the pen test has come in. Like, what the heck do I do with that? Can you go over that? Because that was really scary the first time. He didn't say scary, but it was scary when I was the dev and I received it the first time. So I'm like, ideally, you know, you receive bugs, security bugs, the same way you receive all your bugs. So if you're using like Jira or Bugzilla or whatever, it's in there and it's been validated. So, you know, it's a true positive and there's explanation as to the risk. It's been prioritized for you. There's information about how to fix it. Maybe there's even a little lesson if we're in magic land in Tanya's dream. Um, and there's someone that you can ask if you're lost, right? Like that would be ideal. Those things would all be great. But it could also be, uh, the pen tester comes and gives a formal presentation with slides and you don't understand anything they said. It could be you get emailed a PDF and again, there's an, and, and they don't even tell you about it. They don't even ask when it will be due. And then a month later you get bitched at as to why it's not done. Of, it could be you received this weird automated email that went to spam that's from some security tool. And to try to get to it, you have to like remote desktop into something and then remote desktop somewhere else. And then you have to MFA, but you don't have the challenge. And then once you get in, then you have to log in and then you see every single scan that has ever happened for your whole organization. And there's like 25,000 things in there and you're like, oh my gosh, where is my cloud? **15:18 Robert Hurlbut:** Yeah. **15:19 Tanya Janca:** So it's not always ideal and like, here's how you can combat these things. And also, like a, a tip that I give at the end, like, tell the security team, this is how we usually receive our bugs. Will you allow me to automate us to receive them that way? Because you know how to do that and the AppSec team doesn't necessarily know how to code or script or do that, right? And so if you say, this is how we usually receive our bugs and I will make it so we receive them that way. A lot of them would jump at that. Oh, you'll automate it for me? Sounds fantastic. Yeah. **15:52 Chris Romeo:** That's— **15:52 Tanya Janca:** But they're not. Yeah. **15:53 Chris Romeo:** You brought up a, right at the beginning there, you brought up a, a pretty interesting thing that I wanna, I wanna double-click on here. This idea, and I hadn't really thought of this until this moment, the fact that those of us that have been in security for a long time, we may have drifted away from the true developer perspective or the true developer understanding. We may be operating in a world where we're just making assumptions and we just, we've just stacked those assumptions on top of each other to the point where developers, we're not easy to work with. And we're frustrated because why aren't the developers just doing the things that we've describe the things that we've called out that they should do. And we're, we're, we're too far away from them. So that, it just makes me think of this thing that I discussed a few years ago, this idea of developer empathy. So perhaps we need a, we need, we need AppSec teams should be actively looking for ways to get back into the shoes of developers and, and, and make, reconnect and make sure we haven't drifted. 'Cause I've got this fear that we may have drifted. Actually, I'm willing to say we did, we have drifted. **17:11 Robert Hurlbut:** Yeah. **17:11 Chris Romeo:** As a, as a com— I'm just gonna talk about a community and our, our entire, meaning the entire AppSec community. We've, we've drifted away from where we started and there may be work to do to clean that up. **17:21 Tanya Janca:** It, it kind of first came to me, to be honest, when I interviewed the OWASP ASVS team for a podcast I had, and they were talking about By developers for developers, that's ASVS. And I was like, no, it's by amazing security professionals who have so much expertise. 'Cause like at the time I had way less experience and I still think those people that I had on my podcast, like Andrew, Jim, and Daniel, like so smart. **17:53 Robert Hurlbut:** Yeah. **17:53 Tanya Janca:** They're so smart and so knowledgeable, right? And I'm like, no, but y'all have done security so long, you're not really developers anymore. I'm like, have you built an app recently? Like not written 2 lines of code to fix a bug, but like developed a piece of software. And they're like, no, but I don't need to. I'm like, I'm not saying you don't know how to do it anymore. I'm saying that it's not fresh and like things change. And, um, and I was, I was just like, if I would rather you 3 write AS/VS than a random developer, right? Obviously it's gonna be 1,000 times better, but I'm like, have like bringing developers along on the process and getting feedback from them all the time's really important. Yeah. To make sure that they can just grab it and read it. 'Cause I remember the first time I looked at ASVS, I felt underwater. And like the first time I went to an OWASP conference, I didn't understand any of the talks I went to and I felt stupid. I was like, I've been developing software forever and I just started learning, just barely started learning about AppSec and just every talk was just like, whoosh, over my head. Even the builder's track, I was just like, I went to a talk called Why So Serial about deserialization, and that was the only one I kind of understood. And I was like, best title ever. **19:12 Robert Hurlbut:** Um, yeah, yeah, yeah. **19:14 Tanya Janca:** But I was like, oh, oh my gosh, that does sound bad. I should not do that anymore. Right? But I just, I walked around, I swear I walked around like this, like with my mouth open the whole conference. And then I just took lots of notes and then just did tons and tons of reading. And then the next time I went, I was able to understand more and more, and each time it was better. But that's why I always tell OWASP, this is why we have no devs at our conference, 'cause none of the talks are for devs, they're for security people. And they're like, no, we have a builder track. I'm like, no, it's— **19:44 Chris Romeo:** That's a fundamental problem of that OWASP's been suffering since its very inception. And This idea that developers are going to somehow want to be a part of OWASP when there's really not a big value proposition for them, given your experience as far as the steep learning curve to just get value out of it. I think OWASP has got more work to do to, they've almost gotta, they've almost gotta erase the whiteboard. And go back to the drawing, go back to the beginning and say, we gotta, we gotta do something different from anything that we've ever done before. Because what we've done so far for 25 years has worked great as a security community. But you raise a great point there. There's not really any developers there. And the idea is always, well, we need to go out to developer conferences. Sure. That is one thing, but that doesn't solve the fundamental OWASP problem of Developers don't care about OWASP. **20:49 Tanya Janca:** Yeah. **20:51 Chris Romeo:** Maybe. **20:51 Tanya Janca:** Well, I've been working on it with them. So, uh, this, uh, last year they did a conference and they added a developer day. And so I had 3 presentations accepted. So basically secure coding lessons that I was gonna give, and then they canceled it. And so now they're doing, um, an OWASP track. On, uh, the Developer Week conference in Santa Clara. And, um, sorry, I'm just trying to mute things because I had turned off all notifications and I guess 1 hour passed, so it decided to turn them all on. Sorry. I thought I was so smart. Um, but so I'm going to go down to Santa Clara and then present at a developer conference about security on the OWASP track. Um, but one of the issues with that is that like OWASP can't, because it's a community, it can't cover any travel costs. So it's like all out of pocket. And luckily I work at SummGrab. Thanks, boss. I was gonna pay for it, right? But if I didn't work there, it'd be really hard for me to go, uh, to a non-security conference. So I'm not gonna get business there. **22:01 Robert Hurlbut:** Right. **22:01 Tanya Janca:** Right? 'Cause I get hired by the AppSec team. That's where all my money comes from, the AppSec team. Buys the SoundGraph products, the AppSec team hires me to come do secure coding training or come speak for their devs. I don't get hired by developers, right? So it's all out of pocket then if we do it. And that's complicated from an incentives thing, which I do talk about in the book. I talk about how we have some perverse incentives. So for instance, developers get paid to make amazing new features. They don't get promoted because they fix lots of security bugs. It's very rare that they're rewarded. Yeah. **22:39 Robert Hurlbut:** Hmm. **22:39 Tanya Janca:** Um, and so then we give them these perverse incentives, like, yeah. Anyway, um, so I'm, I'm hoping and I'm glad that I have a new boss and he's super pro-dev and developer conferences, so I'm applying and doing that. But it's really hard, right? 'Cause most of us receive our business From OWASP, we're from security professionals, so we wanna speak at security events and attend security events. But where we're needed is at PyCon and Developer Week, and we are developers and all of the other really, like, there's so many amazing, like, amazing developer conferences. **23:17 Chris Romeo:** Yeah, this'll be an interesting, call it experiment, with you going into Developer Week as part of that OWASP track. **23:25 Robert Hurlbut:** No. **23:25 Chris Romeo:** I'm curious to see who comes to those talks. Is it the security people that happen to be at Developer Week? Because if that's the case, then we really need to go back to the, to the whiteboard and start fresh and say, there's gotta be a new pathway in to try to do what we've all been trying to do ultimately for 20+ years, which is get developers on board. Because I think we've all come to agree that we can't do this with security teams. There's just not enough. **23:52 Tanya Janca:** Yeah. **23:53 Chris Romeo:** There's just not enough money in anybody's budget to build a 500-person security team that's gonna go do all of those things. And so, there's, there's gotta be a different, a different way forward. **24:04 Tanya Janca:** Well, if you could tell the developer conferences to accept my talks, that would help because when I applied to a security— **24:12 Chris Romeo:** Let me make a couple calls here real quick. **24:14 Robert Hurlbut:** Yeah. **24:14 Tanya Janca:** When I applied to a security, I like have an, like an 80, maybe 75% acceptance rate for security conferences, and I have an almost zero acceptance rate for developer conferences. **24:25 Chris Romeo:** Yeah, that's— **24:27 Tanya Janca:** They're just like, security, ew. **24:29 Chris Romeo:** Yeah, it's state of— that's the state of the industry though. Like, that's the— **24:32 Robert Hurlbut:** that's a— **24:33 Chris Romeo:** that's a— that's a view of the— the way what we're dealing with in our industry. So, I wanna make sure we get some time into some of the things in the book. So, the— no, this is great. Like, I— we could, like, you're our, our most popular guests. So, I mean, we could sit here and chat too, but I want to dive in. I want to get some more stuff from the book though. I want to get some perspective. So, I know in the book you're breaking down various pieces of the SDLC. And so threat modeling was one, but I'm curious about some of the other ones too. Like what, you know, I'm going to back up, rewind, pretend I didn't just say all that. Is this book written for developers or security people? **25:10 Tanya Janca:** It was my goal to make it for a developer. So every time I speak to them, it's like, so the security team might do this, or you might need to ask the security team, or you are totally allowed to take this and run with it, and you don't need any permissions, just give 'er. Oh, which is Canadian for, I encourage you to go do so. **25:28 Robert Hurlbut:** Okay. **25:30 Chris Romeo:** So that does help me scope the, so I definitely wanna dive into the pieces of SDLC, but we are talking specifically from the developer's perspective. So I'm curious now, you know, Robert and I spend a lot of years thinking about threat modeling and, and, and, and pushing it forward on, on our industry and trying to get developers to do it. How'd you come at, at threat modeling then with this developer-first kind of thought process? **25:55 Tanya Janca:** Okay. So I started with, so this is what threat modeling is. It's a, it's a conversation where you're trying to discover all the threats to your system, decide which ones are worse. Either mitigating or eliminating. And then the hard part, doing all the steps after to make that happen, right? And so if you're going to attend a threat model, this is what it's gonna be like and this is what you should bring. So think about the idea, if I was gonna hack my app, how would I do it? What is the worst thing that could happen? Is, is there anything like I'm secretly worried about? Are there, are there problems that you already know about that you haven't mentioned? Because No one asked. Like the first time I did a threat model where I was the leader of it, um, I remember asking the, the developers, so if you were gonna hack your app, how would you do it? And they look at each other and then one of them's like, mm, he kind of shakes his head a little bit. And the other one's like, okay. And they're like, well, we, we, we'd go through the admin module. And I'm like, oh, the admin module isn't on the design document. Tell me about it. And like, The CISO's head looked like it was about to explode, and I had told him in advance, so like, there might be scary things that come up, try to remain calm. And, um, which is something I personally had to work on a lot when I started because I wear my feelings on my sleeve. I'm like very expressive. And, uh, and so it turned out their boss wouldn't pay overtime, and once a month they had to administer something and it had to be at midnight. **27:27 Chris Romeo:** Oh. **27:28 Tanya Janca:** And so both of them lived really far away from the office. So it was about like a 45-minute drive there and back at midnight. And he went and they wouldn't pay overtime for it or any, anything. There were, there was nothing in it for them. They couldn't even come in late the next morning. So you get home at like 1:30 in the morning. That sucks. So they built a little admin module so they could do it themselves. And so then I, I look at their boss and I'm like, security flaw? **27:52 Chris Romeo:** Mm-hmm. **27:53 Tanya Janca:** Or $150 extra bucks a month. And he's like, I'll take the $150 bucks. So he started paying them overtime and we took apart the admin module, right? And, uh, we talked through a lot of other things and we, we made a bunch of changes. And so then when it came time for the pen test at the end, they did pretty darn well. **28:09 Robert Hurlbut:** See? **28:10 Tanya Janca:** And the, the idea that, so you're not gonna get in trouble, no one's gonna be angry at you, and it's actually a pretty fun process, like I know that maybe the 3 of us are biased because we like threat modeling, but in my opinion, I like threat modeling because I find it creative. I find it interesting. I find that, to be quite blunt, other people have such brilliant ideas and I love hearing them. I love learning from others and like the developers, oh my gosh, they have some ideas. They're all little hackers, just no one told them yet. Like, right? Like they're so smart. And they're always coming up with things where I'm like, Oh, I would never have thought of that. Write that down. And so, um, I, I just try to give them my enthusiasm and infect them with my excitement and interest. And I think it's a great team building. And I also explain that if you are not good at it the first time, that was me. I sucked at it. I was like, why would you do that to my poor little app? That's my baby. And then now I'm totally evil. **29:14 Chris Romeo:** Right. **29:14 Tanya Janca:** I'm so evil all the time now. Um, I went on a vacation and they took my luggage and they didn't give me a little ticket for it. And then when I, I went to the next thing, they had lost one of my bags. And so I filed a complaint and then they gave me a bottle of wine and I almost never drink, so I don't know what I'm gonna do with it. Um, but anyway, uh, and to say sorry, but eventually they found my bag. It took about 24 hours. But I remember thinking I could just file a complaint that they lost a bag that never existed. And then I would, and then they'd have to pay it out. Oh my gosh, there's like no security here. And, and then I started like kind of, and then my partner's like, please stop threat modeling. You're not at work now, babe. I'm like, I should go tell the security team. But eventually you'll see threats everywhere, right? **30:06 Robert Hurlbut:** Yeah. **30:06 Tanya Janca:** I bet, I bet the two of you see threats everywhere. And so you become good at it very quickly, and then you are gonna build badass apps. Because once you've learned threat modeling and you start seeing those flaws, you can't unsee them. And so when you're designing things, you're just gonna be better and better and better at it. And it is, all of the things in the book are like your first giant step towards becoming a senior software developer. Right? Like, if you're the person that everyone wants at the threat model that, that's building really tough apps that pass the pen test, you're the one that knows the answers. Like, that's, that's senior dev material. **30:43 Chris Romeo:** Yeah. **30:44 Tanya Janca:** Yeah. **30:45 Chris Romeo:** It makes me, just made me think of something that I always say when I start doing threat modeling with developers. And, and that is that you're an expert in what you build as a developer. you know so much more than I ever will about the thing that you're building. But I do that because it's true, but it also empowers them to start throwing things on the table because I've kind of said, hey, I'm not this security person that thinks I'm coming in with all the answers. I'm actually coming in with none of the answers. What I do is I just ask questions. Sometimes I know the answer to them, other times I don't know the answer to them, or I think I know the answer to them, but often I don't know the answer. I just throw the question out there, like, what would happen if this did this and talked to that? And they'll either say, oh, that could be something, or that isn't even possible. I don't know where you came up with that idea. But I try to give them that power to say, you have the ability, you are the one that has the real ability here, not me, because you're the one that's building this thing and designing it. And so I think there's a lot of power in what you've unlocked here and what you unlocked in that story by letting them explain what they saw as the real issues, because you would've never known if it was just a security person doing the threat model and they handed you the data flow diagram and it didn't have the admin module, you'd never know that it existed. But it was them being empowered to be successful. **32:11 Tanya Janca:** Well, and, um, they had told me after that basically the last pen tester was really harsh on them and arrogant. And they're like, we felt like you were just one of the devs on our team. Like, we felt very comfortable with you. Like, you just didn't seem that intimidating. And I was like, oh good, I don't wanna, I'm not here to intimidate. I'm here to try to make things better and help. Right? And they're like, oh, that, that was not the attitude of the last guy. Okay. **32:42 Chris Romeo:** That really makes my blood boil when I hear stories like that though, because Nobody has, none of us have all the answers. Nobody has any reason to be arrogant in this world, in this, in this field. If you tell me, like, I love it when I see when someone says, oh, well, then they are self-described expert. I'm like, first of all, you can't call yourself an expert. Someone else can nicely call you an expert and you can kind of humbly say, well, you know, that's, um, there is no such thing as an expert. But when you, when you hear stories about somebody coming in that's being, that's just arrogant about it, it just, it makes it so much difficult for the next security people that come in. and are trying to be, trying to help these folks do something, but they're like, ah, this is probably just somebody who's like that last person who was just a jerk and, and was not really there for our best interest. And it's just, I don't know, we don't, people, we don't have to do that. Like, you can be humble in what you do. I mean, I've been doing this for 20, almost 28 years I've been in cybersecurity. And I often, every day I learn something new or I'll be on a call and somebody will say something. I'll be like, wow, Wow, that's really cool. I never thought of that. I never even thought that was a thing. And so I, I just, I embrace it. **33:53 Robert Hurlbut:** I love it. **33:53 Chris Romeo:** Like, it's, this is a, this is a field where you're constantly learning. And if you're not constantly learning, then you're in trouble. But none of us have this all figured out. Nobody has it all figured out anywhere. So people out there, don't, don't act arrogant if you're, uh, if you're a security person and you're, you're representing the rest of us as well and making it more challenging. **34:12 Tanya Janca:** I feel like it's less fun too. I feel like when you make things adversarial, everyone has less fun. And I know work isn't supposed to be solely about fun, but it doesn't mean we can't have a great time doing it, right? **34:26 Chris Romeo:** Yeah, true. Yeah. I mean, the tension that that pentester must have created in that room, that's just an uncomfortable situation for everybody. Like, who wants to live their life being uncomfortable like that? Like you said, there was no reason for it. It was just somebody being arrogant and thinking they had all the answers. Like, work should be fun. Like, if work's not fun, especially in what we do, like, there's not a lot of us. And if you're not having fun, go somewhere else and have fun. Like, go somewhere else where they'll let you have fun. Because that's— life's too short to sit around and be uptight and angry all the time and stressed out and everything else. So. **35:03 Tanya Janca:** Yeah. **35:05 Chris Romeo:** What about other areas? Let's explore one more area in the SDLC and then folks will have to buy the book and read it to get out to see all the other ones. But I'm curious, like, what would be another area you would go to outside of threat modeling? **35:16 Tanya Janca:** To be honest, like, one that I feel that people aren't really talking about enough is maintenance. So, once you release your app, there's still work to do. You still have to care for your baby. If anything, like, I find it very strange that a lot of companies, they're like, yeah, we did a bunch of scans, we released it, we're good now. And I'm like, well, no, until the day you decommission it, there's still work to do. And so I talk about the idea of monitoring, observability, logging, what to log, what not to log, alerting, the idea of blocking or shielding your app, like when you might wanna do that, when it might not be necessary. the idea of continuous testing. So you can connect like a static analysis tool or software composition analysis or like a secret scanner right to your code repository and just have it scan every Sunday, right? And then if you have time Monday, go look at the results. And if you don't, you look at 'em next Monday, right? Like worst case, you like, you can set up all these automated things to just keep kind of checking and checking and making sure, 'cause software does not age like wine. It does not get better. It ages like cheese. in the sun. It is not good. And I love cheese and I love the sun, but they don't belong together. And, and, and so, right. **36:37 Chris Romeo:** That's just an area like a lot of people don't, like you've tapped into something here that now I'm kind of going back through my mind, excuse me, thinking of talks I've seen or conversations or processes I've seen. And people just don't, maintenance tends to be not something that's part of the SDLC. It tends to be something that falls off and happens after. **37:02 Tanya Janca:** Yeah, I talk a lot about incidents. So what their role is when there's a security incident, like what the ideas of need to know, how that works, why they should not be talking about it. You know, the likelihood of them being called to participate in an incident is low. But if they do, here's what we're they're gonna need from you. This is why security incidents are so important. And like, they need you because you are the expert, because you are the person that literally built this app and cares for it, and you know more about it than anyone else on the planet. And so if they ask for your help, like, they've, first of all, they really need it. And second of all, like, this is your chance to shine. And I talk about business continuity and disaster recovery planning because that is another thing that I see a lot of companies Not do well. And I remember when I was a dev, so my second last dev job, we had, uh, the boss of IT left and we didn't have a new boss. So one of the managers was acting as the CIO, the chief information officer for a while. And we were gonna do business continuity planning and disaster recovery. And, and I was like, okay, I wanna do this, I wanna do that. And he's like, that's gotta take time and money. We don't have time for that. I'm like, yeah, we do. And he's like, here's my plan. And he wrote, panic accordingly, then resign. And he's like, yeah, I'm just, I'm just gonna resign. And I, and I was like, so that's what you're gonna write? He's like, yeah. I'm like, cool, you're fired. He's like, you can't fire me. I'm your boss. I'm like, if I was your boss, I would fire you on the spot if you submitted that because you've decided to let down our company. That is not acceptable. And he's like, why do you always have to be the adult in the room? I wasn't even in security then, right? I was just a dev, but I'm like, Mark, these are my babies, my 72 babies, my apps, because I was in charge of all the devs or most of them. Um, and so, and I'd been like the senior dev forever, right? And I, at that place, and I was like, no, we have to take care of them. I want this, I want that. And so we started again and then we built a real one, right? But you'd be surprised how many places don't have anything. And I, I just, so did you notice during COVID some companies, they didn't skip a beat and other ones like fell apart? They like stopped working for several months. They, whatever. And then other ones, they're just like, yeah, I got this. No problem. And it's because they had a business continuity plan. It's because they had disaster recovery planning. It's because they prepared for the worst. And so then they just did their plan and it worked. And especially if you practice that plan, like practice it, not just doing backups, but practicing a rollback to make sure it actually works. **39:47 Chris Romeo:** Mm-hmm. **39:48 Tanya Janca:** Yeah. Yeah. It's unfortunately rare, but I hope it won't be. And so I talk about if you're a developer, you can do that. You can say, what's our disaster recovery plan? What's our business continuity plan? Because I need my apps, like, and just to be clear, Not every app needs to be part of the immediate up plan, right? Like there's mission critical apps. You should know which ones those are. There should be a list. And those are the things that come up first, probably your email, probably your website. When I worked in the Canadian government, the number one thing was putting the website up. And I know that that sounds silly, uh, compared to providing services for Canadians, but it was so important because then Canadians would become afraid. Some of them would become quite afraid and panic if the government's website went down. So it was number one to get it back up immediately. And so those should have extra special planning. And then it's like layers of how we boot up this, boot up that first, and these can wait, et cetera. And like knowing all of that can really save you. I, I remember having some outages and having things happen and not all of us got back up gracefully. **41:01 Chris Romeo:** So, there was another topic in the book that caught my eye. So, I'm wondering if you can just share one of these as a teaser. I don't even, I don't want people to have to go look at the book, but agnostic fundamentals of creating a secure code, of creating secure code that applies to any language or framework. And so, maybe just share one of those, and then people can go read the book to To discover all the rest of them that go into it. **41:25 Tanya Janca:** So I've mentioned this one on the show before, but it is the number one one that I want people to do that a developer is totally in charge of. And this is input validation. So quite often I hear everyone say, yeah, you gotta sanitize your inputs. I'm like, no, what you want to do is validate that you are receiving what you're expecting to receive. And so let's say it's a date. It better be a date, and it should be in the format you're expecting. And then should it? It should be in the range that you're expecting. So if it's a date of birth, it better not be in the future, right? And it probably shouldn't be 600 years ago, right? And so validating that it is in within the parameters of what it's supposed to be, and if it's not, you just reject it and say, "I'm sorry, this is what we're expecting." Bad input, right? And then, and and and we're doing that against. An allow list, so an approved list of characters or numbers or format or whatever of yes, not a block list of no. And so once you do that, then you decide if you're going to sanitize or escape. So if you have to accept some special characters that are potentially dangerous, that's cool, you accept them. But then either you sanitize them out, so like take it out, put like a tilde sign instead of a single quote or whatever works for you, or just remove them completely if that makes sense, or escape them. I usually escape. Personally, but whatever. That's your choice. If we could get that right, because sanitizing is hard, and not everyone gets that, does a great job of that. If we all validated first and threw away everything that did not measure up, and then did the escaping and sanitizing, our lives would be so much better. And if we all learned to use an approved or an allow list rather than a block list, Again, life way better. I, I was taking this training with Jason Haddix on, um, on AI, which was like very, very interesting, um, and informative. And, uh, he was talking about pen testing, uh, cuz he is a red teamer who I'm very glad is not a bad person, um, cuz if he is, I'll be in trouble. Um, but he talked about, oh, like when there's, he's like, oh yeah, it's the best when they have a block list cuz then I just scoot around it. **43:38 Chris Romeo:** Yeah. **43:38 Tanya Janca:** Everything's good. He's like, oh, and they have an allow list. It's the worst. Like, yes, that's what I want to hear. I was like, yeah, that's right. That's right. I couldn't say it better myself, Jason. You say it again. **43:48 Chris Romeo:** Put it on a t-shirt. That's good stuff. Well, that's, that's, uh, and there's a lot more, right? There's a lot more tips in the book and whatnot about, uh, applying secure coding in, in a, uh, a way that works kind of universally with everything else. So. With that, I think, Robert, take us to our one-question lightning round. Yeah. Because Tanya's special and, and we have to make new lightning rounds when Tanya shows up because we've already asked all of the other questions in previous episodes. So, all right. **44:24 Robert Hurlbut:** So the one question today is, um, please highlight, or could you highlight, uh, 3 people that our listeners probably have not heard of? **44:33 Tanya Janca:** Mm-hmm. Okay, so definitely my first choice will be Confidence Staverly. So she is an API security author and, um, podcaster from Africa, and she is such a delight. She's brilliant, super technical, breathes all the fire, and she's just so charming and fun and nerdalicious. Uh, and then next would be Rana Khalil, and you might've heard of her, but if you wanna learn pen testing, she's so great. She's so patient. and gentle and kind and, and generous with her knowledge, but then she's also like ridiculously destructive. And again, I'm glad she's on our team because that would be scary if not. And then, um, the last one I wanna mention, um, so you already had Milan on, so I'm not gonna mention her. She's awesome. Um, but a lot of people in North America haven't heard of Laura Bellamy. **45:29 Robert Hurlbut:** Yeah. **45:30 Tanya Janca:** So she's the CEO of SafeStack, but I, I joke that she's New Zealand's Tanya and I am Canada's Laura because we both have secure coding academies. We both wrote books about secure coding. We both love to teach and we're both like just nerdy brunettes. And, um, I feel like she's a really good teacher and she's so like light in the way she teaches. **45:56 Robert Hurlbut:** Yeah. **45:56 Tanya Janca:** And I feel it's very accessible. And so, um, I think those 3 are pretty, pretty good. If you haven't heard of them, you should check them out. **46:03 Chris Romeo:** Yeah, definitely. Definitely. Well, Tanya, how about a key takeaway for the audience based on our conversation here? **46:12 Tanya Janca:** I would say, and I feel like the 2 of you will probably agree with this, is that if you have not tried threat modeling before, figure out a situation where you can do one. Even if you threat model your organization's mission, which I find very powerful, or threat model something at home, um, it sounds weird, but by doing perhaps Adam Schostak's 4-question frame, let's say you have a vacation planned, like what could go wrong? Like, do we think we need cancellation insurance because our schedules change all the time or whatever? And you go through and you're like, oh, if I do this, this, and this. **46:51 Chris Romeo:** Yeah. **46:51 Tanya Janca:** then none of those things can go wrong and I can just chill out and relax. So try doing a threat model if you have not done one before. And if you have done one, try inviting someone who has not done one along with you next time, just so they can sit in and learn because it's so valuable and interesting. **47:09 Chris Romeo:** Well, the new book, Alice and Bob Learn Secure Coding, I saw on Amazon earlier today, it's available February 5th. According to Amazon. So that'll be, and I'm sure you can get it other places where you buy books as well. So, Tanya, thank you for joining us again for another episode. Great conversation. And we talked about secure coding. We also talked about a lot of other things too, which I love. So, good luck with the book, and we will definitely be looking forward to the live streams, which I just remembered. So, tell us about the live streams. **47:44 Robert Hurlbut:** Yeah. **47:44 Tanya Janca:** Okay. So once the book comes out and everyone has a copy, so probably 2 months after it comes out, uh, I'm gonna start doing just like I did for the first book, a livestream each month for every chapter of the book where I invite a bunch of friends on who happen to be experts on those topics. And we're gonna discuss it and we're gonna answer the questions at the back of the book. So every chapter has questions and then there are answers, but we're gonna answer them live. We're gonna take audience questions. And then it's all going to be saved onto YouTube. So if you want to go, go to newsletter.shehackspurple.ca and sign up for my newsletter. You'll get invited. If you bought the book, it's in the book, right? But you have to read a while to get to that part. So to make sure you don't miss any, just join the newsletter. It's free. And I'll just tell you when they are and invite you. And, um, Chris and Robert, I hope to have you as guests on one of them because you two are both so great and knowledgeable. And so, um, yeah, I hope to see all of you there. **48:46 Chris Romeo:** Yep. And I know we would be honored to, uh, to join for one of those sessions. So thanks, Tanya. **48:51 Robert Hurlbut:** Definitely. **48:52 Tanya Janca:** My pleasure. --- Source: https://appsecpodcast.com/tanya-janca-a-secure-sdlc-from-a-developer-s-perspective/